4 ms·
At the end of the post he seems quite snarky and bad mouthing namecheap's security for things that aren't even their fault or even security issues. > The VPS p
by johnnyfaehell 10y ago
At the end of the post he seems quite snarky and bad mouthing namecheap's security for things that aren't even their fault or even security issues.
> The VPS panel allows full serial console with only a login/password (no 2FA required or possible)
Yea that's because it's a serial console, if you want 2FA or something then that's a matter for your operating serivce. A serial console is literally like you're plugged directly into the machine.
> They send out your VPS panel login/password in plain text emails when you sign up, and when you reset the password. So if you ever failed to delete one of those emails completely and someone gets into your email…your totally screwed…
To be fair this is pretty standard. It's your job to secure your passwords once they've given them to you. If they're storing it in plain text then you can complain but this basically sounds like you're complaining that they're not encrypting emails. Sure they could only show you it once when you boot it up. But since this action was done via customer support they would have to give you the password some how. To your email address the most secure other than the chat which can be by an attacker like it was in this case.
> VPS can be irrevocably wiped within seconds without any prompts or confirmations just by the click of one button; whether the server is turn on/off it doesn’t matter.
This isn't a security issue. A UX issue yea, but it's not even that big of a deal. It's in an area you won't be that often and where you know you're doing admin related thing.
> They keep no backups, even to cover hardware or security failure.
This isn't a security issue. It's your job to back up your stuff not a VPS provider.
> And of course the icing on the cake is that they ignore 2FA and are willing to send out your username/password to anyone that asks.
Yep. Pretty valid.
- dougmany 10y ago>> They send out your VPS panel login/password in plain text emails >To be fair this is pretty standard. This practice has always bothered me. An expiring link to reset is much better.
- jimktrains2 10y ago> Yea that's because it's a serial console, if you want 2FA or something then that's a matter for your operating serivce. A serial console is literally like you're plugged directly into the machine. Which, once the machine is up, is basically just exporting getty and exposing the system login prompt. Why couldn't the system login prompt require 2FA. Mostly for historical reasons I'm assuming, but just because it's serial doesn't mean it isn't just some software on the other end.