9 ms·
Tell HN: Namecheap gave my account to an unverified third party
I’ve been a NameCheap customer for 13 years. I’ve also helped out an old college club paying for a .com they use (that is registered to me under my name, address, and phone number). During a recent leadership transition, the incoming club lead wanted to make changes to the DNS and didn’t know to contact me. They figured out the domain name was parked at NameCheap, so they initiated a password reset using the domain name. I got a password reset email and immediately filed a NameCheap support ticket saying “I did not initiate this”. They called me to verify I was the one who filed the ticket, and then followed up with a canned email with tips like check your anti-virus.
The incoming club leader was persistent though, and called NameCheap support. He convinced them the domain registered in my name and address really belonged to his club, and with no verification or validation whatsoever, NameCheap changed my password, and changed the email address associated with my account. All because someone simply asked nicely on a phone call.
Meanwhile in the background, someone advised the new club leader who I was and we were able to connect and get things transferred over. Ultimately I was happy to give them access or even ownership if they wanted (student club turnover being what it is, it’s likely a domain doesn’t get renewed and gets gobbled up by a squatter, which is why I was keeping it current for them).
But NameCheap had no way of knowing any of this. As far as NameCheap was aware, this was a personal account of mine. They demonstrated they were perfectly able to pick up a phone and call me (to verify my initial support ticket) but when someone calls them and says “but I really want access to that account” they don’t bother?
I’d hesitate to even call this social engineering. It’s clearly a massive vulnerability. I’ve already moved a dozen of my most critical domains out of NameCheap after seeing just how easy it is for a third party to completely take over a NameCheap account: just ask nicely.
- superkuh 2mo agoYep. I've been with Namecheap for a similar length of time. This week they sent me an email saying I had to update my namecheap profile information or they would close my account in 24 hours. They locked my account so I couldn't log in. To be clear, my whois information was fullly legally compliant, and I was happy to also update my namecheap profile, but when I sent them an email they didn't get back to with an response email until there was just an hour left. Things had been going down hill slowly and lots of my peers have already moved on to porkbun, etc, but I think now things are going downhill quite fast. I did manage to save my account (and so domains) but now I will be moving to a new registrar.
- DANmode 2mo ago> saying I had to update my namecheap profile information or they would close my account in 24 hours. Did they mention what prompted this? Are you aware of anything?
- ramgine 2mo agoI got that same email but skimmed it. I guess I need to double check and then move.
- iAMkenough 2mo ago24 hours is a ridiculously short warning period, especially when they lock you out from meeting their demands yourself. What if their email got caught in a spam filter? What if you only check that inbox a few times a week or after business hours? I'll be moving my personal domains after doing some research.
- jddj 2mo agoThat sounds more like a phishing attempt than anything a real company should send. I think I have one domain left with them. I haven't received anything yet, but it's a good reminder to move on.
- ethin 2mo ago> That sounds more like a phishing attempt than anything a real company should send. And yet companies do it all the time. Which is hilarious because they also will happily tell you to beware of phishing and scams, but they do the exact same things a phisher/scammer would do
- happytoexplain 2mo agoJust a few weeks ago I moved from Namecheap to Porkbun. That's not an advertisement - I simply Googled popular registrars. But it is an indictment of Namecheap. They are going the way of GoDaddy. Please move away from them immediately. They are shifting to short-term strategies (high prices, immoral data practices, etc). Edit: Apparently they were bought by private equity just weeks before I noticed something was wrong. Not a coincidence, I'm sure. We need to legally destroy private equity takeovers. They are pure evil and nothing but a negative force, at least in the USA.
- rickydroll 2mo agoIs it time to change registrars already? I fled Gandi a while ago because of private equity fuckery. And now I need to go somewhere else. Who won't adopt enshitification-as-a-business-plan for a few years? No wonder people are leaving tech to go be goat farmers.
- chrismarlow9 2mo agoI am also looking for something that will last for a good while.
