Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

151–160 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#151
post #33

Earlier quoted context omitted.

>The lions share of issues with domains would go away if we made squatting illegal, or at the least, extremely expensive. How do you define squatting? Is the owner of nissan.com "squatting" on it because he wouldn't sell to the japanese car company? How much interest do you need in a given domain before it's not squatting?

I would argue if you aren't doing some combination of: - Hosting a website - Operating email accounts - Infrastructure (mail, DNS, etc.) - Misc. Services (Minecraft server, TeamSpeak server, something) Then you're squatting. Like if you own turkeyonapig.com and it's literally just a web page with a picture of a turkey sitting on a pig? Not squatting. It's odd but it's clearly doing exactly what it's meant to be doing…

You can boil it down to: are you offering it for sale? If yes, squatting. If not, early bird gets the worm. You should be able to own a domain name and not be required to do anything with it beyond paying the registrar to legitimize your ownership.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#152
post #143

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

I wonder if we could add some type of verification registry. It would be nice if browser's could have a big indicator saying that this website is verified to associated with Dell inc.

HTTPS certificates should do exactly this.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#153

My primary catch-all email domain for accounts is at a silly TLD (.rodeo). My biggest complaint is that some large retailers/services completely refuse to believe it is a valid domain. (I'm looking at you, Walgreens. You blocked me during a pandemic from signing up for a vaccine with my actual email address, which is why fuckwalgreens@myother.domain is now my email in your system.)

I’d guess it was their first rodeo.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#154

Earlier quoted context omitted.

The problem is the new gTLDs don't increase the useful supply of domains. For casual usage like personal blogs and whatnot? Sure, use whatever. But if I was starting a web-based business and couldn't afford the .com? I'd rename the company before I'd use .xyz - if your business takes off the squatters will notice and raise their prices, so the .com will never be cheaper. If you got an "urgent e-mail" saying your empl…

What it you get an email from [yourbank].bank? Or if your mother got one? It's never a single signal, and the more legitimate a domain looks, the bigger a chance is that someone fells victim to a scam.

Bad example. The requirements to register in .bank are quite rigorous (see https://register.bank/eligibility/). Phishers typically go for TLDs that impose far fewer requirements on their registrars.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#155

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

What looks like squatters might also be people who just want their own domain only for email, not hosting.

Or are hosting non-public services and want TLS certs that all my devices trust automatically, like me.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#156

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

gTLDs don't really solve the problem of running out of domain names any more than doing it yourself like myname-shop.com There are too many gTLDs for anyone to remember so they're really just an arbitrary extension on the 2nd/3rd level name.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#157

A friend of our family almost got scammed from a .top domain. They convinced her she needed 'tech support' and transferred $30,000 from her savings to checking and tried to get her to go to the bank to get more money. She got suspicious and got new bank accounts and thankfully didn't get any actual money stolen. She's retired and it could have ruined her financially. I don't think she realizes how close she was to th…

Cyberfraud is infuriating when we know the victim, and depressing when you look how ripe the target space is, but the TLD is neither the most interesting thing about the crime nor what’s to blame, right?

There’s a lot of trust in a namespace system that doesn’t deserve it, although odds are you personally can use it to be immune to scams. What do we do for everyone else?

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#158

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

People would fall for `dell.scam` too, it's a number's game.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#159
post #152
post #143

Earlier quoted context omitted.

I wonder if we could add some type of verification registry. It would be nice if browser's could have a big indicator saying that this website is verified to associated with Dell inc.

HTTPS certificates should do exactly this.

They should. And sort of already do. Though, I wonder how difficult it is to register with some certificate issuers under a fraudulent name.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#160

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

The lions share of issues with domains would go away if we made squatting illegal, or at the least, extremely expensive. Tbh I'm increasingly thinking that just about any speculative instrument in the economy is just grift and drag. If you want to make money, make things. Stop trying to extract rent or exorbitant prices for land, for domains, for PS5s, etc. Feels like 9/10ths of the economy now is nothing but fucking…

If you're starting a new company, squatters are not a real problem. Just pick another name. If your favorite name is so valuable that it's squatted, then it's valuable! The squatter was reserving it for you, the only company that could really make good use of it, instead of some random personal blogger who happened to walk in first and would wasted its high value.

Also, what's the difference between a squatter and a personal blogger?

Post reply on HN