Earlier quoted context omitted.
In what way are you more secure then when someone uses a .com domain? In both cases it is easy to register a url and turn into a malicious site. It really seems you are blackholing parts of the web for no good reason except to exempt yourself from actually performing a security check on the sites on the assumption all other tld's are safe.
Wrong question. Risk. Reward. Administrative cost. The first of these I blocked when I looked at the domain and realised that the TLD were registering any old line noise. I'm not going to bother sorting that. Search for other experience turned up Blue Coat. I subscribe to blocklists, and they update periodically. There are other levels of protection. When a TLD is 99.9% malware or scams, it's far easier to block it o…
Turn any link into a suspicious-looking one
51–60 of 103 posts
Re: Turn any link into a suspicious-looking one
#52Re: Turn any link into a suspicious-looking one
#53This: secure.verylegit.link/warez737speedupurpc.gif.pdf (example from site) doesn't look dodgy to me at all. I'd have no qualms clicking on it, because my browser and I can handle suspicious websites. (Especially ones ending pdf.) Something that would give pause would be: https://tinyurl.com/2ea2mu4?command=127.0.0.1/activate I would think...wait a minute... I probably wouldn't click this example.
Good for you. But this is a scary looking link for the average internet browser.
If this seemed suspicious to the people you're talking about, nobody would start a letter to them with the words, " Please permit me to make your acquaintance in so informal a manner. This is necessitated by my urgent need to reach a dependable and trust wordy foreign partner. This request may seem strange and unsolicited but I will crave your indulgence and pray that you view it seriously. " (I found this example online.)
So, I simply disagree that the example produced looks suspicious. It looks fine.
Further, I wouldn't even think twice before clicking it. The example I quoted simply doesn't look suspicious. (Because pdf is a 'safe' filetype.) I don't think it would give the average Internet user pause, either.
Re: Turn any link into a suspicious-looking one
#54Earlier quoted context omitted.
As an aside, BlueCoat is not a very reputable company. They are responsible for the government-sponsored censorship of Burma's and Syria's internet[1]. Which means that Symantec is currently the (American) company responsible for the censorship blacklist of Syria and Burma. [1]: http://surveillance.rsf.org/en/blue-coat-2/
Two points here, about both the advice and the people giving it. Regarding the advice, personally I think the advice is bogus. A lot of Mastodon instances have started legitimately using unconventional newTLDs. And I seem to see more URI shorteners, .com and .ru in spam than all the newTLDs put together (zero, from a hacked site, costs less than free). Country K-lining, while attractive to the lazy network operator,…
The federated structure of Mastodon means that, so long as I'm accessing toots via my host instances, the source of the toots doesn't matter. That plumbing is managed by the instances, not my local network gateway.
(If I were locally hosting, the situation would be different.)
Punching holes as needed would be another alternative.
I'm aware of the various arguments in favour, and opposed to, various forms of security blocking or not. I've participated in those discussions for most of the past 30 years. There are times when the onslaught simply becomes sufficiently excessive that measures need to be taken.
DNS namespace is large. I'm not going to independently add every last damned host, or domain, by hand. And even with blocklist subscriptions, the overhead is substantial.
I suspect this is a situation which may come to a head in the not-too-distant future, though timing such matters is difficult. The consolidation of much Web activity to a relatively small number of sites already reflects this in part.
Re: Turn any link into a suspicious-looking one
#55Is there any way to get SSL error messages in Firefox? https://irc.verylegit.link/0x8c*download()194mobiads(windows... is supposed to redirect to Facebook, and it does if you use HTTP. However, over HTTPS Firefox just gives me a very generic "Secure Connection Failed" message. (Chrome is rather more helpful, giving me "ERR_CONNECTION_CLOSED".)
http://hey.look.a.verylegit.link/malware-425iphone)ip-steale...(.docx.html.rar
Edit: Although it appears Hacker News decided to mangle this link that I posted. Apparently it's not happy about mismatched parenthesis in links. Why HN wants to try to match parenthesis in links... that's a good question.
Re: Turn any link into a suspicious-looking one
#56Re: Turn any link into a suspicious-looking one
#57Earlier quoted context omitted.
Yes, I found that, but that's not even an inadequate error message -- it's just wrong. Firefox has no way to tell if the connection is encrypted or not because the connection is being dropped while the encryption is being established.
So a connection that doesn't exist cam hardly be encrypted now can it? Scnr But yeah I noticed this trend too in browsers, it's getting harder to get to the technical bits every time they try to make these warnings more user friendly. I usually switch to openssl s_client in a terminal at this point.
I've been aware of it since Linus Torvalds pointed out that so called "ux-improvements" were actually ux problems back in gnome 2.
UX-ers here (hopefully there must be a few ones from Google and Mozilla here): please help stop this long trend of dumbification. I'm not asking you to make it like bash and vim just to stop hiding menus, removing settings etc etc.
Re: Turn any link into a suspicious-looking one
#58Earlier quoted context omitted.
Considering most people in the world use Windows, dmg is pretty much irrelevant. They can only be opened/unpacked on Macs, so even if it contains a evil payload you won't ever got to it on Windows or Linux. Exe-files has much bigger impact and can be run through emulation on non-Windows systems. I'd say exe is a much better choice.
My mental pronunciation mechanism cannot stop reading "dmg" as "damage"
Re: Turn any link into a suspicious-looking one
#59Earlier quoted context omitted.
pdf and dmg are already pretty scary.
Considering most people in the world use Windows, dmg is pretty much irrelevant. They can only be opened/unpacked on Macs, so even if it contains a evil payload you won't ever got to it on Windows or Linux. Exe-files has much bigger impact and can be run through emulation on non-Windows systems. I'd say exe is a much better choice.
Re: Turn any link into a suspicious-looking one
#60Earlier quoted context omitted.
Considering most people in the world use Windows, dmg is pretty much irrelevant. They can only be opened/unpacked on Macs, so even if it contains a evil payload you won't ever got to it on Windows or Linux. Exe-files has much bigger impact and can be run through emulation on non-Windows systems. I'd say exe is a much better choice.
As an OSX user, it is fairly amusing when some sketchy ad auto-downloads some "setup.exe" file.