logoalt Hacker News

paxysyesterday at 10:07 PM2 repliesview on HN

How is domain privacy relevant here? That only hides your email from public records. What if the attacker already knows it (as they did in this case)? Email address is quite literally something you are meant to share publicly. It is not a password.


Replies

Thrashedyesterday at 10:53 PM

I think their point was that if WHOIS data were hidden, a password reset request that relied on providing the email address would've been impossible. But since NC's account management allows visitors to provide just a domain name to generate an unlock email, domain privacy wouldn't be a protective layer here.

show 1 reply
vel0cityyesterday at 10:33 PM

Registration info usually also includes a physical address and names.

show 1 reply