Live data from Hacker News

The short tale of an online scam

duarteocarmo.com

31–40 of 98 posts

Re: The short tale of an online scam

#31
post #27

Earlier quoted context omitted.

There has also been a push by Google and others lately to "dumb down" the url bar to hide the full address from users. Not sure why but I assume the justification would be some misguided attempt at making it look nicer while the real reason is somehow ad related.

> There has also been a push by Google and others lately to "dumb down" the url bar to hide the full address from users. Not sure why but I assume the justification would be some misguided attempt at making it look nicer while the real reason is somehow ad related. Suggesting Google might do anything without ad-related motives is probably too generous, but I've always thought that this was an optimisation in the sens…

I think the reason was mostly AMP.

Hiding/obscuring details from the URL bar seems like much less of a big deal if the goal is to rehost someone else's content. The value statement of the URL goes down a lot in that case, and the push to drive users away from it starts to make sense.

Either which way, I still hate it - The only non-work related ticket I've put in for chromium was a request for an option to disable this behavior entirely.

It's bad form from folks who should know better.

Re: The short tale of an online scam

#32

> "Also, (2) if you want to protect other people from falling victims to scams like these: tell them to always look at the url bar. Always." This is good advice, as things stand right now, it is in fact the best advice we can give. In absolute terms it is borderline useless advice. Many companies still communicate from and operate from domains other than their well-known main domain. How is anybody supposed to know t…

[deleted]

Re: The short tale of an online scam

#33
post #14

Earlier quoted context omitted.

I've written a little bit about why NameCheap is so beloved by scammers. See https://shkspr.mobi/blog/2021/05/why-do-scammers-love-namech... They allow anonymous payments and they're slow to respond to takedown requests. They've started monitoring registrations now - so you can't register domains like `hsbc-co-uk.biz` without going through some extra checks.

>They allow anonymous payments and they're slow to respond to takedown requests. things that might also be liked by non-scammers.

I love being able to use anonymous payments and I don't do anything malicious.

Re: The short tale of an online scam

#34
post #2

Scammers really have stepped up their game in recent years. I keep getting spam emails that say "we have your data, click here to see the list..." Of course, the link wants to authorize against my (nonexistent) gmail. Nice try. The people I feel bad for are the elderly: I know two that have been taken in by these things. They really aren't mentally equipped for the complexities of the modern Internet.

Lots of scams want your bank details. Unlike with SMS 2FA where the phone company never offered their service as a magic universal authenticator, the scammers want your bank account because it's a bank account. To the extent such scams work, we should be pretty unequivocal that it is your bank's fault. Banks are always reluctant to put their hands in their pockets when it comes to meaningful security. Whereas merchan…

My bank thinks banning right click on their site and disabling default inspect element is security. I'm sure making it annoying for me to copy the routing numbers is really going to help out.

Re: The short tale of an online scam

#35

> "Also, (2) if you want to protect other people from falling victims to scams like these: tell them to always look at the url bar. Always." This is good advice, as things stand right now, it is in fact the best advice we can give. In absolute terms it is borderline useless advice. Many companies still communicate from and operate from domains other than their well-known main domain. How is anybody supposed to know t…

There has also been a push by Google and others lately to "dumb down" the url bar to hide the full address from users. Not sure why but I assume the justification would be some misguided attempt at making it look nicer while the real reason is somehow ad related.

My interpretation is that they don't want users to go to a specific URL, Google wants users to search for it (and click an ad) on Google.

Re: The short tale of an online scam

#36
post #21

"always look at the url bar" I remember reading about a scam where the URL seemed legit, and the suspicious part was pushed after so much white space that it was no longer visible in the URL bar. I don't remember the details and I'd be curious to know if anyone remembers it. I remember even sophisticated users saying they might have fallen for it.

URL bars should condense whitespace or use an obvious graphic rendering.

Re: The short tale of an online scam

#37

> "Also, (2) if you want to protect other people from falling victims to scams like these: tell them to always look at the url bar. Always." This is good advice, as things stand right now, it is in fact the best advice we can give. In absolute terms it is borderline useless advice. Many companies still communicate from and operate from domains other than their well-known main domain. How is anybody supposed to know t…

Plus the redirect shenanigans some companies pull is pretty ridiculous too. It seems like logging into an intranet protected by MS login it flashes through about 15 different domains that I can't even make out.

Re: The short tale of an online scam

#38

Earlier quoted context omitted.

There has also been a push by Google and others lately to "dumb down" the url bar to hide the full address from users. Not sure why but I assume the justification would be some misguided attempt at making it look nicer while the real reason is somehow ad related.

One of the justifications is that showing only the hostname will make it easier to recognize malicious hostnames; as it is, the typical non-technical user just sees a bunch of stuff, doesn't really know how to distinguish hostname from path. I buy it honestly.

how they suppose to learn about it or at least be curious about it if they do not even see it?

>I buy it honestly.

phishing should look nice to the victim?

Re: The short tale of an online scam

#39
post #16

An obvious red flag for me is always an opening message with "I'm interested in X", where "X" is verbatim copied off the title of the ad.

The problem with that (at least in what I've sold online), is that older/elderly people tend to copy and paste into their messages or type it out verbatim.

Again, maybe that's specific to woodworking tools and supplies, because those people tend to skew older, but I have legit asked 4 or 5 buyers, this year alone, if they were bots because that is literally their first line.

Re: The short tale of an online scam

#40

> "Also, (2) if you want to protect other people from falling victims to scams like these: tell them to always look at the url bar. Always." This is good advice, as things stand right now, it is in fact the best advice we can give. In absolute terms it is borderline useless advice. Many companies still communicate from and operate from domains other than their well-known main domain. How is anybody supposed to know t…

There has also been a push by Google and others lately to "dumb down" the url bar to hide the full address from users. Not sure why but I assume the justification would be some misguided attempt at making it look nicer while the real reason is somehow ad related.

It isn't just Google. Multiple browsers have flirted with hiding it.

There are various mindsets that lead to want to do that - one designer I know calls it a debugging tool that should never have been released in the first place.

For others, it is clearly about controlling the user with various justifications.

(I consider it a canary. Its removal will be a signal that the HugeCos are comfortable relegating the non-corporate web to the fringe, Usenet-style. It will be there, and you can get to it if you go way out of your way, but what it there will mostly be automated spam and weirdness, tons of examples of specific use cases, and a few folks who have been arguing with each other since 1992.)

Post reply on HN