6 ms·
I've been a long, long term customer of Namecheap as well. Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included b
by geuis 2mo ago
I've been a long, long term customer of Namecheap as well.
Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost.
The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset.
This clearly isn't an answer for NC's customer support personnel and company policies.
But I've been a happy customer for many years and I discourage others from immediately reading other comments and rushing to jump to other registrars without doing your due dilligence.
Remember that in any situation, the people most likely to leave negative comments and reviews are the people that have had genuine bad experiences or feel like they've been slighted, even if unwarranted.
- Thrashed 2mo agoI did have domain privacy enabled. NC allows people to initiate a password reset via username, email address, or domain name. I was a happy customer right up until this incident. And I certainly agree that due diligence is a must for something as critical as a registrar.
- geuis 2mo agoGlad you posted your experience. I'll definitely be keeping my eye out for shenanigans on my own domains.
- eviks 2mo agoHow will that help you prevent the transfer? The OP also "kept his eye out"
- blcArmadillo 2mo agoDid you have 2FA enabled too?
- system2 2mo agoPassword reset would bypass 2fa.
- throwaway219450 2mo agoI’ve reset 2FA with a known password and it was pretty onerous. Had to provide a lot of info: username, full name on account, other domains, phone number, order number, email, invoice IDs and payment proof. Asking for my legal ID would have been an improvement, but someone would need a lot more than “pretty please” on the phone.
- deleted 2mo ago[deleted]
- Thrashed 2mo agoYes it was enabled but it's unclear to me how effective it would've been in this case. I attempted to login after support changed the password, but prior to the club president connecting with me. So I filed a support ticket that my password stopped working, and to NameCheap's credit they locked the account shortly thereafter. I worked with support later to regain access. I don't know for sure if the club president was able to successfully auth with the new password before NC locked the account at my request. To be completely transparent, keeping this domain on my personal account was a legacy arrangement that probably should have been handed off sooner. Student club turnover being what it is, I was just renewing it so it wouldn't get squatted. We are fully transferring ownership to them now so there's no friction. It's fair to criticize this arrangement as messy. Regardless, NC shouldn't have simply handed over the account to an unverified phone caller.
- paxys 2mo agoHow is domain privacy relevant here? That only hides your email from public records. What if the attacker already knows it (as they did in this case)? Email address is quite literally something you are meant to share publicly. It is not a password.
- vel0city 2mo agoRegistration info usually also includes a physical address and names.
- john_strinlai 2mo agoi agree that's important to hide, but also irrelevant to preventing what happened here.
- 0x3f 2mo agoSeems pretty relevant to a social engineering attack to have more correct pieces of info to give to support.
- john_strinlai 2mo agoby "what happened here" i mean this specific post. in this specific post, address information was not required.
- 0x3f 2mo agoThat's not clear to me. > He convinced them the domain registered in my name and address really belonged to his club Convinced how? Often such things are via "knowing things" about the account holder.
- john_strinlai 2mo agothe author explicitly said they had domain privacy on. so we know that the caller did not have the address information. and we can be certain that domain privacy wouldn't have helped in this case (because it didn't). https://news.ycombinator.com/item?id=49028611 https://news.ycombinator.com/item?id=49028611 >Convinced how? Often such things are via "knowing things" about the account holder. i have some experience with social engineering attacks (former infosec turned teacher) and it was probably a combination of: - caller confidence that they were the club owner/manager (because they were) - offering/sending club-specific information that matched information on the site (flyers, pamphlets, etc.) - "call the number on the website and i will answer it" - an official college website page that had the caller listed as an owner/manager of the club - some poor 20-something year old working in a hellish, windowless tier 1 tech support center
- tredre3 2mo agoNamecheap's privacy WHOIS still shows a unique email address so that the owner is reachable. Sending mails to it would have been forwarded to OP.
- happytoexplain 2mo agoAgreed - I switched away from Namecheap, but do research. Don't just switch because a couple people on HN did.
- palmotea 2mo ago> Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost. That's not exactly true. IIRC, it's not allowed for .us domains.
- turpentine 2mo agohttps://bsky.app/profile/neocities.org/post/3mnkqgxostk2k https://bsky.app/profile/neocities.org/post/3mnkqgxostk2k - This is recent and inexcusable sloppy work for a domain registrar. Private equity explains it if they're cutting and offshoring operations. Even if they hadn't been acquired by PE, it is still inexcusable. They didn't even bother to respond publicly to explain how it happened and that they're course correcting.
- fsuts 2mo ago>Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost. Many/most domain registrars now give free domain privacy, so that’s not a reason to stay with namecheap. Namecheap renewal rates are also higher than many others so surprises you have stayed and paid above market rates