frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Couple pay >$800k for a gene-editing therapy for their daughter. She died.

https://www.science.org/content/article/exclusive-death-girl-chinese-gene-editing-trial-was-never...
139•Shortness8•1h ago•55 comments

Writing by hand is good for your brain

https://nealstephenson.substack.com/p/writing-by-hand-is-good-for-your
843•dwwoelfel•8h ago•421 comments

Show HN: Echo – Fable-level results at 1/3 the cost using open-weight models

152•adam_rida•3h ago•70 comments

Namecheap Gave My Account to an Unverified Third Party Just Because They Asked

166•Thrashed•1h ago•37 comments

The Beam Engine

https://glinscott.github.io/beam-engine/
74•glinscott•1d ago•29 comments

What happened to TheNumbers.com

https://stephenfollows.com/p/what-just-happened-to-thenumberscom-should-worry-us-all
235•nickthegreek•5h ago•108 comments

Startup founders urge U.S. government not to shut off Chinese open weight AI

https://www.politico.com/news/2026/07/22/startup-founders-urge-trump-not-to-shut-off-chinese-open...
631•theanonymousone•7h ago•587 comments

Building on ATProto

https://lukekanies.com/writing/building-on-atproto/
106•speckx•4h ago•46 comments

Software rendering in 500 lines of bare C++

https://haqr.eu/tinyrenderer/
218•mpweiher•8h ago•39 comments

A solid-state “atomic channel” for separating rare earth elements

https://pme.uchicago.edu/news-events/news/cleaner-route-purifying-rare-earth-elements
55•MarcoDewey•4h ago•9 comments

Learn OpenGL, extensive tutorial resource for learning Modern OpenGL

https://learnopengl.com/
155•ibobev•7h ago•86 comments

Show HN: Palmier Pro – Open-source macOS video editor built for AI

https://github.com/palmier-io/palmier-pro
100•harrisontin•7h ago•17 comments

Astronomers may have found the first exomoon

https://www.eso.org/public/news/eso2610/
185•MarcoDewey•8h ago•72 comments

DARPA, U.S. Air Force fly AI-controlled F-16

https://www.darpa.mil/news/2026/darpa-us-air-force-fly-ai-controlled-f-16
143•r2sk5t•8h ago•160 comments

Converting Files into Minecraft Worlds

https://wuemeli.com/blog/sulfur-part-1/
39•wuemeli•3d ago•10 comments

Launch HN: Screenpipe (YC S26) – Record how you work and turn that into agents

46•louis030195•5h ago•47 comments

The arguments against open source AI are bad

https://tombedor.dev/arguments-against-open-source-ai-are-very-bad/
161•jjfoooo4•5h ago•115 comments

Geekbench 7

https://www.geekbench.com/blog/2026/07/geekbench-7/
39•ilreb•4h ago•31 comments

Learn WebGPU for C++

https://eliemichel.github.io/LearnWebGPU/
74•ibobev•7h ago•10 comments

Escape Analysis in Go: Stack vs. Heap Allocations Explained

https://blog.jetbrains.com/go/2026/07/20/escape-analysis/
23•ingve•2d ago•4 comments

JEP 540: Simple JSON API (Now in Incubator)

https://openjdk.org/jeps/540
87•theanonymousone•6h ago•66 comments

Interview with Matheus Moreira about Lone Lisp and Linux Kernel

https://alexalejandre.com/interviews/interview-with-matheus-moreira/
11•veqq•6d ago•5 comments

Show HN: Trifle – Open-source analytics that stores answers, not events

https://trifle.io/
28•iluzone•1d ago•2 comments

Meta Garbage Collection: Using OCaml's GC to GC Rust

https://soteria-tools.com/blog/meta-garbage-collection
36•annieversary•3d ago•0 comments

Fields Medals 2026

https://www.mathunion.org/imu-awards/fields-medal/fields-medals-2026
108•nill0•8h ago•49 comments

Selfie for sign-in: a new, easy way to access your Google Account

https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in/
59•lkurtz•3h ago•48 comments

Hitchcock and Herrmann: The Friendship and Film Scores That Changed Cinema

https://www.lrb.co.uk/the-paper/v48/n13/jonathan-coe/where-was-the-drum-kit
7•mitchbob•3d ago•1 comments

AI Companies Are Trying to Hide a Staggering Amount of Debt

https://futurism.com/artificial-intelligence/ai-companies-hide-debt-off-balance-sheet
548•technewssss•9h ago•261 comments

Emacs Is a Lispboard

https://en.andros.dev/blog/06bfd107/emacs-is-a-lispboard/
85•andros•8h ago•33 comments

Show HN: OneCLI – OSS credential gateway that keeps secrets out of AI agents

https://github.com/onecli/onecli
65•Jonathanfishner•6h ago•25 comments
Open in hackernews

Namecheap Gave My Account to an Unverified Third Party Just Because They Asked

163•Thrashed•1h ago
I’ve been a NameCheap customer for 13 years. I’ve also helped out an old college club paying for a .com they use (that is registered to me under my name, address, and phone number). During a recent leadership transition, the incoming club lead wanted to make changes to the DNS and didn’t know to contact me. They figured out the domain name was parked at NameCheap, so they initiated a password reset using the domain name. I got a password reset email and immediately filed a NameCheap support ticket saying “I did not initiate this”. They called me to verify I was the one who filed the ticket, and then followed up with a canned email with tips like check your anti-virus.