- js2 2mo ago> Who won't adopt enshitification-as-a-business-plan for a few years? I don't have a crystal ball, but NearlyFreeSpeech was recommended to me in 2010 and I've been using it since 2012. I don't think it's changed at all in that time. https://www.nearlyfreespeech.net/services/domains https://www.nearlyfreespeech.net/services/domains https://www.nearlyfreespeech.net/services/respect https://www.nearlyfreespeech.net/services/respect
- acidburnNSA 2mo agoTheir FAQ says they use Public Domain Registry to actually buy the domains. They are a wholly owned subsidiary of The Endurance International Group, who is owned by Clearlake Capital, a PE firm! So while it may shield you a bit, if you're moving from namecheap just to avoid PE then that may not be the most obvious choice. https://faq.nearlyfreespeech.net/q/difftos https://faq.nearlyfreespeech.net/q/difftos https://publicdomainregistry.com/about-us/ https://publicdomainregistry.com/about-us/ https://en.wikipedia.org/wiki/Clearlake_Capital https://en.wikipedia.org/wiki/Clearlake_Capital
- addaon 2mo agoWell, they didn't call it NameCompetent, did they?
- Retr0id 2mo agoThey're not even cheap these days, either. I'm still with them as a matter of laziness but I really need to migrate out.
- jolan 2mo agoCloudflare offers domain registration/renewal with no markup if you're looking for an option. I moved to them after AWS increased fees.
- appcustodian2 2mo agoi'm sure that will last
- fsuts 2mo agoIt’s a loss leader for their other products so it may well do
- The_Blade 2mo agonamechintzy.com is available
- dalmo3 2mo agoI've had the exact same issue with a small local registrar. Had an account where I managed multiple clients. One of the clients had their "IT guy" contact the registrar for a DNS change. The registrar promptly gave the guy full access to my account, changing the password and locking me out in the process. As soon as I regained access I moved everything off there.
- sixtyj 2mo agoDon’t be shy. Tell us the name. This is unacceptable and such companies should change their policy or be out of business.
- ivanmontillam 2mo agoAnd it wouldn't even be a defamation lawsuit because it's true.
- rmunn 2mo agoIn countries with a sensible legal system, yes. Truth is not a defense against defamation in all countries. I can't know what country you (generic you) are in, so best to look up your local laws on defamation.
- preg_match 2mo agoThis is basically sim swaps attacks or number porting attacks but for domains. If the telecos can figure it out, anyone can. Yes it took them way too long, but those attack vectors are essentially dead now.
- geuis 2mo agoI've been a long, long term customer of Namecheap as well. Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost. The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset. This clearly isn't an answer for NC's customer support personnel and company policies. But I've been a happy customer for many years and I discourage others from immediately reading other comments and rushing to jump to other registrars without doing your due dilligence. Remember that in any situation, the people most likely to leave negative comments and reviews are the people that have had genuine bad experiences or feel like they've been slighted, even if unwarranted.
- Thrashed 2mo agoI did have domain privacy enabled. NC allows people to initiate a password reset via username, email address, or domain name. I was a happy customer right up until this incident. And I certainly agree that due diligence is a must for something as critical as a registrar.
- geuis 2mo agoGlad you posted your experience. I'll definitely be keeping my eye out for shenanigans on my own domains.
- eviks 2mo agoHow will that help you prevent the transfer? The OP also "kept his eye out"
- blcArmadillo 2mo agoDid you have 2FA enabled too?
- system2 2mo agoPassword reset would bypass 2fa.
- phendrenad2 2mo agoAh namecheap. Stories about them make it to HN quite regularly: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=Namecheap&sort=byPopularity&type=story https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
- slig 2mo agoThis is the scariest https://news.ycombinator.com/item?id=30506581 https://news.ycombinator.com/item?id=30506581
- pilingual 2mo agoNamecheap has been owned by a private equity firm for several months now. It would be nice to have a nonprofit registrar so jumping every few years isn't necessary.
- viccis 2mo agoEnshittification and PE sellouts are great for DNS providers because migrating it can be a real pain sometimes and carry a high risk if something goes wrong. It's why so many of them are chains of "Buy through Company N! We used to work for Company N-1 before they sold out!"
- terribleperson 2mo ago...seriously? Where do I jump ship to now?
- deadalus 2mo agoPorkbun. Yes, Cloudflare Domains exists but let's support the small guys.
