Tell HN: Namecheap gave my account to an unverified third party
tech
A long-time Namecheap customer has described a critical account security vulnerability on Hacker News. When a college club's new leader called support requesting DNS access to a domain registered under the customer's name, Namecheap changed the account password and email address—despite the original owner having already alerted the company to an unauthorized access attempt. The account holder notes that support had called to verify their earlier report, but didn't perform similar verification when the third party requested access. After the two parties eventually connected, the account holder says they would have willingly transferred ownership. The incident highlights what they describe as a major vulnerability: an unauthorized person successfully seized account control simply by asking nicely on a phone call.
Source: https://news.ycombinator.com/item?id=49028037
Listen to this story
Hear this and more stories in a personalized audio briefing.
Open The Chonkerton