Namecheap. Surprise. They seem to be the preferred DNS provider for this sort of thing.
In what world can a DNS provider verify every single domain purchaser’s intent and activities post-sale? I don’t understand your argument at all…
The short tale of an online scam
41–50 of 98 posts
Re: The short tale of an online scam
#42More work, but with potential to waste more of the scammer’s time, would be to fake up requests corrupted in a way that suggests your browser config exposes some subtle bug, say a race condition, in his scripts. Might keep him busy for days …
Re: The short tale of an online scam
#43Re: The short tale of an online scam
#44The only odd thing I noticed was around 4000 requests were sent in perhaps a short time. That would indeed tip off the scammer. Might've been better to send in two or three a day, and ramp it up slowly until you get caught.
Re: The short tale of an online scam
#45That being said, I fell for another shipping scam in DK, seems it's quite common these days. Bank cancelled the card and transactions easily, though.
Re: The short tale of an online scam
#46Earlier quoted context omitted.
Lots of scams want your bank details. Unlike with SMS 2FA where the phone company never offered their service as a magic universal authenticator, the scammers want your bank account because it's a bank account. To the extent such scams work, we should be pretty unequivocal that it is your bank's fault. Banks are always reluctant to put their hands in their pockets when it comes to meaningful security. Whereas merchan…
> My good bank actually has security. Would you be willing to make a recommendation?
However I live in the United Kingdom, so this recommendation won't be much use to people who live elsewhere. My recommendation certainly does not stretch to their parent, HSBC, once the Hongkong and Shanghai Banking Corporation which likely does operate other banks where you live.
Re: The short tale of an online scam
#47An obvious red flag for me is always an opening message with "I'm interested in X", where "X" is verbatim copied off the title of the ad.
Re: The short tale of an online scam
#48The only odd thing I noticed was around 4000 requests were sent in perhaps a short time. That would indeed tip off the scammer. Might've been better to send in two or three a day, and ramp it up slowly until you get caught.
I thought so as well, but if they generated a new url per each victim, storing the referrer could make it trivial to filter out...
Re: The short tale of an online scam
#49Earlier quoted context omitted.
I've written a little bit about why NameCheap is so beloved by scammers. See https://shkspr.mobi/blog/2021/05/why-do-scammers-love-namech... They allow anonymous payments and they're slow to respond to takedown requests. They've started monitoring registrations now - so you can't register domains like `hsbc-co-uk.biz` without going through some extra checks.
>They allow anonymous payments and they're slow to respond to takedown requests. things that might also be liked by non-scammers.
Re: The short tale of an online scam
#50Earlier quoted context omitted.
One of the justifications is that showing only the hostname will make it easier to recognize malicious hostnames; as it is, the typical non-technical user just sees a bunch of stuff, doesn't really know how to distinguish hostname from path. I buy it honestly.
how they suppose to learn about it or at least be curious about it if they do not even see it? >I buy it honestly. phishing should look nice to the victim?