Live data from Hacker News

It's Way Too Easy to Get a .gov Domain Name

krebsonsecurity.com

111–120 of 184 posts

Re: It's Way Too Easy to Get a .gov Domain Name

#111
post #85

Earlier quoted context omitted.

The city of Lafayette's police department (in the SF East Bay) accepts crime tip emails using a Gmail address (94549TIP@gmail.com). It's plastered on all their police cars, even though the city and police department have an official domain. Though even that is a .org domain, lovelafayette.org.

Well presumably one would not be feeling much “Love Lafayette” when reporting crimes.

... but they would want to get the government, the "gman" involved - so "gmail" fits perfectly!

Re: It's Way Too Easy to Get a .gov Domain Name

#112

Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…

Large cities tend to be blue, and you want to pick a recognizable large city name to get the point across. Politics aside, the example would've had less impact for a republican stronghold just because it wouldn't be as recognizable a city name.

did he name any cities?

Re: It's Way Too Easy to Get a .gov Domain Name

#114
post #112

Earlier quoted context omitted.

Large cities tend to be blue, and you want to pick a recognizable large city name to get the point across. Politics aside, the example would've had less impact for a republican stronghold just because it wouldn't be as recognizable a city name.

did he name any cities?

Yes, Miami.

Re: It's Way Too Easy to Get a .gov Domain Name

#115

Earlier quoted context omitted.

So an email address that looks like a fraud (or just random) and a domain name that looks like a porn site.

94549 is their city zip code. And a palindrome.

> And a palindrome.

spilled my coffee

Re: It's Way Too Easy to Get a .gov Domain Name

#116

Good reporting, until this paragraph: Now consider what a well-funded adversary could do on Election Day armed with a handful of .gov domains for some major cities in Democrat strongholds within key swing states: The attackers register their domains a few days in advance of the election, and then on Election Day send out emails signed by .gov from, say, miami.gov (also still available) informing residents that bombs…

related: https://news.ycombinator.com/item?id=21110318

tldr; republicans tend to win by slimmer margins compared to democrats

Re: It's Way Too Easy to Get a .gov Domain Name

#117

Isn't the main issue that TLDs are a poor way of establishing trust? Otherwiae does every company and government need to get specialized TLDs to prevent impersonation? Even then it only works is users know and always notice the domain. EV certs are dead for good reason but nothing seems to have replaced them. I guess the only option is to verify each site once and then bookmark it and always make sure it's https. But…

EV certs, for the curious, extended validation certificates:

https://en.wikipedia.org/wiki/Extended_Validation_Certificat...

Re: It's Way Too Easy to Get a .gov Domain Name

#120

Earlier quoted context omitted.

That's not how .nyc is used or is expected to be used. It's a top-level domain, not a dotless host name. Here's an example of how it's used: https://thecity.nyc/

> That's not how .nyc is used or is expected to be used. It's a top-level domain, not a dotless host name. While it is prohibited by the ICANN policy [1], it is not strictly enforced so that there are multiple TLDs with A/AAAA records. They traditionally could be resolved with a trailing dot (thus it is not a dotless host name, that would have no dot), but nowadays many browsers refuse to resolve them without an expl…

This prohibition only applies to gTLDs. It does not apply to ccTLDs.
Post reply on HN