Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

171–180 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#171
post #82

Earlier quoted context omitted.

That's because it's a ccTLD, not because it's not dot-com though. The powers that be could very well decide to just promote it to be a gTLD if they wanted to not destroy stuff for no reason. Actual gTLDs aren't susceptible to the same kinds of issues.

> The powers that be could very well decide to just promote it to be a gTLD No, they can’t do that. Every two-letter TLD is defined to be a ccTLD, and nothing else.

Yes they can. They did it before after the Soviet Union broke up and they kept the .su TLD. It's still active. I'd argue that keeping around .io is more important than keeping .su around, seeing how many people and businesses use .io domains.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#172

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

Have you seen the domains Microsoft uses? Half the time I am not sure if they are genuine or not, it's actually crazy. Sometimes they use .com, other times .ms. Sometimes Microsoft is in the top-level other times it's in the second-level. Sometimes they have no subdomain, sometimes they have two. It's utterly inconsistent and it's insane to me how close some of them look to actual phishing domains...

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#173
post #107

Earlier quoted context omitted.

> Seeing dell.computerdealshop.com will snap a lot of people out of it where seeing dell.shop would not have. Would love to see citations for that.

Here's one [0]! [0] : https://news.ycombinator.com/item?id=42307876

It's just a claim. There's no support for that actually happening. And no real source.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#174

Earlier quoted context omitted.

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

When a scam hits someone's inbox or text message, it finds them in a particular time in their life, in a particular state of mind, and in a particular context. It's not just about how gullible or uninformed or whatever they are. They may be tired, they may be drunk, they may be spending all their energy worrying about a sick relative, or trying not to. They may have just been shopping for a computer, maybe even a del…

> Seeing dell.computerdealshop.com will snap a lot of people out of it where seeing dell.shop would not have.

I see this and raise you HP using domains like h30434.www3.hp.com for decades now. They only started to disappear fairly recently. Many companies will do it and people don't really care.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#175
post #78

Earlier quoted context omitted.

> I rarely find a reputable business that is using anything but .com or .co.XX as the primary domain What about all the other ccTLDs? Okay, maybe not .ly, .by, .ru and friends, but what do you have against .it, .fr, .de, es?

.ly, .by and .ru are legitimate in their own context. https://www.mos.ru (Moscow's city site), https://www.belarus.by/ (Belarus' tourism site) and https://libyaobserver.ly (Libyan newspaper) are three examples. And I'd be almost as suspicious of buy-viagra-pills.de as I would be of buy-viagra-pills.ru.

.de domains require a German postal address, so I would actually trust them more than the .ru equivalent. Plenty of other ccTLDs have even stricter nationality requirements for registration.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#176

Honestly the only "legitimate" use for these TLDs seem to be fediverse/bsky vanity URLs. Everything outside that just looks like a scam, even if it isn't.

On the contrary, when I'm given a fediverse or bsky vanity URL I'm inherently suspicious of the domain; and when I go there and see that absolutely nothing of consequence renders without Javascript, I am very much disinclined to whitelist anything, even if the page claims that it's just running a Mastodon instance or whatever. ("A likely story", you know.)

if someone gives me a fedi url I'm almost certainly going to read it on my instance so it doesn't have any stupid CSS so imo you really don't need to be whitelisting anything

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#177
domain names are like real estate in a poorly-planned city.

the city centre is overcrowded and super-expensive, while the new neighbourhoods in the suburbs are a mixed bag.

while some become instant hits and sometimes cost more than inside the city (like .ai lately), while you got these tlds that only bring pain.

not to forget you are always leasing, and own nothing in the end.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#178
I remember once I saw a blog post how a companies internal emails were getting blocked because they were on .xyz and got fixed by moving to a .com.

After that I decided to only get .xyz domains for internal usage like infra domains or for internal self hosted apps.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#179
post #82

Earlier quoted context omitted.

> The powers that be could very well decide to just promote it to be a gTLD No, they can’t do that. Every two-letter TLD is defined to be a ccTLD, and nothing else.

Yes they can. They did it before after the Soviet Union broke up and they kept the .su TLD. It's still active. I'd argue that keeping around .io is more important than keeping .su around, seeing how many people and businesses use .io domains.

The Soviet Union ceased to exist. As long as the British Indian Ocean Territory is not breaking up or otherwise dissolving, it still is allocated a ccTLD.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#180

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

Answers like this, that basically call the users idiots and abdicate any responsibility on the part of tech, are a losing long-term business proposition. Figure it out and gain loyalty and market share.
Post reply on HN