Comment by sandeepkd
1 hour ago
In the absence of actual details its hard to say what was considered for making this decision. If I have to take a wild guess then being able to demonstrate the control on the webserver hosting the content could have been one way to prove ownership over the domain.
It can be called social engineering, however one can also put it in category of account recovery by verifying content control on the domain.
The part where it gets hairy is if your credit card was associated with the account, thats probably a recipe for disaster?
Webserver control is never used and must not be used to prove domain ownership. If you're pwned and have to re-point to a server stood up from backup, having registrar relying on someone being able to put up a random file on a compromised machine would be a total security disaster.