Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

11–20 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#11

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#13
post #5

I have always thought the infinite proliferation of TLDs was a stupid idea. I'd be enlightened if I could think of one scenario that benefits from it outside of the registrars.

There are lots of people called John Smith. They all want a domain name. There's only so many variations of jsmith, j-smith, etc you can squeeze into .com, .net, and a few others.

Why shouldn't they be able to buy a domain name which contains their name?

Is it useful to be able to differentiate between McDonald's the restaurant and McDonald's the legal firm and McDonald's garage?

Why shouldn't each of those industries get their own TLD?

The original list of TLDs aren't some platonic good written by ineffable sages. It's OK for things to change.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#14

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

Yep that's the issue, I'm just saying I'd rather have that problem than the one where I can't register a clean looking personal domain because every idea I have is already registered (with 95% of them leading to a parking page untouched for years except to pay the bill). Feels like we just need more names available and I don't see how else we could get them.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#15
> John Levine is author of the book “The Internet for Dummies” and president of CAUCE. Levine said adding more TLDs without a much stricter registration policy will likely further expand an already plentiful greenfield for cybercriminals.

He's from pre-gold-rush Internet, and still making the net better: https://en.wikipedia.org/wiki/John_R._Levine

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#16
post #6

Honestly the only "legitimate" use for these TLDs seem to be fediverse/bsky vanity URLs. Everything outside that just looks like a scam, even if it isn't.

Interesting! Now that you mention it, I did buy a .luxury domain for this purpose - a Gemini server. I also bought a .ski to have a domain with my (polish) last name.

It's great to be able to get silly domains for projects, back to the old days of IRC vanity hosts, but can you imagine seeing a link to something like jackets.luxury and going "yeah that seems legit, I'm definitely giving them my card details"

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#17
post #8

Once I found I couldn’t iMessage a .xyz link I decided to stay away…

This would have me staying away from iMessage. What other content is Big Brother not transmitting for my "protection?"

This is actually why I moved off of Facebook Messenger. It started blocking random links I tried to send so I moved to something E2E encrypted.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#18
post #2

> new gTLDs introduced in the last few years command just 11 percent of the market for new domains, but accounted for roughly 37 percent of cybercrime domains reported between September 2023 and August 2024. > .com and .net domains made up approximately half of all domains registered...they accounted for just over 40 percent of all cybercrime domains. Hardly earth shattering. .net and .com are still pulling 80% of th…

> Maybe the real story here is that the ccTLD registrars, who weren't mentioned, are disproportionately good at deterring cybercrime.

I think that some ccTLDs requiring positive identification, usually as a side effect of residency or nationality requirements, immensely help here (versus most gTLDs requiring f***-all identification).

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#19
post #13
post #5

I have always thought the infinite proliferation of TLDs was a stupid idea. I'd be enlightened if I could think of one scenario that benefits from it outside of the registrars.

There are lots of people called John Smith. They all want a domain name. There's only so many variations of jsmith, j-smith, etc you can squeeze into .com, .net, and a few others. Why shouldn't they be able to buy a domain name which contains their name? Is it useful to be able to differentiate between McDonald's the restaurant and McDonald's the legal firm and McDonald's garage? Why shouldn't each of those industrie…

>There are lots of people called John Smith. They all want a domain name. There's only so many variations of jsmith, j-smith, etc you can squeeze into .com, .net, and a few others.

>Why shouldn't they be able to buy a domain name which contains their name?

I fail to see how johnsmith[insert number here].com is any worse than johnsmith.[insert TLD here]. If anything a number is less likely to get mixed up than tlds, which have confusing pairs like ".tech" and ".technology", or ".engineer" and ".engineering".

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#20
post #15

> John Levine is author of the book “The Internet for Dummies” and president of CAUCE. Levine said adding more TLDs without a much stricter registration policy will likely further expand an already plentiful greenfield for cybercriminals. He's from pre-gold-rush Internet, and still making the net better: https://en.wikipedia.org/wiki/John_R._Levine

OT, but man, I remember reading that book when I was a kid. Then started reading HTML books and, of course, the Llama book.
Post reply on HN