The incoming club leader was persistent though, and called NameCheap support. He convinced them the domain registered in my name and address really belonged to his club, and with no verification or validation whatsoever, NameCheap changed my password, and changed the email address associated with my account. All because someone simply asked nicely on a phone call.

Meanwhile in the background, someone advised the new club leader who I was and we were able to connect and get things transferred over. Ultimately I was happy to give them access or even ownership if they wanted (student club turnover being what it is, it’s likely a domain doesn’t get renewed and gets gobbled up by a squatter, which is why I was keeping it current for them).

But NameCheap had no way of knowing any of this. As far as NameCheap was aware, this was a personal account of mine. They demonstrated they were perfectly able to pick up a phone and call me (to verify my initial support ticket) but when someone calls them and says “but I really want access to that account” they don’t bother?

I’d hesitate to even call this social engineering. It’s clearly a massive vulnerability. I’ve already moved a dozen of my most critical domains out of NameCheap after seeing just how easy it is for a third party to completely take over a NameCheap account: just ask nicely.

Comments

superkuh•57m ago
Yep. I've been with Namecheap for a similar length of time. This week they sent me an email saying I had to update my namecheap profile information or they would close my account in 24 hours.

They locked my account so I couldn't log in. To be clear, my whois information was fullly legally compliant, and I was happy to also update my namecheap profile, but when I sent them an email they didn't get back to with an response email until there was just an hour left.

Things had been going down hill slowly and lots of my peers have already moved on to porkbun, etc, but I think now things are going downhill quite fast. I did manage to save my account (and so domains) but now I will be moving to a new registrar.

DANmode•49m ago
> saying I had to update my namecheap profile information or they would close my account in 24 hours.

Did they mention what prompted this?

Are you aware of anything?

ramgine•44m ago
I got that same email but skimmed it. I guess I need to double check and then move.
iAMkenough•43m ago
24 hours is a ridiculously short warning period, especially when they lock you out from meeting their demands yourself.

What if their email got caught in a spam filter? What if you only check that inbox a few times a week or after business hours?

I'll be moving my personal domains after doing some research.

jddj•20m ago
That sounds more like a phishing attempt than anything a real company should send.

I think I have one domain left with them. I haven't received anything yet, but it's a good reminder to move on.

happytoexplain•49m ago
Just a few weeks ago I moved from Namecheap to Porkbun. That's not an advertisement - I simply Googled popular registrars. But it is an indictment of Namecheap. They are going the way of GoDaddy. Please move away from them immediately. They are shifting to short-term strategies (high prices, immoral data practices, etc).
rickydroll•39m ago
Is it time to change registrars already? I fled Gandi a while ago because of private equity fuckery. And now I need to go somewhere else. Who won't adopt enshitification-as-a-business-plan for a few years?

No wonder people are leaving tech to go be goat farmers.

chrismarlow9•31m ago
I am also looking for something that will last for a good while.
js2•30m ago
> Who won't adopt enshitification-as-a-business-plan for a few years?

I don't have a crystal ball, but NearlyFreeSpeech was recommended to me in 2010 and I've been using it since 2012. I don't think it's changed at all in that time.

https://www.nearlyfreespeech.net/services/domains

https://www.nearlyfreespeech.net/services/respect

NetOpWibby•22m ago
Gandi got EXPENSIVE which is unfortunate because they often had TLDs no one else had first. I'm still with them for a single domain. Once Cloudflare supports .se, I'm outta there!
addaon•41m ago
Well, they didn't call it NameCompetent, did they?
Retr0id•38m ago
They're not even cheap these days, either. I'm still with them as a matter of laziness but I really need to migrate out.
jolan•18m ago
Cloudflare offers domain registration/renewal with no markup if you're looking for an option. I moved to them after AWS increased fees.
dalmo3•39m ago
I've had the exact same issue with a small local registrar.

Had an account where I managed multiple clients. One of the clients had their "IT guy" contact the registrar for a DNS change. The registrar promptly gave the guy full access to my account, changing the password and locking me out in the process.

