Posted by: Jeremy Benisek (CyberAxe) Don't Panic Business Technologies | April 10, 2018

Wix website hosting’s lazy domain transfer policy is dangerous.

This is a response I wrote to wix support asking for a responsible option to transfer a domain to another wix account. The current method requires the new owner of the domain to give you his username and password giving you full access to everything in his account. Customer contact info and messages. You could even change his password and lock him out.

Wix support reply:

Hello,
Unfortunately, this part cannot be bypassed. You can ask the owner to set a temporary password in order for you transfer the domain. Once it’s transferred they can update the password.
We apologize for the inconvenience. If you require any further assistance do not hesitate to contact us,

Nancy

My reply:

What stops me or anyone from logging into his account and taking everything. Destroying his websites, deleting emails, contacting his customers. Stealing his contacts and client lists….. on and on and on.
This is insain given the amount of data being stored in wix. I manage 15 accounts on wix and its insulting to our security and privacy to risk our businesses and lively hoods to transfer a $10/year domain.
With Facebook, youtube, google and others under investigation for poor privacy standards and not doing enough a few complaints might be worth bring up wix and these types of questionable lazy pratices. This is anything but security.

My comments on this issue:

To say this is some type of security is a direct lie. Never ever in any technical world is sharing your account username and password with random people online a form of security.

I assume this is all to avoid Federal domain transfer laws.


Leave a comment

Categories