- cube00 2mo agoGiven Cloudflare's reputation for shakedowns once you pass their undisclosed thresholds I wouldn't trust them with my domains. I'm not expecting something for nothing, we all need to eat. I'm happy to stay within any limits or even have no free tier at all. I just don't want the fear of waking up to a sales email one morning demanding I suddenly fork out more then I earn in a year off the project for an enterprise plan because I've exceeded their undisclosed thresholds.
- ElijahLynn 2mo agoCan you expand more on cloudflare's shakedowns? I have some domains on Cloudflare and thought they were a trustworthy service. Is there there anything particular you can point to?
- linsomniac 2mo agoCloudFlare has their plusses and minuses, but they do offer domain registration at cost, for example $10.46/year for .com (every year, not one of those deals for the first year then more expensive down the line).
- sigio 2mo agoThe problem is that they then force you to use them as a DNS host as well.
- himata4113 2mo agoYou actually can use your own nameservers... if you pay for the business plan which is $2400/yr.
- system2 2mo agoI am totally fine with cloudflare DNS. There is nothing better with free tier out there. Can't beat $10.
- AussieWog93 2mo agoHonestly I don't really see this as a bad thing for the average person. I don't register my domains with CloudFlare, but I do all my DNS through them and it's great. Everything propagates in 10 seconds rather than 10 hours.
- greyface- 2mo agoIt boggles the mind that this is allowed by ICANN.
- foresto 2mo agoCloudflare has become a middleman and gatekeeper of the web, a single point of surveillance, and an enemy of the open internet. Giving them more business would make these problems worse. No thanks.
- paxys 2mo agoPeople are (rightfully) concerned about superintelligent AI but social engineering continues to be by far the biggest attack vector for digital infrastructure. And it’s being made worse by companies continuously cutting costs in areas like support. The call center employee making third world minimum wage doesn’t give a shit who the real owner of the domain is. They want to end the call quickly and get 5 stars from the customer on the feedback form. I have made it a point to move off services that force SMS-based 2fa for this exact reason. Recently even changed banks because of this.
- ethin 2mo agoHonestly I'm wayyy more concerned with social engineering attacks than some theoretically superintelligent AI. Social engineering is, IMO, the far worse of the too
- mook 2mo agoIsn't prompt injection basically social engineering for LLMs already anyway?
- ethin 2mo agoPretty much. Which is why I'm far more concerned about that. So many of the AI doomers are terrified of some super-intelligent autonomous AI doing something on it's own that wipes us out (and, mind you, they have no evidence that any super-intelligent AI would actually do that, other than si-fi, but that's a different topic). But there's nothing stopping us from doing something stupid like developing some super-intelligent AI that has yet to not have any reason to disobey the "help the user" and is subsequently socially engineered to do something horrible that ends up destroying a nation for example.
- Georgelemental 2mo agoSuperintelligent AI is getting very good at social engineering. See e.g. voice cloning scams
- preg_match 2mo ago
- hmokiguess 2mo agoHumans are the weakest link, wouldn't be shocked if it's some underpaid off shore call centre or whatever. That's not a vulnerability though, that is social engineering, the attack vector was a human and the exploit was a form of identity theft.
- assimpleaspossi 2mo agoScrolling through the current comments. In the meantime, been with NameCheap for I don't recall how long with no issues whatsoever.
- dessimus 2mo agoPost your domain and we can see if that is still the case in a few days.
- happytoexplain 2mo agoLack of a negative is the least compelling anecdote possible.
- assimpleaspossi 2mo agoHow about 16 years of lacking a negative? Does that count? How about never heard of any issues till this unverified, anonymous thread. Shouldn't that make one suspicious of it? Does that count?
- happytoexplain 2mo agoI don't understand where the anger is coming from. No, of course it's not as valid as positives (i.e. "I experienced X" vs "I never experienced X"). See also: "Works on my machine." I used Namecheap since 2011. This year, they lost me. The only difference between you and me is one bad experience.