As soon as I regained access I moved everything off there.

sixtyj•32m ago
Don’t be shy. Tell us the name.

This is unacceptable and such companies should change their policy or be out of business.

geuis•36m ago
I've been a long, long term customer of Namecheap as well.

Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost.

The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset.

This clearly isn't an answer for NC's customer support personnel and company policies.

But I've been a happy customer for many years and I discourage others from immediately reading other comments and rushing to jump to other registrars without doing your due dilligence.

Remember that in any situation, the people most likely to leave negative comments and reviews are the people that have had genuine bad experiences or feel like they've been slighted, even if unwarranted.

Thrashed•31m ago
I did have domain privacy enabled. NC allows people to initiate a password reset via username, email address, or domain name.

I was a happy customer right up until this incident. And I certainly agree that due diligence is a must for something as critical as a registrar.

geuis•26m ago
Glad you posted your experience. I'll definitely be keeping my eye out for shenanigans on my own domains.
eviks•17m ago
How will that help you prevent the transfer? The OP also "kept his eye out"
blcArmadillo•14m ago
Did you have 2FA enabled too?
phendrenad2•29m ago
Ah namecheap. Stories about them make it to HN quite regularly: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
pilingual•24m ago
Namecheap has been owned by a private equity firm for several months now.

It would be nice to have a nonprofit registrar so jumping every few years isn't necessary.

viccis•18m ago
Enshittification and PE sellouts are great for DNS providers because migrating it can be a real pain sometimes and carry a high risk if something goes wrong. It's why so many of them are chains of "Buy through Company N! We used to work for Company N-1 before they sold out!"
terribleperson•17m ago
...seriously? Where do I jump ship to now?
deadalus•5m ago
Porkbun. Yes, Cloudflare Domains exists but let's support the small guys.
linsomniac•23m ago
CloudFlare has their plusses and minuses, but they do offer domain registration at cost, for example $10.46/year for .com (every year, not one of those deals for the first year then more expensive down the line).
sigio•17m ago
The problem is that they then force you to use them as a DNS host as well.
paxys•18m ago
People are (rightfully) concerned about superintelligent AI but social engineering continues to be by far the biggest attack vector for digital infrastructure. And it’s being made worse by companies continuously cutting costs in areas like support.

The call center employee making third world minimum wage doesn’t give a shit who the real owner of the domain is. They want to end the call quickly and get 5 stars from the customer on the feedback form.

I have made it a point to move off services that force SMS-based 2fa for this exact reason. Recently even changed banks because of this.

hmokiguess•16m ago
Humans are the weakest link, wouldn't be shocked if it's some underpaid off shore call centre or whatever. That's not a vulnerability though, that is social engineering, the attack vector was a human and the exploit was a form of identity theft.
assimpleaspossi•6m ago
Scrolling through the current comments.

In the meantime, been with NameCheap for I don't recall how long with no issues whatsoever.

xyst•5m ago
Notably, they have been bought out by private equity.

> September 2025, CVC Capital Partners acquired a majority stake in Namecheap for an undisclosed amount, valuing the company at $1.5 billion.[3][4] Kirkendall stepped down as CEO on December 16, 2025

But prior to this they have had many incidents. Switched all domains to porkbun a few years ago

ryandrake•4m ago
This kind of story makes me wonder what's the most popular/valuable domain I can take control of simply by being convincing over the phone. Sounds tempting!

I can't even log in to most web sites anymore without doing a side-trip to my E-mail inbox, "for enhanced security," but these clowns let you just take a domain by asking nicely!

richardchilders•3m ago
Namecheap forces users to log in to identify themselves. So far, OK.

But then when one attempts to pay for a domain, after one has already provided all of one's credit card information to Namecheap ... Namecheap up and refers its customers to something called Link, which forces Namecheap's customers to create an account and become Link's customers - providing all that confidential credit card information, all over - leaving the customer wondering why Namecheap collected it and what they are going to do with it.

Link forces you to authenticate via SMS so that they know where you are.

This all happened less than 24 hours ago and I was already getting ready to put domain service shopping on my list of things to do but I'm glad to see I'm not the only one.

I nominate Paul Vixie as a possible candidate for CTO or even CEO of a hypothetical nonprofit DNS domain service.

More info: uggcf://fnynanir-ehalba.bet/ureovr.ugzy

em-bee•9m ago
namecheap has had a mixed reputation for several years now. when i took over responsibility for a domain registered on namecheap the first thing i did was move it off there (to gandi, because that was before gandi was sold) because i heard some problematic stories about namecheap. it baffles me everytime i see namecheap recommended.
paxys•23m ago
How is domain privacy relevant here? That only hides your email from public records. What if the attacker already knows it (as they did in this case)? Email address is quite literally something you are meant to share publicly. It is not a password.