Live data from Hacker News

Turn any link into a suspicious-looking one

verylegit.link

21–30 of 103 posts

Re: Turn any link into a suspicious-looking one

#22
post #18

I've DNS blackholed the entire .link TLD, along with .science, .country, .click, and .rocks. So, there's that. (DNSMasq, router-based blocklist.)

How's your signal-to-noise ratio? Is this the first legit site you've wanted to access on one of those TLDs?

Yes.

Mind that if I want to access a site, I can do so by using one of several proxies. E.g., archive.is or the like.

The blocks are, in that sense, soft, but strongly advisory.

I'm also increasingly blocking just straight-up shit sites, as well as a large number of advertising and monitoring sites, via standard blocklists (mostly based off uBlock / uMatrix's lists).

Re: Turn any link into a suspicious-looking one

#23
This:

   secure.verylegit.link/warez737speedupurpc.gif.pdf
(example from site) doesn't look dodgy to me at all.

I'd have no qualms clicking on it, because my browser and I can handle suspicious websites. (Especially ones ending pdf.)

Something that would give pause would be:

https://tinyurl.com/2ea2mu4?command=127.0.0.1/activate

I would think...wait a minute... I probably wouldn't click this example.

Re: Turn any link into a suspicious-looking one

#26
post #17

Earlier quoted context omitted.

Click the (i) icon to the left of the URL in the address bar, the the `>` button, then “More information” at the bottom. The technical details say the connection is not encrypted.

Yes, I found that, but that's not even an inadequate error message -- it's just wrong. Firefox has no way to tell if the connection is encrypted or not because the connection is being dropped while the encryption is being established.

So a connection that doesn't exist cam hardly be encrypted now can it? Scnr

But yeah I noticed this trend too in browsers, it's getting harder to get to the technical bits every time they try to make these warnings more user friendly. I usually switch to openssl s_client in a terminal at this point.

Re: Turn any link into a suspicious-looking one

#29

Earlier quoted context omitted.

Do you care to share the reasons you've taken this decision?

Direct personal realisation, an increasingly take-no-prisoners approach to online abuse, and a considerable amount of evidence from elsewhere that such TLDs are almost entirely void of value. My router doesn't have sufficient resources to list individual hosts, particularly where widespread abuse is found. Plus it's just too much fucking work. BlueCoat Security (now part of Symantec) have been publishing a "Shady TLD…

These lists, it should be pointed out, are quickly becoming outdated as more folks sign up for new domain names. For example, there’s this on .xyz https://www.symantec.com/connect/blogs/exploring-xyz-another... and then there’s actual usage of it: https://abc.xyz (completely not mentioned...) If you want to know the most popular/relevant sites on a TLD, search google for `site:xyz` to see a small list... E.g. .link often is used by websites with very long domains looki for a shorter one, like http://gcr.link/ Amazon has http://aws.science/ .country is mostly crap, but there is http://cma.country/ .click is indeed only slightly less spammy, but does have http://bbc.click/ And .rocks doesn’t deserve the ban. It’s used by fan sites, people promoting tech or events, and fun stuff like kqed.rocks for kqed.org ... I’ll admit though, it can be hard to tell with all the third party domains which sites are legitimate and which aren’t...
Post reply on HN