Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

61–70 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#61
post #2

> new gTLDs introduced in the last few years command just 11 percent of the market for new domains, but accounted for roughly 37 percent of cybercrime domains reported between September 2023 and August 2024. > .com and .net domains made up approximately half of all domains registered...they accounted for just over 40 percent of all cybercrime domains. Hardly earth shattering. .net and .com are still pulling 80% of th…

.net and .com are still pulling 80% of their weight when it comes to cybercrime.

The article states it's half that.

"while .com and .net domains made up approximately half of all domains registered in the past year… they accounted for just over 40 percent of all cybercrime domains. Interisle says an almost equal share — 37 percent — of cybercrime domains were registered through new gTLDs."

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#62

Earlier quoted context omitted.

The problem is the new gTLDs don't increase the useful supply of domains. For casual usage like personal blogs and whatnot? Sure, use whatever. But if I was starting a web-based business and couldn't afford the .com? I'd rename the company before I'd use .xyz - if your business takes off the squatters will notice and raise their prices, so the .com will never be cheaper. If you got an "urgent e-mail" saying your empl…

There are a few options, though. The fact that .io got so popular shows that we are not forever chained to .com. It's just that a lot of the nuTLD options are honestly hilariously bad, most of them are just lame. My personal top picks are ".online" and ".software" with mention to ".network" but they're all WAY too long. I actually use ".cafe" for my personal stuff because it's short and cute. Obviously can't use that…

I use .network for my internal network with a proper FQDN. This allows me to get certs for internal services that validate in all browsers.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#63
post #24

Earlier quoted context omitted.

They're different. Companies register all kinds of crazy domains and redirect you through them all the time. Why is it crazy that some marketing person at Dell thought it would be cool to link people to 'dell dot shop'? I would check the certificates, but honestly only as a precaution. If the website looks correct that isn't such an insane thing. That is exactly why it's so dangerous and effective versus your example…

> Companies register all kinds of crazy domains and redirect you through them all the time That's the real problem with domain trust these days. Companies go out of their way to make sure you know to only visit official links, and then do stupid stuff like buying vanity domains for one-time deals, or make you click through mailchimp tracking URLs because marketing tracking is more important than your customers fallin…

A little searching shows Dell have dell.to, used as a link shortener, even though Dell has little business in Tonga.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#64
post #33

Earlier quoted context omitted.

>The lions share of issues with domains would go away if we made squatting illegal, or at the least, extremely expensive. How do you define squatting? Is the owner of nissan.com "squatting" on it because he wouldn't sell to the japanese car company? How much interest do you need in a given domain before it's not squatting?

I would argue if you aren't doing some combination of: - Hosting a website - Operating email accounts - Infrastructure (mail, DNS, etc.) - Misc. Services (Minecraft server, TeamSpeak server, something) Then you're squatting. Like if you own turkeyonapig.com and it's literally just a web page with a picture of a turkey sitting on a pig? Not squatting. It's odd but it's clearly doing exactly what it's meant to be doing…

> It's a tricky thing but not impossible to figure out.

Good to hear. So after that you'll be sorting out world peace - right?

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#65

The whole environment of the newer gTLDs just feels… gross. I rarely find a reputable business that is using anything but .com or .co.XX as the primary domain. Putting on my regular-person hat: When I see a billboard or print ad with e.g. `example.travel`, I read that as a social media handle and not a website address like `example.com` would convey. In public perception, dot com means websites. Always has. (Tangenti…

Remember reading Ford Motor Company already registered FordSucks.com and a bunch of permutations of that way back when.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#66

The whole environment of the newer gTLDs just feels… gross. I rarely find a reputable business that is using anything but .com or .co.XX as the primary domain. Putting on my regular-person hat: When I see a billboard or print ad with e.g. `example.travel`, I read that as a social media handle and not a website address like `example.com` would convey. In public perception, dot com means websites. Always has. (Tangenti…

I never deal with co.xx to be honest. Most websites I visit are on ccTLDs. Whenever I see a .com link to any local business, I start out by assuming it's a scam website. That said, .app has found plenty of adoption. Tech companies absolutely love .io and .ai is now also gaining popularity. The good American URLs have all been bought years ago so people flock to ccTLDs and gTLDs for new products and businesses. Even .…

This is very regional.

.co.xx is common in Britain (.co.uk), Japan (.co.jp), New Zealand (.co.nz) and probably others. It's perfectly legitimate for a site linked to those countries.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#67

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

The problem is the new gTLDs don't increase the useful supply of domains. For casual usage like personal blogs and whatnot? Sure, use whatever. But if I was starting a web-based business and couldn't afford the .com? I'd rename the company before I'd use .xyz - if your business takes off the squatters will notice and raise their prices, so the .com will never be cheaper. If you got an "urgent e-mail" saying your empl…

If I got an 'urgent email' I wouldn't go to any domain, I would contact my employer directly and confirm with them before doing anything. The people who would fall for this phishing scam would fall for almost any domain, because it's not about the domain.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#68
post #55

Earlier quoted context omitted.

It's not a particularly hard problem. Most countries have rules on what you can use as a business name or register as a trademark. Domain names are just more of the same. And you don't really own your domain. You are just renting it from whichever authority is responsible for the TLD. If you stop paying, the authority will eventually take it back.

Trademarks are specific to the field it is used on. Classic example is Apple Records vs Apple Computers, which one should get apple.com?

And there are also businesses with identical names. But the basic idea was already established long before the internet. If you have a legitimate claim to a name, you have a legitimate claim to that name. There may be multiple entities with a legitimate claim to a particular name, in which case the first one that used it in a particular context gets to use it in that context. And if you think that someone is using a name you have claimed in a misleading way or acting in bad faith, you can sue them and let the courts decide.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#69
A friend of our family almost got scammed from a .top domain. They convinced her she needed 'tech support' and transferred $30,000 from her savings to checking and tried to get her to go to the bank to get more money. She got suspicious and got new bank accounts and thankfully didn't get any actual money stolen.

She's retired and it could have ruined her financially. I don't think she realizes how close she was to this.

The software they used bypassed windows defender because it was legitimate software called 'screen connect'. I was able to remove it pretty easily. It looked like a reverse-shell attached to a windows service (small .exe with no front-end).

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#70
post #33

Earlier quoted context omitted.

>The lions share of issues with domains would go away if we made squatting illegal, or at the least, extremely expensive. How do you define squatting? Is the owner of nissan.com "squatting" on it because he wouldn't sell to the japanese car company? How much interest do you need in a given domain before it's not squatting?

I would argue if you aren't doing some combination of: - Hosting a website - Operating email accounts - Infrastructure (mail, DNS, etc.) - Misc. Services (Minecraft server, TeamSpeak server, something) Then you're squatting. Like if you own turkeyonapig.com and it's literally just a web page with a picture of a turkey sitting on a pig? Not squatting. It's odd but it's clearly doing exactly what it's meant to be doing…

>I would argue if you aren't doing some combination of: [...]

cloudflare offers free website hosting and email forwarding, so it's basically free for a squatter to check those boxes.

>I mean, it depends. One would argue that people going to nissan.com are clearly looking for the Japanese car company, so it's in the public's interest that that domain be sold to them.

So you basically want the Kelo v. City of New London decision to be applied to domains as well? You own "erictrump.com" but aren't the president-elect's son? Well tough luck because it's "in the public's interest" that president-elect's son gets it rather than you.

Post reply on HN