24 ms·
Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
- kingofkyiv 4y ago
- sva_ 4y ago> kingofkyiv.com > buyagf.com What the hell am I looking at?
- smt88 4y agoMy best guess for the second one is "human trafficking".
- sph 4y agoOr perhaps a Runescape fan. "buying gf, 100 gp" I wonder if they also have an armour trimming service.
- teeceetime2 4y agoI became overwhelmed with osrs flashbacks after reading this
- smt88 4y agoLook at the person's comment history. He seems to be very sincere about wanting to sell women to people.
- kingofkyiv 4y agoAbsolutely not. The women are willing and come to me to help them leave Ukraine and move elsewhere. I screen my clients with background checks and proof of income. Mail order bride is more appropriate.
- metadat 4y agoThe kingofkyiv account frequently tries to plug their sketchy eastern-european-women-"love"-connection huckster website on HN. Preying on desperate nerds could be profitable.
- shepherdjerred 4y ago
- renewiltord 4y agoLOL the hand wringing over this is dumb. If he hadn't made this tweet and his service was hackable you think people wouldn't? The gain is quite a bit higher than $10k for the right domain. Give me a break.
- prvit 4y agoWhat a weird thing to get excited about.
- rvz 4y agoHardly surprising if one admits to being a "23 years old", "mentally ill, "anarchist kitten". So many deranged folks on Twitter these days.
- tennisflyi 4y agoPoorly worded bounty, IMO.
- debacle 4y agoNamecheap is good. They are my registrar, even though Amazon would be easier, because their support + personability makes me feel like I'm dealing with human beings. They are the Linode of the domain space.
- deleted 4y ago[deleted]
- gnomesteel 4y agoGuess I should move elsewhere. What is everyone using for domains and DNS these days?
- mario_kart_snes 4y agoNameSilo or Cloudflare
- bombcar 4y agoAs for Cloudflare I'd recommend NOT hosting your DNS with your domain name provider, just in case one of them does something stupid (but often if your domain goes sideways there's not much you can do anyway ...)
- jaywalk 4y agoLike you said, if your registrar shuts down your domain it doesn't matter where your DNS is hosted. So your recommendation makes no sense.
- that_guy_iain 4y agoTime to move somewhere else because the CEO is so confident they can't be hacked he publically offers money to anyone who can do it? You want to be with one that thinks it is insecure?
- gnomesteel 4y agoNot exactly. The Namecheap dashboard has become annoying, and the only thing keeping me there is their customer service.
- nebukadnet 4y agoIsn't this standard procedure for big companies? If you point out flaws in their security they will give you a reward. https://www.techtimes.com/articles/271004/20220125/apple-rewards-student-100-500-discovering-mac-webcams-hacked.htm https://www.techtimes.com/articles/271004/20220125/apple-rew... https://www.pcgamer.com/security-researchers-aka-hackers-make-dollar800k-prize-money-for-exploiting-windows-11-and-teams/ https://www.pcgamer.com/security-researchers-aka-hackers-mak...
- sp332 4y agoYou're not supposed to cause actual substantive changes to actual customers. In addition to being questionably ethical, that would usually disqualify a researcher from any possible bug bounties and forfeit legal protections offered by the program.
- CodesInChaos 4y agoHacking accounts without consent of the victim is probably illegal. So normally you'd use an account you own (or your friend/colleague owns), but the challenge is excluding those. The company setting up special test accounts can be a good option as well, but needs to be done in good faith and is problematic when the attack is social engineering based. So the challenge is either giving attackers permission to hack accounts of strangers, or requires the attacker to engage in potentially illegal behaviour. Neither of which is acceptable. I assume this is just badly phrased, and what was actually intended was a requirement that the victim doesn't collude with or help the attacker.
- zdragnar 4y agoNot really, they don't often advertise that you should attack their customers directly. The closest I can remember was the LifeLock guy putting his social security number up publicly. Otherwise, they prefer you hit test or personal accounts rather than paying customers...
- MuffinFlavored 4y ago> The closest I can remember was the LifeLock guy putting his social security number up publicly. ha. Did anything "good" (or bad) come of this?
