Live data from Hacker News

Turn any link into a suspicious-looking one

verylegit.link

91–100 of 103 posts

Re: Turn any link into a suspicious-looking one

#92
post #52

If I were trying to send someone to my nefarious website, I'd definitely now wrap the link in this, so that the savvy viewer would think it's a harmless verylegit.link...

You already have that same deal with bit.ly and friends. http://bit.ly/2saifoB http://bit.ly/2t5xNhB Which is safe and wonderful and which is dangerous?

Yes, absolutely. And on Twitter with its damn t.co hrefs even though the text is a truncated version of the real thing.

Re: Turn any link into a suspicious-looking one

#93
post #26

Earlier quoted context omitted.

So a connection that doesn't exist cam hardly be encrypted now can it? Scnr But yeah I noticed this trend too in browsers, it's getting harder to get to the technical bits every time they try to make these warnings more user friendly. I usually switch to openssl s_client in a terminal at this point.

A general trend. I've been aware of it since Linus Torvalds pointed out that so called "ux-improvements" were actually ux problems back in gnome 2. UX-ers here (hopefully there must be a few ones from Google and Mozilla here): please help stop this long trend of dumbification. I'm not asking you to make it like bash and vim just to stop hiding menus, removing settings etc etc.

Complain about how hard it is to get to the details of a bad cert if you want, but this instance does not exemplify the trend you're referring to.

This is one of only HTTPS errors that you aren't required to click through to uncover the details of the error—the connection is being shut down.

Re: Turn any link into a suspicious-looking one

#94
post #73

Earlier quoted context omitted.

But what if you do the same on Linux, with Wine installed? are you vulnerable the same way Windows users are ? I mean: Wine lets you just double-click exe file to run it.

No idea, however I doubt any Linux user with Wine installed would double click some random setup.exe that was auto downloaded.

You are dangerously underestimating stupid...

Re: Turn any link into a suspicious-looking one

#95
post #88

Earlier quoted context omitted.

For the uninitiated: just add a + to the end of any bitly URL to expose metrics and preview the destination. http://bit.ly/2saifoB+ http://bit.ly/2t5xNhB+

Produces an empty page for me thanks to Noscript. I mean, I'm sort of used to this bullshit by now, but it's particularly egregious since this feature's audience is specifically the tinfoil crowd.

If your research suggests there's a market for a url shortener which uses no JS for analytics etc., you're quite empowered to start one.

Re: Turn any link into a suspicious-looking one

#96
post #88

Earlier quoted context omitted.

For the uninitiated: just add a + to the end of any bitly URL to expose metrics and preview the destination. http://bit.ly/2saifoB+ http://bit.ly/2t5xNhB+

Produces an empty page for me thanks to Noscript. I mean, I'm sort of used to this bullshit by now, but it's particularly egregious since this feature's audience is specifically the tinfoil crowd.

This feature's audience is the marketing crowd.

Re: Turn any link into a suspicious-looking one

#97

Earlier quoted context omitted.

Direct personal realisation, an increasingly take-no-prisoners approach to online abuse, and a considerable amount of evidence from elsewhere that such TLDs are almost entirely void of value. My router doesn't have sufficient resources to list individual hosts, particularly where widespread abuse is found. Plus it's just too much fucking work. BlueCoat Security (now part of Symantec) have been publishing a "Shady TLD…

These lists, it should be pointed out, are quickly becoming outdated as more folks sign up for new domain names. For example, there’s this on .xyz https://www.symantec.com/connect/blogs/exploring-xyz-another... and then there’s actual usage of it: https://abc.xyz (completely not mentioned...) If you want to know the most popular/relevant sites on a TLD, search google for `site:xyz` to see a small list... E.g. .link o…

Another .rocks one:

https://react.rocks/

Re: Turn any link into a suspicious-looking one

#98
post #36
post #25

Earlier quoted context omitted.

pdf and dmg are already pretty scary.

Dmg isn't scary. It's just a disk-image that mounts upon download. You have to manually start any executable on it. And yes, there are users who click on executables carelessly, but those aren't scared by url-parts.

Uhh... It mounts after downloading? Aside from that I doubt (or don't want to believe) that's what's happening... Doesn't that sound inherently dangerous to you? We've seen files that could infect Windows machines just from having the file browser look directly at them.

Re: Turn any link into a suspicious-looking one

#99

Earlier quoted context omitted.

It's kind of wild that "SHADY URL" is something phishers want to use. But, in the end I guess it's all about finding a domain that isn't tied to them?

Similar to 419 scams, shady links/propositions are a good way to select the people who are easy to trick.

Yeah that's my best guess. I was shocked how much it was used for scams. Might also be possible the link is so suspicious looking it's actually more intriguing to click.

Re: Turn any link into a suspicious-looking one

#100

Earlier quoted context omitted.

People have a sense of humor, and this is a fantastic meta joke. Why so serious?

This site doesn't like jokey comments, so how are pointless jokey links tolerated? It's not like the linked to site is making a serious point in a light hearted way.

I think the site makes an important comment: I've had two very on-to-it people say in response to my share (legit.link pointing to itself), "I'm not clicking that".

My thoughts are, why should the the "obviously dodgy looking" link be any more risky than a bit.ly shortened one. Bit.ly is not coming out and saying "I'm shady", but other than that you have no idea what's on the other end (I'd argue most people don't know about the + on the end reveal).

Post reply on HN