5 ms·
I did have domain privacy enabled. NC allows people to initiate a password reset via username, email address, or domain name. I was a happy customer right up u
by Thrashed 2mo ago
I did have domain privacy enabled. NC allows people to initiate a password reset via username, email address, or domain name.
I was a happy customer right up until this incident. And I certainly agree that due diligence is a must for something as critical as a registrar.
- geuis 2mo agoGlad you posted your experience. I'll definitely be keeping my eye out for shenanigans on my own domains.
- eviks 2mo agoHow will that help you prevent the transfer? The OP also "kept his eye out"
- blcArmadillo 2mo agoDid you have 2FA enabled too?
- system2 2mo agoPassword reset would bypass 2fa.
- throwaway219450 2mo agoI’ve reset 2FA with a known password and it was pretty onerous. Had to provide a lot of info: username, full name on account, other domains, phone number, order number, email, invoice IDs and payment proof. Asking for my legal ID would have been an improvement, but someone would need a lot more than “pretty please” on the phone.
- deleted 2mo ago[deleted]
- Thrashed 2mo agoYes it was enabled but it's unclear to me how effective it would've been in this case. I attempted to login after support changed the password, but prior to the club president connecting with me. So I filed a support ticket that my password stopped working, and to NameCheap's credit they locked the account shortly thereafter. I worked with support later to regain access. I don't know for sure if the club president was able to successfully auth with the new password before NC locked the account at my request. To be completely transparent, keeping this domain on my personal account was a legacy arrangement that probably should have been handed off sooner. Student club turnover being what it is, I was just renewing it so it wouldn't get squatted. We are fully transferring ownership to them now so there's no friction. It's fair to criticize this arrangement as messy. Regardless, NC shouldn't have simply handed over the account to an unverified phone caller.