- noirscape 4y agoReally glad I moved my domains to Porkbun recently. This is Namecheaps second blunder this year in terms of being a reliable service provider. First engaging in politically cheap racial discrimination (their ban on Russia seemingly having hit anyone who ever in their history used a Russian IP adress and demanding evidence of a users current location before lifting it), now giving hackers carte blanche to screw with existing customers. Extremely unreliable.
- prvit 4y agoOh yeah, it’s truly shocking that a company with most of their staff in Ukraine decided to cut off Russia. What unreliable pieces of shit. How dare they?
- noirscape 4y agoThe problem isn't the decision itself. The problem is all the context surrounding it. Namecheap is a Californian company with it's support staff outsourced to Ukraine. Cutting off Russia on it's own already subjects a bunch of probably already very stressed out Ukranians to the stress of dealing with angry Russians, most of whom have nothing to do with the war in Ukraine. These customers mind you, used Namecheap to host content the Russian regime disapproves of; they were pretty much the only reputable registrar offering domains to Russian customers that wasn't ran by the state. Getting rid of those customers pushes those people to Russian state registrars, who will gladly come knocking for contact details if someone hosts something that the Kremlin disapproves of. Adding to that, the actual methodology used was basically the dumbest method. It seems they targeted everyone who ever had Russian bank details in their account, anyone who ever accessed the site over a Russian IP address and anyone who had a Russian last name. This included hitting several thousands of people who fled the regime over a decade ago, who upon contacting Namecheap support were told to hand over proof of their permanent housing outside of Russia, people who used their account over a VPN, people in neighboring countries because GeoIP isn't an accurate science and people who have Russian roots but haven't even set foot in the country. The only way to prove this was to send fairly specific details of your housing to Namecheap support (reports at the time even indicated that affected customers had to send photographs of their own house to remain a client), something which can be very sensitive for some people, wrt OPSEC and it's also data they could easily verify with existing KYC data, but they categorically refused to do that. Like, the methods employed and the complete lack of perspective on what Russians used Namecheaps domains for are what make it racial discrimination, the decision itself is justifiable enough, many companies dropped Russia after the invasion.
- cgb223 4y agoIf the result of this tweet is that one of my domains is altered, and that I lose income, users, or other useful metrics to measure the value of my site, this seems like a great piece of evidence to be litigious towards Namecheap
- s_dev 4y agoHow is this different from any other bug bounty program as an incentive to compromise live functionality/user data always exists?
- dymk 4y agoIt’s the difference between stepping in a bear trap and poking a lion.
- mirashii 4y agoWell run bug bounty programs have strict guidelines on what is and is not out of scope, and changes like this would certainly be out of scope (in fact, generally social engineering as part of the exploit chain is itself wholly out of scope).
- nicolas_17 4y agoBug bounty programs usually explicitly forbid accessing other people's data.
- EricE 4y agoYikes - never taunt happy fun ball (The Internet)
- gkoberger 4y agoHow else is the CEO supposed to respond? He's in the tough position where he can't prove a negative; the burden of proof is on the original tweeter. So the CEO needs the "hacker" to either prove it or admit they were mistaken, and bug bounties are exactly how companies do this. (Also, I feel like it's implied that "an account that isn't yours" doesn't mean "mess with any of our customers you want." He's clarifying that because with white-hat(ish) hackers, you'd be shocked how many people try to claim bug bounties from us because they "hacked" their own account using their own credentials.)
- NamecheapCEO 4y agoThanks for your comment and you are correct with your latter point and assumption. It's hard to word things properly when you're limited with the amount of allowed characters on twitter.
- eric__cartman 4y agokek I thought this was a troll account until I saw your post history. I like your straight forward approach to username creation.
- aaaaaaaaata 4y agoApproach to additional username creation, most likely!
- ebfe1 4y agolove the bounty proposal but may I suggest creating a bounty target specifically for this and share it with everyone so whitehat folks can have a crack at it without raising concerns about hacking customers accounts? :)
- muhehe 4y ago> you'd be shocked how many people try to claim bug bounties from us because they "hacked" their own account using their own credentials. Wait ...what? Like, seriously?
