Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

41–50 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#42
post #24

Earlier quoted context omitted.

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

They're different. Companies register all kinds of crazy domains and redirect you through them all the time. Why is it crazy that some marketing person at Dell thought it would be cool to link people to 'dell dot shop'? I would check the certificates, but honestly only as a precaution. If the website looks correct that isn't such an insane thing. That is exactly why it's so dangerous and effective versus your example…

> Companies register all kinds of crazy domains and redirect you through them all the time

That's the real problem with domain trust these days. Companies go out of their way to make sure you know to only visit official links, and then do stupid stuff like buying vanity domains for one-time deals, or make you click through mailchimp tracking URLs because marketing tracking is more important than your customers falling for phishing. Those vanity domains then end up expiring, and now emails and web links that used to go to an official $brand server are all ready to be swooped up by scammers. Customers never stood a chance.

This isn't a TLD problem. It's a shitty company problem.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#44
My primary catch-all email domain for accounts is at a silly TLD (.rodeo).

My biggest complaint is that some large retailers/services completely refuse to believe it is a valid domain. (I'm looking at you, Walgreens. You blocked me during a pandemic from signing up for a vaccine with my actual email address, which is why fuckwalgreens@myother.domain is now my email in your system.)

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#45

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

[dead]

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#46

Earlier quoted context omitted.

> a web page with a picture of a turkey sitting on a pig? Not squatting GPT/Cursor will create that page for you in 5 min. I bet a NotSquattingAsAService startups will appear which will create the "not squatting" fake site for you for $2.

I mean, that's an improvement in my mind over millions of insipid "BUY THIS DOMAIN!" web pages. At the least the internet would be more interesting? But also like, then you aren't advertising it for sale. So I'm wondering how many offers you're going to get to sell that domain, which is the point of squatting it.

That's not how most squatting pages are sold. They are registered for sale in places like NameCheap and you can see it directly when you search for domains.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#47

Earlier quoted context omitted.

The problem is the new gTLDs don't increase the useful supply of domains. For casual usage like personal blogs and whatnot? Sure, use whatever. But if I was starting a web-based business and couldn't afford the .com? I'd rename the company before I'd use .xyz - if your business takes off the squatters will notice and raise their prices, so the .com will never be cheaper. If you got an "urgent e-mail" saying your empl…

There are a few options, though. The fact that .io got so popular shows that we are not forever chained to .com. It's just that a lot of the nuTLD options are honestly hilariously bad, most of them are just lame. My personal top picks are ".online" and ".software" with mention to ".network" but they're all WAY too long. I actually use ".cafe" for my personal stuff because it's short and cute. Obviously can't use that…

Unfortunately, .io is now also unsafe with the upcoming transfer away from the UK; another cautionary tale for those considering not getting a .com.

I’ve been seeding government and business forms with a .io email address for years (to counter gmail dominance), and I’m quite concerned about the situation now.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#48
If you see a phishing link, you can perform a DNS A record request to find their IPs, typically behind Cloudflare. You can report them to Cloudflare. Their WHOIS record will tell you who their registrar is, and again you can report them there too. If they use URL shorteners, you can report those.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#49
post #24

Earlier quoted context omitted.

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

They're different. Companies register all kinds of crazy domains and redirect you through them all the time. Why is it crazy that some marketing person at Dell thought it would be cool to link people to 'dell dot shop'? I would check the certificates, but honestly only as a precaution. If the website looks correct that isn't such an insane thing. That is exactly why it's so dangerous and effective versus your example…

Maybe companies should stop doing that then ? Also, homonyms aren't uncommon for smaller companies, especially across the world.

EDIT : and ninjaed...

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#50

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me.

That wasn't what the article stated. The article stated that the problem is that the new TLDs are so cheap as to be disposable, and the registration requirements are lax. The combination makes them attractive to criminals.

It's literally the first sentence of the article:

"Phishing attacks increased nearly 40 percent in the year ending August 2024, with much of that growth concentrated at a small number of new generic top-level domains (gTLDs) — such as .shop, .top, .xyz — that attract scammers with rock-bottom prices and no meaningful registration requirements, new research finds."

Post reply on HN