- xyst 2mo agoNotably, they have been bought out by private equity. > September 2025, CVC Capital Partners acquired a majority stake in Namecheap for an undisclosed amount, valuing the company at $1.5 billion.[3][4] Kirkendall stepped down as CEO on December 16, 2025 But prior to this they have had many incidents. Switched all domains to porkbun a few years ago
- codegeek 2mo agoOH no. This is really bad news. Gotta think of alternatives now. I never had a single hosting/software company that got better after being bought by PE. They got 1000x worse in a few months since PE take over.
- ryandrake 2mo agoThis kind of story makes me wonder what's the most popular/valuable domain I can take control of simply by being convincing over the phone. Sounds tempting! I can't even log in to most web sites anymore without doing a side-trip to my E-mail inbox, "for enhanced security," but these clowns let you just take a domain by asking nicely!
- jacobgkau 2mo agoBe careful, I assume there are laws on the books that normal people wouldn't know about but a large enough target could use if you tried to pull this on them (or you could find yourself on the receiving end of a civil lawsuit).
- nkrisc 2mo agoIn many countries that’s probably illegal, even if it’s easy. Just because a crime is easy to commit doesn’t mean it isn’t a crime. So, keep it hypothetical.
- paxys 2mo agoI can’t think of a jurisdiction where it would not be illegal. The “I was only testing your security, in fact I should get rewarded for it” defense never works outside of nerd fantasies.
- nkrisc 2mo agoI agree, it’s likely illegal in any modern state with rule of law. But I don’t actually know that for sure.
- arendtio 2mo agoHonest citizens think like that; others wonder what the punishment is, even if it is illegal. I mean, maybe paying a fine vs maybe getting access to a popular domain? At least corporations seem to work like that. Not following the law seems completely okay as long as the fine is not X% of their annual turnover.
- richardchilders 2mo agoNamecheap forces users to log in to identify themselves. So far, OK. But then when one attempts to pay for a domain, after one has already provided all of one's credit card information to Namecheap ... Namecheap up and refers its customers to something called Link, which forces Namecheap's customers to create an account and become Link's customers - providing all that confidential credit card information, all over - leaving the customer wondering why Namecheap collected it and what they are going to do with it. Link forces you to authenticate via SMS so that they know where you are. This all happened less than 24 hours ago and I was already getting ready to put domain service shopping on my list of things to do but I'm glad to see I'm not the only one. I nominate Paul Vixie as a possible candidate for CTO or even CEO of a hypothetical nonprofit DNS domain service. More info: uggcf://fnynanir-ehalba.bet/ureovr.ugzy
- Walf 2mo agoLink is just payments processing done by Stripe. https://stripe.com/payments/link https://stripe.com/payments/link If you've bought anything online recently, especially if it's not obvious who's collecting the payment details or it looks like first party on the checkout page, you've probably used Stripe.
- ryandrake 2mo agoBut in those cases you don't have to sign up for it, or create an account with SMS verification. That should be totally unacceptable. Imagine going to a grocery store and when you want to buy your pack of soda and chips, they tell you: Woah there, pardner! You need an account with MyPaymentProvider before you pay for those groceries! Oh, and you'll need to set up a password and give them your mobile number...
- Walf 2mo agoYeah, I don't love it. Forcing phone numbers is the worst, as I've practically never needed to call or be called about a purchase, but it's a de facto ID.
- 2mo ago
- sandeepkd 2mo agoIn the absence of actual details its hard to say what was considered for making this decision. If I have to take a wild guess then being able to demonstrate the control on the webserver hosting the content could have been one way to prove ownership over the domain. It can be called social engineering, however one can also put it in category of account recovery by verifying content control on the domain. The part where it gets hairy is if your credit card was associated with the account, thats probably a recipe for disaster?
- maxgashkov 2mo agoWebserver control is never used and must not be used to prove domain ownership. If you're pwned and have to re-point to a server stood up from backup, having registrar relying on someone being able to put up a random file on a compromised machine would be a total security disaster.
