gTLDs also have cost risks like when .tech was taken over by a holding company and then 3x the registration price. Who knows about next year and the year after that.
Phishers Love New TLDs Like .shop, .top and .xyz
41–50 of 220 posts
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#42Earlier quoted context omitted.
The people who would fall for that would probably also fall for `dell.computerdealshop.com` though
They're different. Companies register all kinds of crazy domains and redirect you through them all the time. Why is it crazy that some marketing person at Dell thought it would be cool to link people to 'dell dot shop'? I would check the certificates, but honestly only as a precaution. If the website looks correct that isn't such an insane thing. That is exactly why it's so dangerous and effective versus your example…
That's the real problem with domain trust these days. Companies go out of their way to make sure you know to only visit official links, and then do stupid stuff like buying vanity domains for one-time deals, or make you click through mailchimp tracking URLs because marketing tracking is more important than your customers falling for phishing. Those vanity domains then end up expiring, and now emails and web links that used to go to an official $brand server are all ready to be swooped up by scammers. Customers never stood a chance.
This isn't a TLD problem. It's a shitty company problem.
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#43Re: Phishers Love New TLDs Like .shop, .top and .xyz
#44My biggest complaint is that some large retailers/services completely refuse to believe it is a valid domain. (I'm looking at you, Walgreens. You blocked me during a pandemic from signing up for a vaccine with my actual email address, which is why fuckwalgreens@myother.domain is now my email in your system.)
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#45The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…
I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#46Earlier quoted context omitted.
> a web page with a picture of a turkey sitting on a pig? Not squatting GPT/Cursor will create that page for you in 5 min. I bet a NotSquattingAsAService startups will appear which will create the "not squatting" fake site for you for $2.
I mean, that's an improvement in my mind over millions of insipid "BUY THIS DOMAIN!" web pages. At the least the internet would be more interesting? But also like, then you aren't advertising it for sale. So I'm wondering how many offers you're going to get to sell that domain, which is the point of squatting it.
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#47Earlier quoted context omitted.
The problem is the new gTLDs don't increase the useful supply of domains. For casual usage like personal blogs and whatnot? Sure, use whatever. But if I was starting a web-based business and couldn't afford the .com? I'd rename the company before I'd use .xyz - if your business takes off the squatters will notice and raise their prices, so the .com will never be cheaper. If you got an "urgent e-mail" saying your empl…
There are a few options, though. The fact that .io got so popular shows that we are not forever chained to .com. It's just that a lot of the nuTLD options are honestly hilariously bad, most of them are just lame. My personal top picks are ".online" and ".software" with mention to ".network" but they're all WAY too long. I actually use ".cafe" for my personal stuff because it's short and cute. Obviously can't use that…
I’ve been seeding government and business forms with a .io email address for years (to counter gmail dominance), and I’m quite concerned about the situation now.
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#48Re: Phishers Love New TLDs Like .shop, .top and .xyz
#49Earlier quoted context omitted.
The people who would fall for that would probably also fall for `dell.computerdealshop.com` though
They're different. Companies register all kinds of crazy domains and redirect you through them all the time. Why is it crazy that some marketing person at Dell thought it would be cool to link people to 'dell dot shop'? I would check the certificates, but honestly only as a precaution. If the website looks correct that isn't such an insane thing. That is exactly why it's so dangerous and effective versus your example…
EDIT : and ninjaed...
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#50The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…
That wasn't what the article stated. The article stated that the problem is that the new TLDs are so cheap as to be disposable, and the registration requirements are lax. The combination makes them attractive to criminals.
It's literally the first sentence of the article:
"Phishing attacks increased nearly 40 percent in the year ending August 2024, with much of that growth concentrated at a small number of new generic top-level domains (gTLDs) — such as .shop, .top, .xyz — that attract scammers with rock-bottom prices and no meaningful registration requirements, new research finds."