Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

121–130 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#121
post #104

When I used to run my own email, .top and .xyz received an automatic -10 on spam evaluation. I can't remember a single legitimate website that I actually used and would have had an account on from these TLDs; all I ever saw was spam.

I thought the same, out of the 5 domains listed, I'm not sure I have used any legitimate website using them, so I might as well block them entirely

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#122

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

I'm doubtful that most non-technical people familiarize themselves with TLDs/domain names. They use a search provider for whatever they need. As far as emails/phishing goes, it's a game of cat and mouse; it will never be over. Basically, don't trust unprompted email links and just go to the site if it's something you really want.

The always-search-instead-of-bookmark practice is then introduced this situation https://www.bleepingcomputer.com/news/security/sneaky-amazon...

Its really an unsolvable cat and mouse game without proper familiarising oneself with the dos and don'ts of the internet.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#123
post #104

When I used to run my own email, .top and .xyz received an automatic -10 on spam evaluation. I can't remember a single legitimate website that I actually used and would have had an account on from these TLDs; all I ever saw was spam.

I hope this sentiment isn't too widespread... I use .xyz for my personal blog and primary email :shrug:

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#124
post #64

Earlier quoted context omitted.

I would argue if you aren't doing some combination of: - Hosting a website - Operating email accounts - Infrastructure (mail, DNS, etc.) - Misc. Services (Minecraft server, TeamSpeak server, something) Then you're squatting. Like if you own turkeyonapig.com and it's literally just a web page with a picture of a turkey sitting on a pig? Not squatting. It's odd but it's clearly doing exactly what it's meant to be doing…

> It's a tricky thing but not impossible to figure out. Good to hear. So after that you'll be sorting out world peace - right?

I really don't think eliminating domain squatters is some impossible task. you could probably just tax sales of domain names to death (90% sales tax on any resold domain names) to disincentivize it vs registration upkeep costs.

Squatters are a massive blight on the internet.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#125
post #5

I have always thought the infinite proliferation of TLDs was a stupid idea. I'd be enlightened if I could think of one scenario that benefits from it outside of the registrars.

have you gone through the process of naming and securing domains for startups over and over again because let me tell you, it's brutal. the more TLDs, the better.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#126
post #118

Earlier quoted context omitted.

I see a lot of personal blogs that use .xyz here on HN.

I use .XYZ because it was pretty cheap when I bought it

I do too, aesthetically it's great. Unfortunately the rise in phishing from xyz domains means if you use it to send email your deliverability is likely to suck.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#127
post #24

Earlier quoted context omitted.

They're different. Companies register all kinds of crazy domains and redirect you through them all the time. Why is it crazy that some marketing person at Dell thought it would be cool to link people to 'dell dot shop'? I would check the certificates, but honestly only as a precaution. If the website looks correct that isn't such an insane thing. That is exactly why it's so dangerous and effective versus your example…

> Companies register all kinds of crazy domains and redirect you through them all the time That's the real problem with domain trust these days. Companies go out of their way to make sure you know to only visit official links, and then do stupid stuff like buying vanity domains for one-time deals, or make you click through mailchimp tracking URLs because marketing tracking is more important than your customers fallin…

There is no domain trust problem, because there is no trust to be had on domains.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#128

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

The problem is the new gTLDs don't increase the useful supply of domains. For casual usage like personal blogs and whatnot? Sure, use whatever. But if I was starting a web-based business and couldn't afford the .com? I'd rename the company before I'd use .xyz - if your business takes off the squatters will notice and raise their prices, so the .com will never be cheaper. If you got an "urgent e-mail" saying your empl…

What it you get an email from [yourbank].bank? Or if your mother got one?

It's never a single signal, and the more legitimate a domain looks, the bigger a chance is that someone fells victim to a scam.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#129

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

Maybe, maybe not. [citation needed] But store.apple.com is perfectly legit, so what’s wrong with apple.shop[0]? Sure, you and I know that one is a subdomain and one is a TLD. How many random folks on the street in Des Moines know this? 15%? Less? “Say what? It matters which end the ‘shop’ part is on? Whose brilliant idea was that?”

[0] sigh Apparently nothing is wrong with it, as it redirects to apple.com. So much for that example; take in the spirit intended.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#130
it seems like if this is a problem, then the whole domain system is a problem.

there's nothing that makes .top or .xyz more problematic than .net or .org. if the assertion is that it's too confusing for people to pay attention to all the parts of a domain name, then why do domain names continue to have multiple parts? let's just deprecate everything other than .com and be done with it.

Post reply on HN