- sandeepkd 2mo agoTo clarify, my observation is around how it might have happened, not if this is the right way to do it
- sandeepkd 2mo agoOn a different note, adding a file on webserver is one of the ACME methods (HTTP-01) to get a SSL/TLS certificate so it is indeed considered as possession method in real world already
- maxgashkov 2mo agoYou're missing that HTTP-01 challenge grants you no ability beyond what the check has demonstrated, i.e. you have proven that you're able to serve random file from a webserver, so the grant is to allow you to serve them via TLS connection. There are no comparable _technical_ proof-of-registration methods because all of them would require actual access to registrar control panel and be outright silly ('point the domain to a random nameserver'). So no, proper registrars never use webserver control as means to prove identity or ownership.
- OutOfHere 2mo agoIt was not declared whether 2FA was enabled on the account or not. I will assume that it wasn't enabled.
- mook 2mo agoHmm, I don't know the area well; why would 2FA have been relevant here? From the (unverified) story, the account was administratively handed over via support; there was no indication from any party that the account was hacked. So 2FA prompts would never be part of the picture.
- john_strinlai 2mo agoa support-initiated reset and transfer would bypass 2fa
- Georgelemental 2mo agoI left Namecheap when they took away Databases for Palestine's domains for daring to publish evidence of the Gaza genocide. They do not deserve your business https://www.thecanary.co/skwawkbox/2026/01/03/namecheap-gaza/ https://www.thecanary.co/skwawkbox/2026/01/03/namecheap-gaza...
- h0mie 2mo ago[dead]
- velcrohn 2mo agoSince you brought it up... The population of Gaza has been going up since 1948. Before Hamas attacked, tens of thousands of Gazans had work permits in Israel, and many Gazans were treated in Israeli hospitals. After Hamas started a war, Israel provided food, power, water, fuel, and medicine with intermittent interruptions. They had ceasefires to provide vaccines for children. Israel warned civilians of imminent attacks, and generally gave them time to move. That rarely happens in a war, never mind a genocide. It is absolutely true that tens of thousands of civilians were killed, although it is difficult to quantify because Hamas soldiers do not wear uniforms and has 100% of its military capabilities around and below hospitals, mosques, schools, and apartments. Also, Gazan authorities have never distinguished military and civilian casualties in their reporting. And despite having the world's largest bomb shelter, i.e. 500 km of tunnels, Hamas did not allow a single civilian into them during the war. But stipulating tens of thousands of civilian deaths during an intense urban fighting, there is a name for that. The name for that is "war". Genocide is an entirely different phenomenon. You seem to conflate the two.
- Georgelemental 2mo agoAbout my use of the word "genocide": genocide is defined not primarily by the scale of the killing, but most importantly by the intent behind it. The intent of the war on Gaza, as expressed repeatedly by the people prosecuting it, is to destroy the Palestinian people as a people. That's what makes it a genocide, not just the raw number of dead. https://www.un.org/sites/un2.un.org/files/doc.1_convention_on_the_prevention_and_punishment_of_the_crime_of_genocide_0.pdf https://www.un.org/sites/un2.un.org/files/doc.1_convention_o... (In the interest of keeping things on topic for HN, I won't respond to your other points)
- bschmidt2000 2mo ago[dead]
- n8n_and_coffee 2mo agoThis is disheartening to hear. This year I began slowly switching my domains to NameCheap from Godaddy before renewal because of the huge difference in price plus the added NameCheap free stuff Godaddy charges extra for. I guess there's a reason NameCheap is cheap :( Was your domain in 'locked' status, preventing transfers etc?
- system2 2mo agoIf the price is your concern, the Cloudflare registration is only $10.
- bel8 2mo agoI moved my domains from GoDaddy to NameCheap some years ago. And recently from NameCheap to Cloudflare once I heard NameCheap changed owners. So far, so good. If Cloudflare messes up my domains, of all things, I might as well quit tech and become a farmer.
- Thrashed 2mo agoYeah the domain was/is locked. The domain wasn't transferred - the NC account that owned the domain was handed over. I also moved from Godaddy to NC. For me it was 2013 when GoDaddy supported SOPA.
- Adachi91 2mo agoI moved from Namecheap 2 years ago when I had auto renew on but it did not auto-renew, which their system automatically turns your domain into an advertisement hell page. Transfer system was locked and I contacted them and told them to transfer it to my other registrar or I would file an ICANN complaint. I moved it to my main registrar (Hover) which while more expensive I haven't a problem with them in the decades I've been with them. My original registrar shutdown sometime in the mid 2000s and Hover picked up my domains, so I'm all in over there now.
