Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

161–170 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#161

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

Even aside from that, you probably want to register your own .sucks and .rocks, which just means whoever operates that registry gets to make a bunch of money from companies squatting domains that nobody wanted and bring no value to the world.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#162

Earlier quoted context omitted.

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

When a scam hits someone's inbox or text message, it finds them in a particular time in their life, in a particular state of mind, and in a particular context. It's not just about how gullible or uninformed or whatever they are. They may be tired, they may be drunk, they may be spending all their energy worrying about a sick relative, or trying not to. They may have just been shopping for a computer, maybe even a del…

It would be nice if browsers surfaced the information about when you last visited a site. In the certificate information panel for Firefox you can find things like, "You visited this site 1067 times before" which is helpful information when evaluating if you're on the site you think you're on.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#163
post #143

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

I wonder if we could add some type of verification registry. It would be nice if browser's could have a big indicator saying that this website is verified to associated with Dell inc.

That was EV certificates. They were finally removed from browsers completely around five years ago because they didn’t actually work. At all. The problems were largely social. Plenty has been written about it, you can find it by searching.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#164

Once I found I couldn’t iMessage a .xyz link I decided to stay away…

Given that .zip is now a TLD, I completely support not automatically linkifying things that might be links.

(If you used "https" and made it a full URL, that's different.)

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#165
post #107

Earlier quoted context omitted.

When a scam hits someone's inbox or text message, it finds them in a particular time in their life, in a particular state of mind, and in a particular context. It's not just about how gullible or uninformed or whatever they are. They may be tired, they may be drunk, they may be spending all their energy worrying about a sick relative, or trying not to. They may have just been shopping for a computer, maybe even a del…

> Seeing dell.computerdealshop.com will snap a lot of people out of it where seeing dell.shop would not have. Would love to see citations for that.

Here's one [0]!

[0] : https://news.ycombinator.com/item?id=42307876

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#166
The problem is not new TLDs, the real problem with phishings in 2024 is that the free Cloudflare layer allows phishers to be protected from automatic phishing detection tools like the ones I develop at my current job.

They also don't offer any programs for trusted third parties so we have to spend a lot of time bypassing and paying for services that skip Cloudflare instead of taking down phishing sites.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#167
post #143

Earlier quoted context omitted.

I wonder if we could add some type of verification registry. It would be nice if browser's could have a big indicator saying that this website is verified to associated with Dell inc.

That was EV certificates. They were finally removed from browsers completely around five years ago because they didn’t actually work. At all. The problems were largely social. Plenty has been written about it, you can find it by searching.

Well, the original HTTPS certificates too were supposed to work like that; I remember reading a security article criticizing the EV proposal by quoting the old (circa 1998?) policy statements of different CA's and showing that they're pretty much identical to the EV requirements.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#168
post #27
post #13

Earlier quoted context omitted.

There are lots of people called John Smith. They all want a domain name. There's only so many variations of jsmith, j-smith, etc you can squeeze into .com, .net, and a few others. Why shouldn't they be able to buy a domain name which contains their name? Is it useful to be able to differentiate between McDonald's the restaurant and McDonald's the legal firm and McDonald's garage? Why shouldn't each of those industrie…

And… predictably, johnsmith.com ends up offering no utility to any of the John Smiths out there because it’s being held for ransom by a squatter: https://www.afternic.com/forsale/johnsmith.com

Please don't let the facts get in the way of an argument from principle.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#169
post #6

Earlier quoted context omitted.

Interesting! Now that you mention it, I did buy a .luxury domain for this purpose - a Gemini server. I also bought a .ski to have a domain with my (polish) last name.

It's great to be able to get silly domains for projects, back to the old days of IRC vanity hosts, but can you imagine seeing a link to something like jackets.luxury and going "yeah that seems legit, I'm definitely giving them my card details"

By that logic, would you pull out your credit card if you got linked jacketsluxury.com? .luxury is about twice as expensive as .com so I'm more suspicious of .com sites than of vanity TLDs.

I think there's a generational divide here, the older people seem to distrust more recent TLDs for some reason while younger people don't really care about them.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#170

Earlier quoted context omitted.

It's great to be able to get silly domains for projects, back to the old days of IRC vanity hosts, but can you imagine seeing a link to something like jackets.luxury and going "yeah that seems legit, I'm definitely giving them my card details"

By that logic, would you pull out your credit card if you got linked jacketsluxury.com? .luxury is about twice as expensive as .com so I'm more suspicious of .com sites than of vanity TLDs. I think there's a generational divide here, the older people seem to distrust more recent TLDs for some reason while younger people don't really care about them.

Nice thing about IRC is that you could do it for free so long as you controlled your PTR record.
Post reply on HN