Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

141–150 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#141

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

[deleted]

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#142
post #24

Earlier quoted context omitted.

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

They're different. Companies register all kinds of crazy domains and redirect you through them all the time. Why is it crazy that some marketing person at Dell thought it would be cool to link people to 'dell dot shop'? I would check the certificates, but honestly only as a precaution. If the website looks correct that isn't such an insane thing. That is exactly why it's so dangerous and effective versus your example…

> I would check the certificates

What good does that do? It is pretty rare for companies to get an EV or OV certificate, since it is more expensive and more hassle than a DV cert, and even when they do, the name on the cert isn't always what you expect since it might be the name of the owning company, not the brand you are familiar with.

Whois on DNS isn't always reliable either, since it often just points to another company that provides a dns service (such as AWS).

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#143

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

I wonder if we could add some type of verification registry. It would be nice if browser's could have a big indicator saying that this website is verified to associated with Dell inc.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#144
post #2

> new gTLDs introduced in the last few years command just 11 percent of the market for new domains, but accounted for roughly 37 percent of cybercrime domains reported between September 2023 and August 2024. > .com and .net domains made up approximately half of all domains registered...they accounted for just over 40 percent of all cybercrime domains. Hardly earth shattering. .net and .com are still pulling 80% of th…

> Maybe the real story here is that the ccTLD registrars, who weren't mentioned, are disproportionately good at deterring cybercrime. I think that some ccTLDs requiring positive identification, usually as a side effect of residency or nationality requirements, immensely help here (versus most gTLDs requiring f***-all identification).

I definitely don't want to move to a system where making a website needs both a government and a private corporation vouching for you. That's the worst case scenario.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#145

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

What looks like squatters might also be people who just want their own domain only for email, not hosting.

Email is one of the easier services to detect; not only does SMTP specify that the server sends a greeting before authentication occurs, but there's also a bunch of DNS records just sitting there in full view. I'd say it's easier to detect real usage with email than with HTTP, because, to my knowledge, nobody runs an MTA just to say 'this domain is for sale' like they do on the Web!

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#146
post #84

Earlier quoted context omitted.

If I got an 'urgent email' I wouldn't go to any domain, I would contact my employer directly and confirm with them before doing anything. The people who would fall for this phishing scam would fall for almost any domain, because it's not about the domain.

Millions of people don't have an employer with an HR department they can call on the phone to confirm that an email is legitimate. What if your primary source of income is Uber or Doordash or Etsy or Youtube?

All of these have support contacts for drivers/dashers/etc. Eg https://help.doordash.com/dashers/s/dasher-support?language=...

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#147

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

There aren't "people who fall for phishing" and "people who don't", generally speaking. I know highly intelligent and talented people, well educated in general online security, who have fallen for phishing links and scams.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#148
post #80

Earlier quoted context omitted.

Whether people are more easily fooled by dell.shop dell.computershop.com is a non sequitur from the rather wordy disquisition about why people fall for the scams in general. The eye sees dell first in clear letters for both urls. Their sick relative doesn’t change much here. I would honestly not be sure if either is a scam for the url alone. The improbable deal at the other end is the only meaningful signal.

> Whether people are more easily fooled by dell.shop dell.computershop.com is a non sequitur from the rather wordy disquisition about why people fall for the scams in general. It isn't. People fall because probabilities align. Something can catch their eye to knock them out of it. A bad URL is a bad probability (for the scammer) in the chain, a really good URL is another good probability. If your assessment is that b…

Just the fact that you had your credit report pulled for a loan qualification is immediately sold to ad brokers by the credit bureaus, who will sell it on down the line to less and less scrupulous buyers. It's not surprising to me at all that you got a scam call about a loan while you were in the process of legitmately applying for a loan.

I now ask businesses like these "what number will you call me from" and I put that in my phone as a contact, so that my phone will ring. If they call me from any other number I won't see the call.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#149
post #33

Earlier quoted context omitted.

>The lions share of issues with domains would go away if we made squatting illegal, or at the least, extremely expensive. How do you define squatting? Is the owner of nissan.com "squatting" on it because he wouldn't sell to the japanese car company? How much interest do you need in a given domain before it's not squatting?

I would argue if you aren't doing some combination of: - Hosting a website - Operating email accounts - Infrastructure (mail, DNS, etc.) - Misc. Services (Minecraft server, TeamSpeak server, something) Then you're squatting. Like if you own turkeyonapig.com and it's literally just a web page with a picture of a turkey sitting on a pig? Not squatting. It's odd but it's clearly doing exactly what it's meant to be doing…

Nissan is the guy's name. Come on.

It doesn't matter if you're just a dude or a corporation, you play by the same rules. There isn't anything to solve here. These problems are solved between those those 2 parties and no one else.

Good Lord. It's in the public's interest it remains this way.

Another person here had it right, companies have been playing with fire with their URL shenanigans. From one time TLDs to abusing tracking parameters. Not to mention browsers in their insane quest to strip useful information out off their UIs, making you CLICK to see who owns the place. Clown world really.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#150
post #80

Earlier quoted context omitted.

When a scam hits someone's inbox or text message, it finds them in a particular time in their life, in a particular state of mind, and in a particular context. It's not just about how gullible or uninformed or whatever they are. They may be tired, they may be drunk, they may be spending all their energy worrying about a sick relative, or trying not to. They may have just been shopping for a computer, maybe even a del…

Whether people are more easily fooled by dell.shop dell.computershop.com is a non sequitur from the rather wordy disquisition about why people fall for the scams in general. The eye sees dell first in clear letters for both urls. Their sick relative doesn’t change much here. I would honestly not be sure if either is a scam for the url alone. The improbable deal at the other end is the only meaningful signal.

dell.shop is more believable than dell.computershop.com because shorter urls seem more believable and valuable.

If you don't agree I have a computershopthatisreallycoolandcheap.com to sell you.

Post reply on HN