- terminalbraid 2mo agoporkbun is really good
- system2 2mo agoI have important domains on Namecheap. Should I move them to Porkbun or Cloudflare? I only buy cheap, throwaway-type domains with Cloudflare, as I find them too corporate-like to support me for my cheap $10 domain, and that's why I kept good ones with Namecheap despite their 2x pricing. I want to work with an American company with real support. (But not with godaddy of course).
- happytoexplain 2mo agoPorkbun seems to be the current "correct" choice. That may change in one year or 10 years - but that's just how business works in the 21st century.
- jacobgkau 2mo agoFor what it's worth, I have had brief one-on-one contact with Porkbun support once. Their checkout was failing when using PayPal one day, and a seemingly real person emailed in response to my ticket about an hour and a half later to let me know they'd corrected the issue.
- assimpleaspossi 2mo agoIf you ignore this thread, did you even consider it before now? I've been with Namecheap for at least 16 years but this is the first I've read of complaints and never had any complaints myself. Which should make one question this whole thing altogether.
- slig 2mo agoI believe you did not see this https://news.ycombinator.com/item?id=30506581 https://news.ycombinator.com/item?id=30506581
- assimpleaspossi 2mo agoSo now you need to dig into another anonymous post from over four years ago with no details of what happened?
- prmph 2mo agoYep, never own a domain with NameCheap. My experience was kind of opposite, but still bad nonetheless. I lost domains I had with them simply because I lost the phone I used for 2FA. After several calls to them, they requested some info. I supplied all they wanted, but it took them more than a year to get back to me, by which time I had lost all interest in maintaining domains with them. Luckily these were not critical domains; I had bought them in anticipation of building a business on them. I am moving my domains to CloudFlare.
- captn3m0 2mo agoNamecheap also suspended my primary domain because of a bug at their end: https://captnemo.in/blog/2026/05/05/namecheap-whois/ https://captnemo.in/blog/2026/05/05/namecheap-whois/ tl;dr: Namecheap configured Domain Privacy on my domain, which isn't allowed by my Registry (.in), and then suspended my domain coz the whois info was redacted. I know a few other people that were impacted.
- jacobgkau 2mo agoI stopped trusting Namecheap when they shunted all Russian users due to the Ukraine war. While it wasn't against ICANN regulations (since they did facilitate transfers out), it seemed against the spirit to me for them to do that to individual people and small businesses who weren't legally sanctioned. I kept a couple of domains on them for a while simply because their prices for some exotic TLD's were significantly lower than my previous go-to of Hover, but now Porkbun's got them beat on everything I use, anyway, so I'd transferred the last of them out over the past year or so.
- slig 2mo agoYes, and also this https://news.ycombinator.com/item?id=30506581 https://news.ycombinator.com/item?id=30506581
- bellowsgulch 2mo agoI also didn’t like that, said as much, and had a bunch of people downvote me because I said I didn’t want my utility company playing politics.
- dvdyzag 2mo agoI'm chuckling nervously. Previous discussion from 2022: https://news.ycombinator.com/item?id=32638028 https://news.ycombinator.com/item?id=32638028 Something about a bounty, the original source is down.
- petecooper 2mo ago+1 for Porkbun. I use tld-list.com to shop around for registrars when I need a TLD that Porkbun don't handle.
- luciana1u 2mo ago[flagged]
- bellowsgulch 2mo agoI’m not moving my business domains to a small business called Porkbun.
