Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

101–110 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#101

The whole environment of the newer gTLDs just feels… gross. I rarely find a reputable business that is using anything but .com or .co.XX as the primary domain. Putting on my regular-person hat: When I see a billboard or print ad with e.g. `example.travel`, I read that as a social media handle and not a website address like `example.com` would convey. In public perception, dot com means websites. Always has. (Tangenti…

> When I see a billboard or print ad with e.g. `example.travel`, I read that as a social media handle and not a website address like `example.com` would convey.

This is where I think the new gTLDs registries could do better. Using your domain as a handle on Bluesky is a perfect example of something they could push for to grow the industry, but they seem to think the status quo with a sprinkle of price discrimination is the winning formula.

Most of the new gTLDs work great as domain verified social media handles, but no one is going to use them for that if all the good keywords are classified as premium with $100+ annual renewal fees. However, if you make them too cheap and they get popularized, domain investors will register everything good and try to flip them.

I think first year premium pricing strikes a good balance that doesn't limit novel, non revenue generating use cases too much. Charging $100-200 for the first year causes a very large increase in the amount of capital domain flippers need to invest to acquire a large portfolio of good names.

If Bluesky catches on I think we could hit a point where non-technical people are suddenly shocked when the see someone "using their social media handle for a website." Getting back to having people understand there's more than just Facebook and Twitter would be a step in the right direction IMO, so it would be nice to see Bluesky continue to gain popularity.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#102
post #97

Earlier quoted context omitted.

> Whether people are more easily fooled by dell.shop dell.computershop.com is a non sequitur from the rather wordy disquisition about why people fall for the scams in general. It isn't. People fall because probabilities align. Something can catch their eye to knock them out of it. A bad URL is a bad probability (for the scammer) in the chain, a really good URL is another good probability. If your assessment is that b…

Most people don't understand URLs. Remember that Google was (is?) trying to remove the URL bar. Not just because it reinforces search as the main product and gateway to the web, but also because URLs are kind of hard for most people. Which brings us to the original argument: is this a reason to ban gTLDs? Surely the cost of banning gTLDs outweighs the enormous benefits of making it easy for society's productive users…

Many people do not understand URLs, many people do, and many people have an understanding in between. And they are all targets for scammers.

And I don't think gTLDs should be banned! But I don't like bad arguments even when they support my preference.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#103

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

What looks like squatters might also be people who just want their own domain only for email, not hosting.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#105
post #104

When I used to run my own email, .top and .xyz received an automatic -10 on spam evaluation. I can't remember a single legitimate website that I actually used and would have had an account on from these TLDs; all I ever saw was spam.

I see a lot of personal blogs that use .xyz here on HN.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#107

Earlier quoted context omitted.

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

When a scam hits someone's inbox or text message, it finds them in a particular time in their life, in a particular state of mind, and in a particular context. It's not just about how gullible or uninformed or whatever they are. They may be tired, they may be drunk, they may be spending all their energy worrying about a sick relative, or trying not to. They may have just been shopping for a computer, maybe even a del…

> Seeing dell.computerdealshop.com will snap a lot of people out of it where seeing dell.shop would not have.

Would love to see citations for that.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#108
post #90

The whole environment of the newer gTLDs just feels… gross. I rarely find a reputable business that is using anything but .com or .co.XX as the primary domain. Putting on my regular-person hat: When I see a billboard or print ad with e.g. `example.travel`, I read that as a social media handle and not a website address like `example.com` would convey. In public perception, dot com means websites. Always has. (Tangenti…

I’m disappointed at the arbitrary decision-making that lets the registrars deem certain domains to automatically be “premium” and mark them up appropriately. It feels like that’s an additional layer of extortion on top (doubly so when the premium price carries into the full renewal price, too).

So, to be clear, the following tend to be seen as problems by their interested parties:

  * withholding tons of domains to watch them go up in value means people can't get those domains (scammers, regular people)
  * registries do not make a high price when they sell high-value domains (registries)
  * there's only so many words / groups of words that are easily typeable (everyone)
  * reducing scarcity reduces the value of digital real estate (domain squatters / traders)
Which of these issues / values / interested parties are more important to help than others, and what, if anything, should change?

I, personally, tend to be in favor of reducing the impact of scalpers by increasing total available volume. As a consequence, I'm also willing to accept some terms for the registries that they get to set higher prices for the most premium of their domains to:

  * sweeten the pot for both registries and registrars to even support all these new domains
  * reduce a squatter / trader / speculator / scalper's ability to sit on vast tracts of digital land.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#109
I use a .xyz for my personal domain (I could get my real name as the domain, and it was cheap). I use FastMail for email. Deliverability has been fine, with one exception - Radisson Red hotels. I’ve had two occasions in the last year when I’ve needed to email different Radisson Red properties, and both silently dropped emails from .xyz domains.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#110
post #5

I have always thought the infinite proliferation of TLDs was a stupid idea. I'd be enlightened if I could think of one scenario that benefits from it outside of the registrars.

Domains are the ultimate identity system for building a more trustworthy internet without handing over control to some kind of verified ID scheme or being forced into publishing your personal details to gain credibility.

You can build reputation and trust using a handle, even if it's not associated with your real world identity. For example, I know that if 'ryao' replies to a question about ZFS, the response can be considered trustworthy. I don't know who that is or even what country they live in, but I know they're a contributor that isn't speculating or guessing when they reply and that's all that matters to me.

Domains can be used as verifiable, globally unique handles which simplifies things for the average user because it makes it easier to help users avoid impersonation and confusion if you can point them to something simple and verifiable. For example, look at Bluesky [1].

I've been wanting domain based namespaces and handles for a solid 5 years because it just makes sense. Here's my oldest mention of it (asking why package managers don't use domain verified namespacing) I have on HN [2]:

> It seems like a waste to me when I'm required to register a new identity for every package manager when I already have a globally unique, extremely valuable (to me), highly brandable identity that costs $8 / year to maintain.

You can tell it's old because .com domains only costed $8 back then. IMHO, domain based handles are the #1 reason to use Bluesky over X/Twitter. People used to spend $10-15k buying "noteworthiness" via fake articles, etc. to get verified on Twitter. I can't find any links because search results are saturated with talk of X wanting $1000 per month for organization validation (aka a gold check mark). Domain validation is just as good as that kind of organization validation, at least for well known individuals and organizations.

Given that, I think there would be a bigger market for domains if domain validated identities catch on. It could even spawn specialty gTLDs that do extra identity or notoriety checks (if that's allowed) or maybe attestations would become a big thing if there were an easy way to do them against a domain verified handle.

1. https://bsky.social/about/blog/3-6-2023-domain-names-as-hand...

2. https://news.ycombinator.com/item?id=24674882

Post reply on HN