Earlier quoted context omitted.
I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?
The people who would fall for that would probably also fall for `dell.computerdealshop.com` though
Phishers Love New TLDs Like .shop, .top and .xyz
141–150 of 220 posts
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#142Earlier quoted context omitted.
The people who would fall for that would probably also fall for `dell.computerdealshop.com` though
They're different. Companies register all kinds of crazy domains and redirect you through them all the time. Why is it crazy that some marketing person at Dell thought it would be cool to link people to 'dell dot shop'? I would check the certificates, but honestly only as a precaution. If the website looks correct that isn't such an insane thing. That is exactly why it's so dangerous and effective versus your example…
What good does that do? It is pretty rare for companies to get an EV or OV certificate, since it is more expensive and more hassle than a DV cert, and even when they do, the name on the cert isn't always what you expect since it might be the name of the owning company, not the brand you are familiar with.
Whois on DNS isn't always reliable either, since it often just points to another company that provides a dns service (such as AWS).
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#143The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…
I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#144> new gTLDs introduced in the last few years command just 11 percent of the market for new domains, but accounted for roughly 37 percent of cybercrime domains reported between September 2023 and August 2024. > .com and .net domains made up approximately half of all domains registered...they accounted for just over 40 percent of all cybercrime domains. Hardly earth shattering. .net and .com are still pulling 80% of th…
> Maybe the real story here is that the ccTLD registrars, who weren't mentioned, are disproportionately good at deterring cybercrime. I think that some ccTLDs requiring positive identification, usually as a side effect of residency or nationality requirements, immensely help here (versus most gTLDs requiring f***-all identification).
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#145The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…
What looks like squatters might also be people who just want their own domain only for email, not hosting.
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#146Earlier quoted context omitted.
If I got an 'urgent email' I wouldn't go to any domain, I would contact my employer directly and confirm with them before doing anything. The people who would fall for this phishing scam would fall for almost any domain, because it's not about the domain.
Millions of people don't have an employer with an HR department they can call on the phone to confirm that an email is legitimate. What if your primary source of income is Uber or Doordash or Etsy or Youtube?
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#147Earlier quoted context omitted.
I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?
The people who would fall for that would probably also fall for `dell.computerdealshop.com` though
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#148Earlier quoted context omitted.
Whether people are more easily fooled by dell.shop dell.computershop.com is a non sequitur from the rather wordy disquisition about why people fall for the scams in general. The eye sees dell first in clear letters for both urls. Their sick relative doesn’t change much here. I would honestly not be sure if either is a scam for the url alone. The improbable deal at the other end is the only meaningful signal.
> Whether people are more easily fooled by dell.shop dell.computershop.com is a non sequitur from the rather wordy disquisition about why people fall for the scams in general. It isn't. People fall because probabilities align. Something can catch their eye to knock them out of it. A bad URL is a bad probability (for the scammer) in the chain, a really good URL is another good probability. If your assessment is that b…
I now ask businesses like these "what number will you call me from" and I put that in my phone as a contact, so that my phone will ring. If they call me from any other number I won't see the call.
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#149Earlier quoted context omitted.
>The lions share of issues with domains would go away if we made squatting illegal, or at the least, extremely expensive. How do you define squatting? Is the owner of nissan.com "squatting" on it because he wouldn't sell to the japanese car company? How much interest do you need in a given domain before it's not squatting?
I would argue if you aren't doing some combination of: - Hosting a website - Operating email accounts - Infrastructure (mail, DNS, etc.) - Misc. Services (Minecraft server, TeamSpeak server, something) Then you're squatting. Like if you own turkeyonapig.com and it's literally just a web page with a picture of a turkey sitting on a pig? Not squatting. It's odd but it's clearly doing exactly what it's meant to be doing…
It doesn't matter if you're just a dude or a corporation, you play by the same rules. There isn't anything to solve here. These problems are solved between those those 2 parties and no one else.
Good Lord. It's in the public's interest it remains this way.
Another person here had it right, companies have been playing with fire with their URL shenanigans. From one time TLDs to abusing tracking parameters. Not to mention browsers in their insane quest to strip useful information out off their UIs, making you CLICK to see who owns the place. Clown world really.
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#150Earlier quoted context omitted.
When a scam hits someone's inbox or text message, it finds them in a particular time in their life, in a particular state of mind, and in a particular context. It's not just about how gullible or uninformed or whatever they are. They may be tired, they may be drunk, they may be spending all their energy worrying about a sick relative, or trying not to. They may have just been shopping for a computer, maybe even a del…
Whether people are more easily fooled by dell.shop dell.computershop.com is a non sequitur from the rather wordy disquisition about why people fall for the scams in general. The eye sees dell first in clear letters for both urls. Their sick relative doesn’t change much here. I would honestly not be sure if either is a scam for the url alone. The improbable deal at the other end is the only meaningful signal.
If you don't agree I have a computershopthatisreallycoolandcheap.com to sell you.