Skip to content
HN On Hacker News ↗

Namecheap Gave My Account to an Unverified Third Party Just Because They Asked

▲ 349 points 129 comments by Thrashed 4h ago HN discussion ↗

Pangram verdict · v3.3

We believe that this document is fully human-written

0 %

AI likelihood · overall

Human
100% human-written 0% AI-generated
SEGMENTS · HUMAN 5 of 5
SEGMENTS · AI 0 of 5
WORD COUNT 1,966
PEAK AI % 0% · §5
Analyzed
Jul 23
backend: pangram/v3.3
Segments scanned
5 windows
avg 393 words each
Distribution
100 / 0%
human / AI fraction
Verdict
Human
Pangram v3.3

Article text · 1,966 words · 5 segments analyzed

Human AI-generated
§1 Human · 0%

Namecheap has been owned by a private equity firm for several months now.It would be nice to have a nonprofit registrar so jumping every few years isn't necessary. The problem is that they also need to be big enough not to be rolled by aggressive behaviour such as lawsuits, pressure from politicians, etc. I mean, some of my domains are at a tiny company run by geeks, but I wouldn't really blame them for caving if someone really put the heat on them.There's a certain threshold above which you want to use the "law firm with in-house domain registry" type. I think the threshold is pretty high though, definitely "call us for a quote" territory. But you will notice that big companies like Amazon and Google that have their own registry, don't use it for their critical domains - such as Google.com or Amazon.com. I heard some advice recently, I think in an article here on HN, to just use a big company registry where it's not their profit center, indeed may even be netural to loss making, to drive other business.This makes total sense to me. I'm not saying it solves all problems but it eliminates so many of them, including a meta problem: the risk of new classes of problems being unexpectedly introduced (by say a private equity acquisition or similar).If domains themselves are the profit center, you are likely in trouble if there's really any incentive for them to make incremental revenue in such a competitive market. Doing 'the right thing' just of course will not factor in if there's really no reputation at stake. The only problem with this is that having such a complex function as a non-core business unit makes it ripe to get rid of, or try to find a way to make it a profit center.Cloudflare, for example, removed the ability to change the nameservers for all domains registered with them.Google got tired of being in the business and sold it to Squarespace.Being a domain registrar is a total PITA and is not for the faint of heart, so it's the sort of thing that any business that takes it on as a non-core function will eventually tire of. As someone still smarting from the loss of Google Domains, I would consider this advice carefully.When domains are not the profit center the company might just arbitrarily turn them off as a feature. > Namecheap has been owned by a private equity firm for several months now.

§2 Human · 0%

Namecheap's cavalier attitude long predate private equity, let's stop blaming the evil financiers for everything. I'm sure it's going even further downhill from here because of it, but what happened to OP happened to others before as well and is par for the course when being a namecheap customer. I've been with VentraIP in Australia for a decade now.They're not necessarily better or worse than any other provider (I'm assuming support is good and local but I've never needed it), but they're based in Melbourne - so if push comes to shove I can physically go over there and speak with them directly.Same thing with my payment provider, after a Stripe snafu. For something as basic as domain name registration, absolutely. It takes someone willing to be a bit philanthropic to do it, I guess. Given Cloudflare's reputation for shakedowns once you pass their undisclosed thresholds I wouldn't trust them with my domains.I'm not expecting something for nothing, we all need to eat. I'm happy to stay within any limits or even have no free tier at all.I just don't want the fear of waking up to a sales email one morning demanding I suddenly fork out more then I earn in a year off the project for an enterprise plan because I've exceeded their undisclosed thresholds. Can you expand more on cloudflare's shakedowns? I have some domains on Cloudflare and thought they were a trustworthy service. Is there there anything particular you can point to? I think they're referring to the Enterprise sales where people have felt pressured to sign six- or seven- figure contracts after usage goes above a certain point. However, all the articles I've read on it are from companies using Cloudflare to do suspicious things with rotating domains through IP addresses, or doing things to try and get around service costs. It also seems like they give you months of warning and will try to convince you to sign up for Enterprise, they don't just shut things off. But their sales team seems to portray themselves as legal, support, or compliance teams sometimes so not exactly forthcoming in their approach either.I'm a happy user of Cloudflare, but if you're using it for domain registration and hosting infrastructure, you need to see it as a single point of failure. Any account issues and you won't be able to point your domain to an alternate host while you work things out.