- ButlerianJihad 2mo agoSo, reading through the holes in your story: you are not a leader of this club, nor a member, nor affiliated with the college at all. And the domain name wasn't actually "in use" but parked. And the legitimate leadership of the college-affiliated club was able to prove to NameCheap that they had a right to the domain name, as it was (not a right to your account, but a right to their club's name on the Internet). And NameCheap cooperated in turning over control to those with legitimate rights to it, rather than whoever's credit card was on the last payment? Am I in the ballpark here so far? Perhaps NameCheap did have ways of knowing who the rightful owner was, and who you are not--especially if it was a personal account, not a "college affiliated" or "faculty" account! In your headline, you call the club leadership "an unverified third party" but the college, and the club, and its leadership are, in fact, a first party to this domain and its transactions, while you are the third party, and you also have no idea what verification steps were taken by NameCheap on behalf of the rightful owners, the college, the leadership, or their personal identities. You have no idea about what they did with that. It's not your domain, and you're complaining about losing something that was never yours to begin with. So you helped pay for it. That was a mistake. The way you pay for club assets: your club has a treasurer, and your club has a "purse" or club account, and your club writes the checks. You wanna pay for something, make a donation to your club and/or college. Thankfully, it looks like the mistakes have now been rectified.
- kstrauser 2mo agoThis is bullshit. There are legal processes in place to decide disputes. Absent those processes, possession is ownership, and it would be absolute madness and chaos if it weren't. I could make pretty convincing letterhead "proving" that I own "Google Foods", but that doesn't mean a registrar should give me google.com. The correct process if I want to assert that is to sue for ownership and prove to a court that I'm the rightful owner, and to get an order compelling the registrar to transfer it to me. And if I can't, then Google gets to keep it. This is the only possible sane way to manage domain ownership.
- ButlerianJihad 2mo ago> legal processes in place Another hole in OP's story: when/how did they follow the legal dispute process, rather than just "shooting a couple emails" and creating a new HN account to complain about it?
- userbinator 2mo agoPosted by a 3-hour-old account (as of this comment), and then multiple mentions of the same competitor in the other comments here. Make of that what you will...
- happytoexplain 2mo agoIt's normal for people to make accounts to express grievances. And it's normal for a registrar bought by private equity to begin slowly enshittifying. And Porkbun is very clearly the next most popular choice, regardless of this thread. In fact, it's even been pointed out that they may be the next to enshittify - not something a shill says. I.e shilling skepticism is not rational in this case.
- userbinator 2mo agonot something a shill says. Shilling has moved on from being 100% positivity, precisely because it's too obvious otherwise.
- squigz 2mo agoThe community response here is actually fascinating to me. I would have expected at least some responses pointing out that this sounds far too bad to be true, and asking what parts of the story are we missing, as has happened when other stories like this show up.
- thegrim33 2mo agoThe same namecheap that at the outset of the Ukraine war decided to terminate the service of every single one of their customers (private citizens, businesses, everyone), that had a Russian address associated with their account? Well, if you're still using them, that's on you.
- newsomix9xl 2mo agoI'd say asking nicely is a kind of social engineering. It may not be some Mitnick level impersonation of a Senior VP on vacation needing an urgent change kinda trick but the point of S.E. was that it played on the human element and namely cooperation of same. How it was obtained was not strictly defined AFAIK.
- deleted 2mo ago[deleted]
- kcartlidge 2mo agoEveryone has different requirements and experiences. I switched to Moniker about 4 or 5 years ago and have about a dozen domains there. Never any issues, and a reasonable system.
- MetroWind 2mo agoI mean "cheap" is in the name...
- antrichards 2mo ago[flagged]
- gsofie_sec 2mo ago[flagged]
- famous1470 2mo ago[flagged]
- thr0w__4w4y 2mo agoHate to do a hit & run post but here we go... Both AT&T and Apple transferred (albeit both temporarily) ownership of my phone # (AT&T) and my Apple ID (OK you know the company) from purely social engineering. The AT&T one was basically like this post. A phone call with a convincing person. Eventually (through threat of legal action) I was able to listen to the recorded call where it happened, and it was simultaneously infuriating and fascinating. The Apple one was more sophisticated. Too much to write here, but essentially to pull it off all the thief needed to do was have Apple call my number on file and have me answer it. I suspect I know the attack vector, but all I got from Apple was a very quick reversal, not an apology but an acknowledgment, and an explicit message that the details on their end wouldn't / couldn't be shared b/c of corporate policy (which honestly I think makes some sense if a novel vulnerability via social engineering has been found & exploited). "The meatbag in the loop is the weak link" is said often, isn't always true... but sometimes it is indeed. N.b.: I work in firmware & electronics security & cryptography.
- asanchezt85 2mo ago[flagged]