- jjjjjjjjjjjjjjj 4y agoCoincidentally I just received an email request to reset my password on Namecheap (not issued by me), anyone else? On top of that, my account has been locked for 24 hours for three consecutive failed password or username entry attempts.
- treesknees 4y agoYou should watch your domains and look out for any friends who suddenly have a new car or a new nice watch :-). My strategy for things is to use a unique username and email address (and password..) for critical services, that way any hacks/leaks of other sites don't reveal my entire web presence. It may be that your email was found in another dump, or from a domain whois lookup.
- prvit 4y agoPerhaps someone just got confused with the amount of j's in their username?
- tonmoy 4y agoOff topic- is there a way to see info on twitter without creating an account? I used to look at tweets from my local meteorologist on twitter but now I can’t seem to be able to view info on twitter without a modal blocking the window and asking me to sign uo
- vorvac 4y agoReplace twitter.com with nitter.net, that's worked for me
- teeceetime2 4y agoI'm way less upset by this than a large number of people in that twitter brawl. I can agree that this probably isn't the best way to go about things, but in the end, all I see is a CEO taking a firm stance of confidence behind his products - let's just hope this doesn't turn into a real bad situation for namecheap customers. Ballsy? Yeah. But pitchfork and torch worthy? Not really.
- nibbleshifter 4y ago"Go commit a crime against a third party who didn't consent and I'll give you 10k$" is what this amounts to, given he excludes friends domains from the targets.
- lmilano 4y ago> no questions asked He doesn't even want to know how you did it.
- davidgerard 4y agoNameCheap support is leaking its PHP error log, which should reduce the search space considerably: https://twitter.com/ReneReh1/status/1564349884106477573 https://twitter.com/ReneReh1/status/1564349884106477573 There's at least one customer name in there.
- deletescape 4y agocompletely violating your users trust is an interesting way to react to a disclosure of a potential security vulnerability
- eknkc 4y ago"Nefarious actors are attempting these things 24/7 regardless. As a registrar for millions of domains names, we are constantly under attack so this isn't anything new." - https://twitter.com/NamecheapCEO/status/1564077063480418307 https://twitter.com/NamecheapCEO/status/1564077063480418307 I guess this makes sense. On the other hand such actions might have had legal implications before. I mean until the CEO actively allowed / awarded them.
- prvit 4y agoThis doesn’t have any meaningful legal implications. You will still be in trouble if you deface some random Namecheap customers website to claim this bounty.
- LeifCarrotson 4y ago> Also, I'll put my money where my mouth is. If you can make any changes to a domain that is not yours or a friend's via our help desk, I will send you 10k USD, no questions asked. > and to clarify, said account must be protected by 2fa to begin with. I appreciate what he's trying to say... but perhaps he should instead recommend white-hats instead create a test account and try to access it without using the 2FA mechanism.
- jonny_eh 4y agoOr qualify with "harmless changes", like inserting a TXT entry with your name.
- prvit 4y agoWhats the point? It’s not like it makes any difference. His tweet will not protect you if you choose to make harmful changes to someone else’s stuff.
- throwthere 4y agoIt may or may not make a difference with what happens in the court system, but I assure you there is a set of people who think the tweet would be permission to hijack a domain. And some of that set overlaps with the group that might accept the $10k challenge. Whether they actually follow-through and are able to, hopefully not. A bug bounty really ought to be thought out carefully.
- prvit 4y ago>I assure you there is a set of people who think the tweet would be permission to hijack a domain. And some of that set overlaps with the group that might accept the $10k challenge. And then from all those people you'd still need to find someone who 1) would successfully pull it off and 2) be stupid enough to demonstrate this in a damaging manner. It’s also worth noting that this offer was made to only one person.
- politelemon 4y agoMaybe you could put your actions where your mouth is and just add a 2fa step to the support portals login process? As a namecheap user I don't want to be randomly targeted to prove a point in some face saving contest.
- nathanaldensr 4y agoCool. This reminded me to delete my personal and business Namecheap accounts now that all the resources I had with them have been transferred or expired. Thanks, idiotic Namecheap CEO!