Live data from Hacker News

The Perils of an .xyz Domain

spotvirtual.com

161–170 of 282 posts

Re: The Perils of an .xyz Domain

#161

Earlier quoted context omitted.

You'd be getting an unbelievable amount of SMS spam if carriers weren't allowed to block messages. There's a lot of bad actors out there.

Seconded, having worked in this space I can assure everyone that there are multiple orders of magnitude more (attempted) spam SMS than legitimate SMS.

Very interesting. I definitely get phishing SMS messages from time to time, but I didn't realize these were some of the very few which actually made it through. Any idea how these bad actors are able to send out these massive batches of spam SMS? My naiive guess would be bulk purchasing disposable SIMs but I imagine it's more sophisticated?

Re: The Perils of an .xyz Domain

#163

Earlier quoted context omitted.

You'd be getting an unbelievable amount of SMS spam if carriers weren't allowed to block messages. There's a lot of bad actors out there.

Seconded, having worked in this space I can assure everyone that there are multiple orders of magnitude more (attempted) spam SMS than legitimate SMS.

I believe that, completely. But keyword silently blocking is an objectively bad approach. Tell the sender it failed if you're so keen to do so. Or tag it with a big POTENTIAL SPAM at the beginning of the message and send it. Or literally any of the dozens of smarter ways of content filtering than (if .xyz in y).

Re: The Perils of an .xyz Domain

#164
post #26

> One surprising side effect of having a .xyz domain is that the mere inclusion of .xyz inside of a text message will result in a silent delivery failure for many providers. This is wild to me. Tested it out myself and I couldn't send an SMS with a spot.xyz link to/from Google Voice T-Mobile. And no "failed delivery" notice either, just a silent failure. And yet I still get so many texts that are obviously spam or ph…

Blocking of messages/emails and blanket email server/domain/extension blacklisting is the same as a postal service not delivering mail to or from a particular entity/street/town. Doing so silently and without a valid and case-specific reason should not be legally allowed. Edit: Added "street/town" to analogy, and "case-specific" before reason

It's actually worse than that. It isn't blocked because of the sender or recipient, but because of the content. That would be like the postal service reading your mail and deciding that because of an address in the text of a letter, it shouldn't be delivered.

Re: The Perils of an .xyz Domain

#165
post #26

Earlier quoted context omitted.

Blocking of messages/emails and blanket email server/domain/extension blacklisting is the same as a postal service not delivering mail to or from a particular entity/street/town. Doing so silently and without a valid and case-specific reason should not be legally allowed. Edit: Added "street/town" to analogy, and "case-specific" before reason

You'd be getting an unbelievable amount of SMS spam if carriers weren't allowed to block messages. There's a lot of bad actors out there.

I just saw this in another thread but: "label, not remove" is a better philosophy. I want to receive every message addressed to me.

Enable me to be the judge and get out of the way.

Re: The Perils of an .xyz Domain

#166
post #26

Earlier quoted context omitted.

Blocking of messages/emails and blanket email server/domain/extension blacklisting is the same as a postal service not delivering mail to or from a particular entity/street/town. Doing so silently and without a valid and case-specific reason should not be legally allowed. Edit: Added "street/town" to analogy, and "case-specific" before reason

You'd be getting an unbelievable amount of SMS spam if carriers weren't allowed to block messages. There's a lot of bad actors out there.

No, I'd just be filtering it client-side -- which is the only way it should work in the first place.

Providers should be legally prohibited from intercepting and dropping messages.

Re: The Perils of an .xyz Domain

#167
post #26

> One surprising side effect of having a .xyz domain is that the mere inclusion of .xyz inside of a text message will result in a silent delivery failure for many providers. This is wild to me. Tested it out myself and I couldn't send an SMS with a spot.xyz link to/from Google Voice T-Mobile. And no "failed delivery" notice either, just a silent failure. And yet I still get so many texts that are obviously spam or ph…

Blocking of messages/emails and blanket email server/domain/extension blacklisting is the same as a postal service not delivering mail to or from a particular entity/street/town. Doing so silently and without a valid and case-specific reason should not be legally allowed. Edit: Added "street/town" to analogy, and "case-specific" before reason

In effect, sure, but in implementation these aren’t comparable. Postal services usually come with monopolies and mandates that ISPs, telecoms and email servers usually don’t.

