Namecheap announces support for TOTP-based 2FA(namecheap.com) |
Namecheap announces support for TOTP-based 2FA(namecheap.com) |
The future is hardware U2F tokens. They can securely check the web-origin of a request and only give the token to the correct origin.
I'd really like to see U2F support though as well, domains are very valuable assets and deserve the strongest protection possible.
Their CEO is just pretending to be forthright here. I have a tweet where he replied to me from February 2014 that said Google Auth support is coming in a couple of months.
This all happened because I got locked out of my namecheap account when THEIR system wouldn't sms me the code and they had problems with the voice calling.
So I emailed support. They called me 5 hours later to ask me a bunch of questions. Here's the funny part: they called me on the number I had used for 2FA. Isn't the fact that I answered that number proof enough that I had it?
Everything they do is half assed including their Frankenstein panel that's a mix of their old interface and their new one.
Anyway. Good riddance. Only use namecheap if you can't afford the $1 it costs to host your dns on route53.
Why a checkbox ticking exercise? Even the Oct 2018 post by the CEO [1] says "[...] our proprietary app, was not well-received by many of you and did not serve you in the way many of you preferred to use 2FA." Apart from being such bullshit corpo speak, how was one single second factor device per person sufficient for critical infrastructure? What was I supposed to do, buy two phones? If a place is so clueless about 2FA, run. You can almost be sure they don't use 2FA internally.
(While I'm here, allow me to name and shame Patreon, who used to support TOTP, but removed that option and now only have SMS [2])
[1] https://www.namecheap.com/blog/true-totp-2fa-and-u2f-are-com...
[2] https://support.patreon.com/hc/en-us/articles/206538086-How-...
The other thing that would stop me from returning to or recommending Namecheap is GDPR compliance, or lack thereof. While I don't expect you to fight ICANN, it's a blocker. (Obviously, not many registrars offering compliance at the moment...)
This is probably the worst place to air a grievance like this, but it seemed like my frustrations had fallen on deaf ears. I haven't bought a domain from namecheap since.
Let's Encrypt. Ever going to roll it out?
I plan to switch away from Namecheap soon unless it's implemented, it's really disappointing to me.
You guys are hosting my email and I couldn't be happier.