Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

21–30 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#21
The whole environment of the newer gTLDs just feels… gross. I rarely find a reputable business that is using anything but .com or .co.XX as the primary domain.

Putting on my regular-person hat: When I see a billboard or print ad with e.g. `example.travel`, I read that as a social media handle and not a website address like `example.com` would convey. In public perception, dot com means websites. Always has.

(Tangentially, the `.sucks` TLD in particular should never have been allowed. How many brands out there have to maintain a perfunctory registration there just to prevent somebody else from doing so?)

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#22

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

The problem is the new gTLDs don't increase the useful supply of domains.

For casual usage like personal blogs and whatnot? Sure, use whatever.

But if I was starting a web-based business and couldn't afford the .com? I'd rename the company before I'd use .xyz - if your business takes off the squatters will notice and raise their prices, so the .com will never be cheaper.

If you got an "urgent e-mail" saying your employer needed you to confirm you're legally allowed to work, and they directed you to experianrtw.app - would you go there and send them a photo of your passport?

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#24

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

They're different. Companies register all kinds of crazy domains and redirect you through them all the time. Why is it crazy that some marketing person at Dell thought it would be cool to link people to 'dell dot shop'? I would check the certificates, but honestly only as a precaution. If the website looks correct that isn't such an insane thing.

That is exactly why it's so dangerous and effective versus your example.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#26
> John Levine is author of the book “The Internet for Dummies” and president of CAUCE. Levine said adding more TLDs without a much stricter registration policy will likely further expand an already plentiful greenfield for cybercriminals.

Holy shit. CAUCE is a name I haven't heard in a long time. He's been around for a while and is one of the good ones.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#27
post #13
post #5

I have always thought the infinite proliferation of TLDs was a stupid idea. I'd be enlightened if I could think of one scenario that benefits from it outside of the registrars.

There are lots of people called John Smith. They all want a domain name. There's only so many variations of jsmith, j-smith, etc you can squeeze into .com, .net, and a few others. Why shouldn't they be able to buy a domain name which contains their name? Is it useful to be able to differentiate between McDonald's the restaurant and McDonald's the legal firm and McDonald's garage? Why shouldn't each of those industrie…

And… predictably, johnsmith.com ends up offering no utility to any of the John Smiths out there because it’s being held for ransom by a squatter:

https://www.afternic.com/forsale/johnsmith.com

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#28

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

The lions share of issues with domains would go away if we made squatting illegal, or at the least, extremely expensive.

Tbh I'm increasingly thinking that just about any speculative instrument in the economy is just grift and drag. If you want to make money, make things. Stop trying to extract rent or exorbitant prices for land, for domains, for PS5s, etc. Feels like 9/10ths of the economy now is nothing but fucking middlemen, when we have a dearth of need of ANY middlemen at all anymore.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#29

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

I do not think so. I think if someone would have made an effort to rip off the real Dell site I would fall for it. I am just so lucky that scammer mostly prefer to go after the easier marks.

I am not sure what a better solution could be. The idea of EV certificates was good but executed poorly. Maybe a way to link certificated to business IDs.

I do however still prefer more gTLDs to minimize domain squatting.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#30

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

The problem is the new gTLDs don't increase the useful supply of domains. For casual usage like personal blogs and whatnot? Sure, use whatever. But if I was starting a web-based business and couldn't afford the .com? I'd rename the company before I'd use .xyz - if your business takes off the squatters will notice and raise their prices, so the .com will never be cheaper. If you got an "urgent e-mail" saying your empl…

There are a few options, though. The fact that .io got so popular shows that we are not forever chained to .com. It's just that a lot of the nuTLD options are honestly hilariously bad, most of them are just lame. My personal top picks are ".online" and ".software" with mention to ".network" but they're all WAY too long. I actually use ".cafe" for my personal stuff because it's short and cute. Obviously can't use that for your SV rocketship company though.

Would it have been so hard to sit down and pick a couple short ones - yknow, ones people might actually use?

Post reply on HN