USPS has a monopoly on first-class mail in the US and a Congressional mandate to deliver to every address.

Re: The Perils of an .xyz Domain

#168
post #26

> One surprising side effect of having a .xyz domain is that the mere inclusion of .xyz inside of a text message will result in a silent delivery failure for many providers. This is wild to me. Tested it out myself and I couldn't send an SMS with a spot.xyz link to/from Google Voice T-Mobile. And no "failed delivery" notice either, just a silent failure. And yet I still get so many texts that are obviously spam or ph…

Blocking of messages/emails and blanket email server/domain/extension blacklisting is the same as a postal service not delivering mail to or from a particular entity/street/town. Doing so silently and without a valid and case-specific reason should not be legally allowed. Edit: Added "street/town" to analogy, and "case-specific" before reason

What about MetaMask, popular crypto wallet with a Chrome extension. The extension blocks viewing of "blacklisted" websites IN YOUR BROWSER... and the blacklist is entirely community-led. So a competitor can just easily add your website to the list. Example: metalmark.xyz

Try to visit it with the MetaMask browser extension added to your browser. They won't let you. Someone decided to block a small business, and for what? There's no evidence involved. Incredibly short-sighted of MetaMask to add this & randomly accept edits to the blacklist from the community without peer review.

https://github.com/MetaMask/eth-phishing-detect

Re: The Perils of an .xyz Domain

#169
post #26

> One surprising side effect of having a .xyz domain is that the mere inclusion of .xyz inside of a text message will result in a silent delivery failure for many providers. This is wild to me. Tested it out myself and I couldn't send an SMS with a spot.xyz link to/from Google Voice T-Mobile. And no "failed delivery" notice either, just a silent failure. And yet I still get so many texts that are obviously spam or ph…

Blocking of messages/emails and blanket email server/domain/extension blacklisting is the same as a postal service not delivering mail to or from a particular entity/street/town. Doing so silently and without a valid and case-specific reason should not be legally allowed. Edit: Added "street/town" to analogy, and "case-specific" before reason

As a consumer, I can see both sides of this. On the one hand, I like energetic spam blocking without fear of legal liability, even if there are occasionally a few false positives. On the other, I do not want ISPs/telecoms to be the arbiters of traffic (net neutrality).

The net-neutral solution is for ISPs/telecoms to not spam-block, but rather have spam-blocking be an optional, additional, layer that the consumer can choose at will, or not have at all. But the problem with that solution is that it requires the consumer to do extra work to obtain spam protection, and the consumer would not be protected by default. It also means extra work by all parties delivering spam messages. Unless spam ceases or things otherwise change, I think the clunky solution we currently have is fine for the most part.

Re: The Perils of an .xyz Domain

#170

Earlier quoted context omitted.

So put it in a spam folder. If I had a spam texts folder that showed me everything I was being blocked from, I'd both appreciate it and not feel this massive breach of trust that things being sent to me are being completely ignored by a third party system. The system that does this is absolutely primed for censorship, and we have no way to know it's not being used.

> So put it in a spam folder. 1) Neither the SMS protocol nor any phone I've ever seen has any mechanism to file messages in "folders". 2) Processing SMS messages and delivering them to subscribers has a cost. Doing so for high-volume junk messages would place a significant burden on carriers. 3) Most carriers used to charge subscribers for receiving SMS messages. Some still do! Charging subscribers to receive spam S…

1 and 2: true (to a degree, phones sort messages by sender which is a folder), but if a SMS already reached the provider they have the data. No need to send spam to the client. Instead display the SMS on some webinterface the customer can access. Or email it.
Post reply on HN