Comment by Thrashed
2 hours ago
I think their point was that if WHOIS data were hidden, a password reset request that relied on providing the email address would've been impossible. But since NC's account management allows visitors to provide just a domain name to generate an unlock email, domain privacy wouldn't be a protective layer here.
I still don’t get the argument. Say I call your bank and convince them to give me full control of your account. Are you going to go “well the bank didn’t publish my account number anywhere, so they are in the clear”?
I agree, it's not an excuse to hand over an account. I think that commenter was considering practical mitigations for a broken system, not necessarily absolving NC of responsibility had my WHOIS been public.