Live data from Hacker News

A large collection of fraudulent web stores

chair6.net

11–20 of 75 posts

Re: A large collection of fraudulent web stores

#11

A phish

If homophones are the pattern to follow, then (since a large collection of legitimate stores can be thought of as a "mall") perhaps the new word should be "a maul" or "a mawl" (suggestive of being something that swallows your money, and doesn't give you anything of value in return).

Re: A large collection of fraudulent web stores

#14
The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe.

In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

Re: A large collection of fraudulent web stores

#15

The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

That’s kind of what antivirus web plugins do

Re: A large collection of fraudulent web stores

#16

The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

In practice consumers just go straight to Amazon because they're afraid of the wider internet and depend on the return policy to save them when they get scammed. Doubt any "opt-in validation, ring of trust, p2p feedback and rating" will change that in the next decade.

Re: A large collection of fraudulent web stores

#17

The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

As weird as it sounds, it is still the best.

If we have centralised "licensing" solution it is abused by large capital to wash off smaller - there is plenty of examples.

If we have decentralised solution (which is basically what review is) - it is immediately abused by "marketers".

There is no simple and easy solution to the problem.

Re: A large collection of fraudulent web stores

#18

Off-topic, but something seems dangerously off with urlscan.io (a service I had never heard of before). If I go to urlscan.io and look at the recently scanned sites (which are live-updated), every now and then I can find links with potentially sensitive information. I found OneDrive and SharePoint links. I was unable to actually access the documents in them (it asked me to login), but I could see their content (or me…

Makes me question if URL-as-all-factors is a secure way to authenticate someone/thing. Even with SSL encrypting the path , there is the risk of someone sharing that URL since it is a familiar thing to do to share links.

With third party cookies going away, URL parameters are the only way to do SSO across domains. Not much you can do about it.

Re: A large collection of fraudulent web stores

#19

The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain.

When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

Re: A large collection of fraudulent web stores

#20

The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

That would be a great idea.
Post reply on HN