Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

201–210 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#201
post #127

Earlier quoted context omitted.

There is no domain trust problem, because there is no trust to be had on domains.

do you trust that you are on Hacker News right now?

What I meant was that you can not put any trust in the contents of DNS labels, they should be handled as opaque blob-like identifiers. The only meaningful thing you can do with domain name is to compare it's labels to some reference.

So no, I don't trust that I'm on HN because of I put any trust in the domain "news.ycombinator.com" signifying anything. I only trust that I'm on same HN that I was on yesterday because the domain matches exactly the reference value. But the domain name could be anything, as long as it is stable.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#202
post #200
post #76

Earlier quoted context omitted.

> The article states it's half that. No, the article agrees with dmurray. Read again: 80% of 50% is 40%.

You seem to be implying that 80% of com/net domains are used for cybercrime, which is not a sound conclusion from those numbers. You're confusing "percent of all domains" with "percent of crime domains". You can't just divide them to get something meaningful.

No, the statement was that ".net and .com are still pulling 80% of their weight when it comes to cybercrime." I read that as saying that .net and .com domains show up in cybercrime 80% as often as would be expected if all TLDs were equally likely to be used for cybercrime.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#203
post #64

Earlier quoted context omitted.

> It's a tricky thing but not impossible to figure out. Good to hear. So after that you'll be sorting out world peace - right?

I really don't think eliminating domain squatters is some impossible task. you could probably just tax sales of domain names to death (90% sales tax on any resold domain names) to disincentivize it vs registration upkeep costs. Squatters are a massive blight on the internet.

The problem goes way beyond domain squatting. You have a limited resource, say nissan.com, and you have several valid claimants. Who gets to decide what's fair? First past the post? Heaviest pocket book? Biggest stick? Popular acclaim? ...

Is not unique to domains, this is why the world is uts.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#204
post #127

Earlier quoted context omitted.

There is no domain trust problem, because there is no trust to be had on domains.

do you trust that you are on Hacker News right now?

> do you trust that you are on Hacker News right now?

Is Hacker News asking for my credit card or impersonating any other site?

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#206

Earlier quoted context omitted.

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

Have you seen the domains Microsoft uses? Half the time I am not sure if they are genuine or not, it's actually crazy. Sometimes they use .com, other times .ms. Sometimes Microsoft is in the top-level other times it's in the second-level. Sometimes they have no subdomain, sometimes they have two. It's utterly inconsistent and it's insane to me how close some of them look to actual phishing domains...

If you get credits for Azure they're accessed through microsoftazuresponsorships.com. Why not sponsorships.azure.microsoft.com or something like that? I checked it three times when I got the link, because it's exactly the kind of domain someone would use if they were going to steal your Azure credits.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#207

Earlier quoted context omitted.

I wholeheartedly agree. Subdomains exist for a reason. Vanity domains are so incredibly sloppy and unserious. Another issue is that they can make password management more of a chore. Every time I need to look up my Microsoft login, I have to remember to actually look up “live.com”. Except sometimes the login page is served from “microsoft.com”. Oops, you forgot your password and reset it; now your password for the ot…

bitwarden can list multiple domains in one entry for a password - it might be good to find out if you're manager can do that and merge some?

That seems like the textbook definition of a bandaid solution. Does that even work for the new hotness, passkeys?

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#208

Earlier quoted context omitted.

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

There aren't "people who fall for phishing" and "people who don't", generally speaking. I know highly intelligent and talented people, well educated in general online security, who have fallen for phishing links and scams.

Very true. My dad (late 60s) has written a DNS server, but still nearly fell for an email scam when he was sleep deprived and at the airport believing his flight was overbooked and he was going to be kicked.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#209

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

[deleted]

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#210

Earlier quoted context omitted.

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

There aren't "people who fall for phishing" and "people who don't", generally speaking. I know highly intelligent and talented people, well educated in general online security, who have fallen for phishing links and scams.

It's certainly possible to strongly protect yourself though, vs casually relying on intuition which is hopeless. You just need to establish a process or set of rules to follow. Businesses do this all the time. A classic scam is sending an invoice asking for payment, and some disorganized businesses will just pay you! But those with a process won't because you won't be able to give them a matching purchase order number and other things their process needs.

A basic personal protection is to not trust anyone who initiates contact with you, no matter who they say they are or what they know about you. Verify by contacting them independently instead.

Post reply on HN