Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

131–140 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#131
post #13
post #5

I have always thought the infinite proliferation of TLDs was a stupid idea. I'd be enlightened if I could think of one scenario that benefits from it outside of the registrars.

There are lots of people called John Smith. They all want a domain name. There's only so many variations of jsmith, j-smith, etc you can squeeze into .com, .net, and a few others. Why shouldn't they be able to buy a domain name which contains their name? Is it useful to be able to differentiate between McDonald's the restaurant and McDonald's the legal firm and McDonald's garage? Why shouldn't each of those industrie…

[deleted]

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#132

The whole environment of the newer gTLDs just feels… gross. I rarely find a reputable business that is using anything but .com or .co.XX as the primary domain. Putting on my regular-person hat: When I see a billboard or print ad with e.g. `example.travel`, I read that as a social media handle and not a website address like `example.com` would convey. In public perception, dot com means websites. Always has. (Tangenti…

>(Tangentially, the `.sucks` TLD in particular should never have been allowed. How many brands out there have to maintain a perfunctory registration there just to prevent somebody else from doing so?)

The entire reason for allowing that TLD is a presumption that brands are not entitled to prevent the registration of domains which exists specifically to criticize them.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#133
post #97

Earlier quoted context omitted.

Most people don't understand URLs. Remember that Google was (is?) trying to remove the URL bar. Not just because it reinforces search as the main product and gateway to the web, but also because URLs are kind of hard for most people. Which brings us to the original argument: is this a reason to ban gTLDs? Surely the cost of banning gTLDs outweighs the enormous benefits of making it easy for society's productive users…

Many people do not understand URLs, many people do, and many people have an understanding in between. And they are all targets for scammers. And I don't think gTLDs should be banned! But I don't like bad arguments even when they support my preference.

And then there are plenty of companies who put some legitimate part of their business on a wonky gtld domain they only bought so that it's not bought by a scammer. Systems run by the investor relations department might run on examplecompany.biz, some hiring SAAS on examplecompany.work, the CRM on examplecompany.business and the tech support occasionally instructs someone to get a preview update from examplecompany.cc. Not because that's a smart thing to do, but because coordinating namespaces is not easy and dedicating an otherwise unused domain only bought to keep out the scammers is a tempting shortcut. And because training internet users that sometimes wonky TLD are ok is an externality.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#134

Earlier quoted context omitted.

I wholeheartedly agree. Subdomains exist for a reason. Vanity domains are so incredibly sloppy and unserious. Another issue is that they can make password management more of a chore. Every time I need to look up my Microsoft login, I have to remember to actually look up “live.com”. Except sometimes the login page is served from “microsoft.com”. Oops, you forgot your password and reset it; now your password for the ot…

bitwarden can list multiple domains in one entry for a password - it might be good to find out if you're manager can do that and merge some?

1Password too. This is a must-have feature for me.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#135

Honestly the only "legitimate" use for these TLDs seem to be fediverse/bsky vanity URLs. Everything outside that just looks like a scam, even if it isn't.

On the contrary, when I'm given a fediverse or bsky vanity URL I'm inherently suspicious of the domain; and when I go there and see that absolutely nothing of consequence renders without Javascript, I am very much disinclined to whitelist anything, even if the page claims that it's just running a Mastodon instance or whatever. ("A likely story", you know.)

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#136

Earlier quoted context omitted.

I wholeheartedly agree. Subdomains exist for a reason. Vanity domains are so incredibly sloppy and unserious. Another issue is that they can make password management more of a chore. Every time I need to look up my Microsoft login, I have to remember to actually look up “live.com”. Except sometimes the login page is served from “microsoft.com”. Oops, you forgot your password and reset it; now your password for the ot…

bitwarden can list multiple domains in one entry for a password - it might be good to find out if you're manager can do that and merge some?

iCloud Keychain can too, and I’ve already done that. It’s still an annoying and pointless extra step.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#137

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

I am unlikely to fall for either of them, but given compromising factors as mentioned by the other commenter, I am much less likely to fall for dell..com than dell.

Due to the widespread usage of 3+ common TLDs (com, org, net, etc.) and arbitrary third-level domains, people have been trained that the second-level domain is the one that matters. Now that gTLDs are more common I've needed to retrain my brain that the TLD is also a necessary heuristic for authenticating websites.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#138

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

What looks like squatters might also be people who just want their own domain only for email, not hosting.

Including me.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#139
post #115

Earlier quoted context omitted.

So, to be clear, the following tend to be seen as problems by their interested parties: * withholding tons of domains to watch them go up in value means people can't get those domains (scammers, regular people) * registries do not make a high price when they sell high-value domains (registries) * there's only so many words / groups of words that are easily typeable (everyone) * reducing scarcity reduces the value of…

I think first year premium pricing makes a lot of sense. I'm not sure what the average time to sell is for a domain investor, but say it's 10 years for an easy example. If you go from a standard registration price of $12 / year to a first year premium of $132, you double the 10 year carrying cost of a domain. That, naively, means domain investors can only speculate on half as many domains. By having a first year prem…

If memory serves me, first year premium pricing is definitely a thing for some domains on some tlds with some registrars.

Though I can also definitely understand why, for example, "lawyer.lawyer" would cost $$$$ every year, too, at least myself.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#140
post #118

Earlier quoted context omitted.

I see a lot of personal blogs that use .xyz here on HN.

I use .XYZ because it was pretty cheap when I bought it

I use .xyz because I have a very common first and last name, and nearly all of the permutations of them were taken on .net, .com, .org, and .us; .xyz seems to price based on how desirable they think the name is, so I still couldn't get $FIRST-$LAST.xyz for a reasonable price, but I got something close.
Post reply on HN