Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

181–190 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#181

Earlier quoted context omitted.

It's great to be able to get silly domains for projects, back to the old days of IRC vanity hosts, but can you imagine seeing a link to something like jackets.luxury and going "yeah that seems legit, I'm definitely giving them my card details"

By that logic, would you pull out your credit card if you got linked jacketsluxury.com? .luxury is about twice as expensive as .com so I'm more suspicious of .com sites than of vanity TLDs. I think there's a generational divide here, the older people seem to distrust more recent TLDs for some reason while younger people don't really care about them.

jacketsluxury.com - probably not, luxuryjackets.com would definitely look a bit more trustworthy

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#183

I've been blocking .shop, .top, .xyz, and several other new TLDs but only specific TLDs where we see high (or all) spam. For our org, this means I also block .in and .jp in SMTP, as those are almost exclusively spam for us too.

Which makes them particularly useless for a legitimate business since it’s likely they’ll be blocked, and begs the question of if they really have any purpose at all.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#184

The correct way to identify the entity in the address bar is to display the O= (and country, if it differs from the requester) from the X.509 certificate. URLs following a pattern is not a good way to authenticate a site.

For millions of sites, including this one, that would just show "Let's Encrypt, US".

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#185

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

> Companies have to register on all these random domain to protect themselves.

"Nice business you got there. Shame if a scammer bought your name on my new TLD."

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#186

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

Is dell.com, dell.co.uk and dell.ee owned and backed by the same corporation?

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#188
post #127

Earlier quoted context omitted.

> Companies register all kinds of crazy domains and redirect you through them all the time That's the real problem with domain trust these days. Companies go out of their way to make sure you know to only visit official links, and then do stupid stuff like buying vanity domains for one-time deals, or make you click through mailchimp tracking URLs because marketing tracking is more important than your customers fallin…

There is no domain trust problem, because there is no trust to be had on domains.

do you trust that you are on Hacker News right now?

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#189
post #179

Earlier quoted context omitted.

Yes they can. They did it before after the Soviet Union broke up and they kept the .su TLD. It's still active. I'd argue that keeping around .io is more important than keeping .su around, seeing how many people and businesses use .io domains.

The Soviet Union ceased to exist . As long as the British Indian Ocean Territory is not breaking up or otherwise dissolving, it still is allocated a ccTLD.

But it is dissolving.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#190

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

What looks like squatters might also be people who just want their own domain only for email, not hosting.

That's certainly an issue. There have been a number of cases where companies have demanded that people hand over domain that they "where not using". Not using being defined as "does not have a website".

It feels like there should be some way of determining if a domain is actively being used, to combat squatters, but when ever someone tried to make a rule it ends up being something stupid, like not having a website.

Post reply on HN