Live data from Hacker News

The new .zip TLD is going to cause some problems

shkspr.mobi

41–50 of 90 posts

Re: The new .zip TLD is going to cause some problems

#41

Honestly, I harbour just a smidgeon of hope that cases like this will nudge companies to reevaluate the whole “find text that could be a link with a missing protocol” feature and realise that it’s a terrible idea that causes more trouble than it solves. If you want a link, write a proper URL. The embedded tweet shows another problem, too: > Grrr... Because .zip is a valid TLD, it's impossible to know whether http://t…

[deleted]

Re: The new .zip TLD is going to cause some problems

#45
post #35
post #3

How is this different from .com, which was also a common file extension?

It's not a commonly used extension, and it's a dangerous file type, so users shouldn't be opening received .com files either way. OTOH .zip is quite common and has legitimate uses.

.zip files can also be dangerous.

https://en.m.wikipedia.org/wiki/Zip_bomb

Re: The new .zip TLD is going to cause some problems

#46
post #38

Can someone describe a concrete vulnerability that this creates?

Message someone and mention a file with a .zip extension, like "Go to Trusted Bank and download financials.zip". Since .zip is now a TLD, software could auto-link it to https://financials.zip. The receiver will think the sender legibility linked to financials.zip for their convivence, but in fact they'll be redirected to a URL with a malicious zip file.

Re: The new .zip TLD is going to cause some problems

#49

Earlier quoted context omitted.

.com .sh There are many file extension collisions with TLDs and the sky didn't fall yet

Neither of those are used by general consumers on a regular basis. Those are used by people that are generally knowledgeable. I don't know why people can't wrap their head around this. .zip is used every day by people that aren't the best at understanding computer security. Massive difference.

The category of "tech literate enough to use zips but not enough to know not to blindly click links in emails and also aren't covered by their company's security policy" is a pretty niche group. Your grandpa isn't compressing zips and sending them around to family. Vast vast vaaaaast majority of people just use direct file uploads.

This is going to be a problem, but not for the average folk, but rather for IT teams with unstable rules and other software teams like Gmail who are likely to signal larger differences between attachments and just links.

Re: The new .zip TLD is going to cause some problems

#50

Here's the files you requested: https://attachment.zip

Rickrolling in 2008: Boisterous Synth Music and Rick Astley

Rickrolling in 2023: Video is initially paused with a full title card visible, If you attempt to play it, you get 5 seconds of an AD playing before you can manually click a Skip button, then finally the synth music comes in...

Yeah, it just doesn't work anymore.

Post reply on HN