Live data from Hacker News

Turn any link into a suspicious-looking one

verylegit.link

31–40 of 103 posts

Re: Turn any link into a suspicious-looking one

#31
post #19

Earlier quoted context omitted.

Direct personal realisation, an increasingly take-no-prisoners approach to online abuse, and a considerable amount of evidence from elsewhere that such TLDs are almost entirely void of value. My router doesn't have sufficient resources to list individual hosts, particularly where widespread abuse is found. Plus it's just too much fucking work. BlueCoat Security (now part of Symantec) have been publishing a "Shady TLD…

As an aside, BlueCoat is not a very reputable company. They are responsible for the government-sponsored censorship of Burma's and Syria's internet[1]. Which means that Symantec is currently the (American) company responsible for the censorship blacklist of Syria and Burma. [1]: http://surveillance.rsf.org/en/blue-coat-2/

Taken into consideration. Though this doesn't speak to the specific analysis of TLDs referenced here.

Re: Turn any link into a suspicious-looking one

#32

Earlier quoted context omitted.

Direct personal realisation, an increasingly take-no-prisoners approach to online abuse, and a considerable amount of evidence from elsewhere that such TLDs are almost entirely void of value. My router doesn't have sufficient resources to list individual hosts, particularly where widespread abuse is found. Plus it's just too much fucking work. BlueCoat Security (now part of Symantec) have been publishing a "Shady TLD…

These lists, it should be pointed out, are quickly becoming outdated as more folks sign up for new domain names. For example, there’s this on .xyz https://www.symantec.com/connect/blogs/exploring-xyz-another... and then there’s actual usage of it: https://abc.xyz (completely not mentioned...) If you want to know the most popular/relevant sites on a TLD, search google for `site:xyz` to see a small list... E.g. .link o…

Given the risk/reward of, oh, say, finding my systems hosed or users scammed and/or bank accounts drained, vs. missing out on someone's link shortener, I think I'll err on the side of caution.

This being an assessment based on local awareness of circumstances.

Re: Turn any link into a suspicious-looking one

#33
post #21

How is this top of hacker news???

People have a sense of humor, and this is a fantastic meta joke. Why so serious?

This site doesn't like jokey comments, so how are pointless jokey links tolerated? It's not like the linked to site is making a serious point in a light hearted way.

Re: Turn any link into a suspicious-looking one

#34

Earlier quoted context omitted.

People have a sense of humor, and this is a fantastic meta joke. Why so serious?

This site doesn't like jokey comments, so how are pointless jokey links tolerated? It's not like the linked to site is making a serious point in a light hearted way.

Because the joke is actually a utility, and I for one plan to share links to others with it to continue the fun (can't be done with a witty/funny comment).

Re: Turn any link into a suspicious-looking one

#35
post #25

The suffixes should be exe, com, js, hta, vbs, and so on, for extra evilness.

pdf and dmg are already pretty scary.

Considering most people in the world use Windows, dmg is pretty much irrelevant. They can only be opened/unpacked on Macs, so even if it contains a evil payload you won't ever got to it on Windows or Linux.

Exe-files has much bigger impact and can be run through emulation on non-Windows systems.

I'd say exe is a much better choice.

Re: Turn any link into a suspicious-looking one

#36
post #25

The suffixes should be exe, com, js, hta, vbs, and so on, for extra evilness.

pdf and dmg are already pretty scary.

Dmg isn't scary. It's just a disk-image that mounts upon download. You have to manually start any executable on it.

And yes, there are users who click on executables carelessly, but those aren't scared by url-parts.

Re: Turn any link into a suspicious-looking one

#37
post #25

Earlier quoted context omitted.

pdf and dmg are already pretty scary.

Considering most people in the world use Windows, dmg is pretty much irrelevant. They can only be opened/unpacked on Macs, so even if it contains a evil payload you won't ever got to it on Windows or Linux. Exe-files has much bigger impact and can be run through emulation on non-Windows systems. I'd say exe is a much better choice.

My mental pronunciation mechanism cannot stop reading "dmg" as "damage"

Re: Turn any link into a suspicious-looking one

#38

Earlier quoted context omitted.

These lists, it should be pointed out, are quickly becoming outdated as more folks sign up for new domain names. For example, there’s this on .xyz https://www.symantec.com/connect/blogs/exploring-xyz-another... and then there’s actual usage of it: https://abc.xyz (completely not mentioned...) If you want to know the most popular/relevant sites on a TLD, search google for `site:xyz` to see a small list... E.g. .link o…

Given the risk/reward of, oh, say, finding my systems hosed or users scammed and/or bank accounts drained, vs. missing out on someone's link shortener, I think I'll err on the side of caution. This being an assessment based on local awareness of circumstances.

In what way are you more secure then when someone uses a .com domain? In both cases it is easy to register a url and turn into a malicious site. It really seems you are blackholing parts of the web for no good reason except to exempt yourself from actually performing a security check on the sites on the assumption all other tld's are safe.

Re: Turn any link into a suspicious-looking one

#39
post #25

Earlier quoted context omitted.

pdf and dmg are already pretty scary.

Considering most people in the world use Windows, dmg is pretty much irrelevant. They can only be opened/unpacked on Macs, so even if it contains a evil payload you won't ever got to it on Windows or Linux. Exe-files has much bigger impact and can be run through emulation on non-Windows systems. I'd say exe is a much better choice.

*Considering most people in the world use Android.

Re: Turn any link into a suspicious-looking one

#40
post #25

Earlier quoted context omitted.

pdf and dmg are already pretty scary.

Considering most people in the world use Windows, dmg is pretty much irrelevant. They can only be opened/unpacked on Macs, so even if it contains a evil payload you won't ever got to it on Windows or Linux. Exe-files has much bigger impact and can be run through emulation on non-Windows systems. I'd say exe is a much better choice.

[deleted]
Post reply on HN