The Chonkerton

Namecheap Gave My Account to an Unverified Third Party Just Because They Asked

tech

According to a Hacker News post, a Namecheap customer of thirteen years discovered a critical security flaw in how the registrar handles account access. Someone unrelated to the account called Namecheap support claiming they wanted control of a domain registered in the customer's name. With no verification, Namecheap changed both the account password and the email address on file. This happened even though the customer had already filed a support ticket minutes earlier saying they didn't initiate a password reset—and Namecheap had successfully called them to verify that original ticket. The registrar applied rigorous verification when the account holder called, but none at all when a stranger requested access. The customer says they would have willingly transferred the domain eventually and has now moved a dozen critical domains away from Namecheap over the vulnerability.

Source: https://news.ycombinator.com/item?id=49028037

Listen to this story

Hear this and more stories in a personalized audio briefing.

Open The Chonkerton