Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

111–120 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#111
post #72

I wonder if part of the "business model" behind the ever-growing gTLD list is that all the companies with well-known brands essentially have to also register their brand under the new TLD as well if they don't want to risk it being taken by criminals or competitors. Why only make money once by selling apple.com if you can also sell apple.biz, apple.xyz, apple.froom etc ad infinitum?

I once worked for a big Hollywood studio and they finally stopped registering their name in every new .tld. They reasoned that if anyone used the domain in a way that is a trademark violation, then they could shut them down in court. Otherwise, they'd be chasing ever-increasing (extortion) rates for each new .tld.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#112

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

That’s kinda the point. Scammers want to deal with the poorly informed, the gullible, the vulnerable. They concomitantly prefer that the wary and street-smart select themselves away. A marketing professional would recognise the effective segmentation going on, and every new TLD is an opportunity in that regard.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#113
post #89

Earlier quoted context omitted.

This is very regional. .co.xx is common in Britain (.co.uk), Japan (.co.jp), New Zealand (.co.nz) and probably others. It's perfectly legitimate for a site linked to those countries.

NZ didn't allow registration of raw .nz domains until 2014 so anything registered before that was a .co.nz or similar. It's still more common than .nz due to inertia / muscle memory I guess. I get weird looks when I give people my (name).nz email address - usually people ask if I meant .co.nZ

BR went the other way. Registration of raw .br domains used to be allowed for universities, but AFAIK other than grandfathered registrations it's no longer allowed (new registrations have to use .edu.br).

My suspicion is that it was due to abuse; a long time ago, I noticed some university had registered IIRC .co.br (our correct equivalent to the .com gTLD is .com.br; this is a notable exception to the assertion above that "I rarely find a reputable business that is using anything but .com or .co.XX as the primary domain", since plenty of reputable businesses use .com.br as their primary domain, not .co.br which doesn't exist).

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#115
post #90

Earlier quoted context omitted.

I’m disappointed at the arbitrary decision-making that lets the registrars deem certain domains to automatically be “premium” and mark them up appropriately. It feels like that’s an additional layer of extortion on top (doubly so when the premium price carries into the full renewal price, too).

So, to be clear, the following tend to be seen as problems by their interested parties: * withholding tons of domains to watch them go up in value means people can't get those domains (scammers, regular people) * registries do not make a high price when they sell high-value domains (registries) * there's only so many words / groups of words that are easily typeable (everyone) * reducing scarcity reduces the value of…

I think first year premium pricing makes a lot of sense. I'm not sure what the average time to sell is for a domain investor, but say it's 10 years for an easy example.

If you go from a standard registration price of $12 / year to a first year premium of $132, you double the 10 year carrying cost of a domain. That, naively, means domain investors can only speculate on half as many domains.

By having a first year premium price and then dropping domains back into the 'standard' tier, you also leave registrants with a semblance of price protections via section 2.10c of the registry agreement. As-is, premium domains have zero guarantees when it comes to premium renewal pricing.

There's a lot of room between squeezing domain investors and asking registrants to pay $100-1000+ per year for premium domains.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#116
post #82

Earlier quoted context omitted.

> The powers that be could very well decide to just promote it to be a gTLD No, they can’t do that. Every two-letter TLD is defined to be a ccTLD, and nothing else.

If they did that anyway, who would stop them? This seems like a great time to make an exception.

Literally, these are arbitrary strings following arbitrary rules. It's time to ditch ICANN and develop a parallel DNS that makes sense for today not the 90s.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#117
It's open season on suckers.

With a new crypto-friendly administration coming in, it's going to get much worse. If you haven't been following this, there's a whole industry pushing "meme coins" via pump and dump operations. Some even admit they are pump and dump operations.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#118
post #104

When I used to run my own email, .top and .xyz received an automatic -10 on spam evaluation. I can't remember a single legitimate website that I actually used and would have had an account on from these TLDs; all I ever saw was spam.

I see a lot of personal blogs that use .xyz here on HN.

I use .XYZ because it was pretty cheap when I bought it

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#119

Earlier quoted context omitted.

> Companies register all kinds of crazy domains and redirect you through them all the time That's the real problem with domain trust these days. Companies go out of their way to make sure you know to only visit official links, and then do stupid stuff like buying vanity domains for one-time deals, or make you click through mailchimp tracking URLs because marketing tracking is more important than your customers fallin…

I wholeheartedly agree. Subdomains exist for a reason. Vanity domains are so incredibly sloppy and unserious. Another issue is that they can make password management more of a chore. Every time I need to look up my Microsoft login, I have to remember to actually look up “live.com”. Except sometimes the login page is served from “microsoft.com”. Oops, you forgot your password and reset it; now your password for the ot…

bitwarden can list multiple domains in one entry for a password - it might be good to find out if you're manager can do that and merge some?
Post reply on HN