§3 Human · 0%

Any service outage in CF systems will similarly lock you out of routing around the failure. It's better to have DNS off of cloudflare if they're handling your hosting services also. Or host elsewhere and only handle domains on cloudflare. Their domain pricing doesn't add any costs over the base registrar cost, so the latter is a reasonable option. https://news.ycombinator.com/item?id=40481808You could argue in that case it was a gambling site and it will never happen to you because you're not in a high risk category. The scary thing for me is nowhere in their initial communications did they explain the issue they just demanded large sums of money immediately.The other part that feels shady is the way their sales team represented themselves as "business development" initially and when that didn't result in a sale they represented themselves as the "trust and safety" team. It's just traffic based: sales try to get you on a paid plan, or a higher tier. For some accounts they've given ultimatums ("pay for the higher tier by x date or we have to stop providing service"). But I believe those cases were e.g. online casinos doing specific things with the platform (say, evading national blocks on gambling websites) IIRC. It would be worth recommending a non-US-based registrar, since the Texas government just demonstrated that they can unilaterally suspend any domain managed by any US registrar. They say they started in 2002, but same here, I've had hundreds of domains on Dynadot since the early 2000s with no problems. Two more are NearlyFreeSpeech and UnstoppableDomains.The latter also supports crypto domains which have no chance of a takeover except by government order, although crypto domains require the client to install a browser extension or other software to resolve. The good thing about crypto domains is that there should be no renewal fee, although there will be a fee to update the record. Seconding the NFSN recommendation, they are great if you are technically competent. They even have optional security settings that can permanently lock you out of your account if you lose your recovery credentials, in case you want to be super strict about it. They are very clear that recovery will be impossible if you use those settings. I really like this and wish more services would offer this kind of “hard” commitment.

§4 Human · 0%

Enshittification and PE sellouts are great for DNS providers because migrating it can be a real pain sometimes and carry a high risk if something goes wrong. It's why so many of them are chains of "Buy through Company N! We used to work for Company N-1 before they sold out!" This kind of story makes me wonder what's the most popular/valuable domain I can take control of simply by being convincing over the phone. Sounds tempting!I can't even log in to most web sites anymore without doing a side-trip to my E-mail inbox, "for enhanced security," but these clowns let you just take a domain by asking nicely! In many countries that’s probably illegal, even if it’s easy. Just because a crime is easy to commit doesn’t mean it isn’t a crime.So, keep it hypothetical. Be careful, I assume there are laws on the books that normal people wouldn't know about but a large enough target could use if you tried to pull this on them (or you could find yourself on the receiving end of a civil lawsuit). I've been a long, long term customer of Namecheap as well.Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost.The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset.This clearly isn't an answer for NC's customer support personnel and company policies.But I've been a happy customer for many years and I discourage others from immediately reading other comments and rushing to jump to other registrars without doing your due dilligence.Remember that in any situation, the people most likely to leave negative comments and reviews are the people that have had genuine bad experiences or feel like they've been slighted, even if unwarranted. Namecheap's privacy WHOIS still shows a unique email address so that the owner is reachable. Sending mails to it would have been forwarded to OP. How is domain privacy relevant here? That only hides your email from public records. What if the attacker already knows it (as they did in this case)? Email address is quite literally something you are meant to share publicly.

§5 Human · 0%

It is not a password. I think their point was that if WHOIS data were hidden, a password reset request that relied on providing the email address would've been impossible. But since NC's account management allows visitors to provide just a domain name to generate an unlock email, domain privacy wouldn't be a protective layer here. Seems pretty relevant to a social engineering attack to have more correct pieces of info to give to support. I did have domain privacy enabled. NC allows people to initiate a password reset via username, email address, or domain name.I was a happy customer right up until this incident. And I certainly agree that due diligence is a must for something as critical as a registrar. Glad you posted your experience. I'll definitely be keeping my eye out for shenanigans on my own domains. Yes it was enabled but it's unclear to me how effective it would've been in this case.I attempted to login after support changed the password, but prior to the club president connecting with me. So I filed a support ticket that my password stopped working, and to NameCheap's credit they locked the account shortly thereafter. I worked with support later to regain access.I don't know for sure if the club president was able to successfully auth with the new password before NC locked the account at my request. To be completely transparent, keeping this domain on my personal account was a legacy arrangement that probably should have been handed off sooner. Student club turnover being what it is, I was just renewing it so it wouldn't get squatted. We are fully transferring ownership to them now so there's no friction.It's fair to criticize this arrangement as messy. Regardless, NC shouldn't have simply handed over the account to an unverified phone caller. I’ve reset 2FA with a known password and it was pretty onerous. Had to provide a lot of info: username, full name on account, other domains, phone number, order number, email, invoice IDs and payment proof. Asking for my legal ID would have been an improvement, but someone would need a lot more than “pretty please” on the phone. > Asking for my legal ID would have been an improvementI work with a number of streamers and esports-adjacent individuals.