Live data from Hacker News

The short tale of an online scam

duarteocarmo.com

1–10 of 98 posts

Re: The short tale of an online scam

#2
Scammers really have stepped up their game in recent years. I keep getting spam emails that say "we have your data, click here to see the list..."

Of course, the link wants to authorize against my (nonexistent) gmail. Nice try.

The people I feel bad for are the elderly: I know two that have been taken in by these things. They really aren't mentally equipped for the complexities of the modern Internet.

Re: The short tale of an online scam

#4
post #3

Namecheap. Surprise. They seem to be the preferred DNS provider for this sort of thing.

In what world can a DNS provider verify every single domain purchaser’s intent and activities post-sale? I don’t understand your argument at all…

Re: The short tale of an online scam

#5
post #4
post #3

Namecheap. Surprise. They seem to be the preferred DNS provider for this sort of thing.

In what world can a DNS provider verify every single domain purchaser’s intent and activities post-sale? I don’t understand your argument at all…

They're surprisingly lax with verification, even on ccTLDs with requires actual verification of details they just rubber-stamp what you've said is your contact details.

Re: The short tale of an online scam

#6
post #2

Scammers really have stepped up their game in recent years. I keep getting spam emails that say "we have your data, click here to see the list..." Of course, the link wants to authorize against my (nonexistent) gmail. Nice try. The people I feel bad for are the elderly: I know two that have been taken in by these things. They really aren't mentally equipped for the complexities of the modern Internet.

Lots of scams want your bank details. Unlike with SMS 2FA where the phone company never offered their service as a magic universal authenticator, the scammers want your bank account because it's a bank account. To the extent such scams work, we should be pretty unequivocal that it is your bank's fault. Banks are always reluctant to put their hands in their pockets when it comes to meaningful security. Whereas merchants and customers must upgrade to satisfy PCI DSS rules the banks gave themselves an unlimited free pass to just do whatever they wanted under PCI DSS because hey, those upgrades look expensive, we'd rather not bother.

My good bank actually has security. I'm fairly confident that I couldn't sleepwalk into giving bad guys access to the funds in that account by whatever means. I have a physical authenticator device to get into their online banking site, for example, so your scam would need to persuade me that I need to go get the authenticator and use that to sign in, all more chances for me to realise it's a scam.

But I have two other bank accounts, which both still think passwords are a pretty good level of security in 2021. One of them even lets me sign in using a numeric PIN, presumably they feel they've done enough to protect against brute force and so this is fine.

Re: The short tale of an online scam

#7
post #4

Earlier quoted context omitted.

In what world can a DNS provider verify every single domain purchaser’s intent and activities post-sale? I don’t understand your argument at all…

They're surprisingly lax with verification, even on ccTLDs with requires actual verification of details they just rubber-stamp what you've said is your contact details.

I've never had real identity verification on various domain sites, including namecheap.

Re: The short tale of an online scam

#8
post #2

Scammers really have stepped up their game in recent years. I keep getting spam emails that say "we have your data, click here to see the list..." Of course, the link wants to authorize against my (nonexistent) gmail. Nice try. The people I feel bad for are the elderly: I know two that have been taken in by these things. They really aren't mentally equipped for the complexities of the modern Internet.

>Scammers really have stepped up their game

Here's an innovative one. I got an sms impersonating my cell phone provider telling me they're going to change my plan.

They'd decided which one is the best for me but I have until next month to chose one 'of the new plans' clicking on a bit.ly link. That links points to an Amazon affiliated link, and it's totally unrelated to my provider.

Re: The short tale of an online scam

#9
post #7

Earlier quoted context omitted.

They're surprisingly lax with verification, even on ccTLDs with requires actual verification of details they just rubber-stamp what you've said is your contact details.

I've never had real identity verification on various domain sites, including namecheap.

Probably because you're only registering domains within lax TLDs.

Certain TLDs (like those under .uk, .cn, .jp, or .sg for example) requires more documents in theory - and at least with other domain name providers like Gandi, they asked for my ID and a letter from my company stating that I indeed was authorised to be a representative for that company, plus proof that the company exists (it's easy in the UK because it's already in a public database anyway, so we just send our company number and proof that we're that company), to verify that it is indeed me, authorised by my company, when registering at .uk (and similar arrangements for ccTLDs with similar requirements).

Namecheap on the other hand... well, they just trust you, period.

Re: The short tale of an online scam

#10
post #7

Earlier quoted context omitted.

They're surprisingly lax with verification, even on ccTLDs with requires actual verification of details they just rubber-stamp what you've said is your contact details.

I've never had real identity verification on various domain sites, including namecheap.

Even if they were to verify such details, that doesn’t preclude the purchaser from committing fraud or scamming others. There’s no way for a seller (namecheap) to ensure their product (domain) is not associated with misuse, just like any other real world sales.
Post reply on HN