Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

191–200 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#191
post #143

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

I wonder if we could add some type of verification registry. It would be nice if browser's could have a big indicator saying that this website is verified to associated with Dell inc.

Some HTTP certificates do exactly that, and web browsers used to show the company/identity the certificate was issued to in the URL bar. Now you have to go to the certificates detail, very clear on Firefox, behind a few clicks on Chrome. Here's an example from a bank in Spain: https://www.bbva.es

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#192
post #127

Earlier quoted context omitted.

There is no domain trust problem, because there is no trust to be had on domains.

do you trust that you are on Hacker News right now?

Maybe it would be better to say "there is no inherent trust on domains". I trust HN today because I was on HN yesterday, and the day before, and last year, and 10 years ago, etc., and it's always been trustworthy (so far as I know).

But if I saw a link tomorrow for hackernews.shop and I went there, I'd be very suspicious.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#193

Earlier quoted context omitted.

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

Also depends on how their browser shortens the display of the URL

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#194
post #104

When I used to run my own email, .top and .xyz received an automatic -10 on spam evaluation. I can't remember a single legitimate website that I actually used and would have had an account on from these TLDs; all I ever saw was spam.

Similar for my self hosted email, though I just reject in postfix for about 30 of the cheap/meme tld's.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#195

The whole environment of the newer gTLDs just feels… gross. I rarely find a reputable business that is using anything but .com or .co.XX as the primary domain. Putting on my regular-person hat: When I see a billboard or print ad with e.g. `example.travel`, I read that as a social media handle and not a website address like `example.com` would convey. In public perception, dot com means websites. Always has. (Tangenti…

>(Tangentially, the `.sucks` TLD in particular should never have been allowed. How many brands out there have to maintain a perfunctory registration there just to prevent somebody else from doing so?) The entire reason for allowing that TLD is a presumption that brands are not entitled to prevent the registration of domains which exists specifically to criticize them.

Ok, but now 1 company/squatter can buy all the top .sucks sites... is that much better?

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#196

Earlier quoted context omitted.

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

Have you seen the domains Microsoft uses? Half the time I am not sure if they are genuine or not, it's actually crazy. Sometimes they use .com, other times .ms. Sometimes Microsoft is in the top-level other times it's in the second-level. Sometimes they have no subdomain, sometimes they have two. It's utterly inconsistent and it's insane to me how close some of them look to actual phishing domains...

It is not actually important as you know you cannot trust microsoft more than the usual scammer anyway.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#197

The correct way to identify the entity in the address bar is to display the O= (and country, if it differs from the requester) from the X.509 certificate. URLs following a pattern is not a good way to authenticate a site.

For millions of sites, including this one, that would just show "Let's Encrypt, US".

And that’s the problem. I know I’m talking to “someone who has convinced Let’s Encrypt, US that they are foobar.com”. I have no idea if I’m actually talking to Foobar, Inc. (incorporated in Delaware, US).

There is a standard, reliable register of business entities (typically called “Secretary of State”) and it should be trivial to know if the domain I’m talking to is owned by/part of that entity, that the X.509 matches, and so forth.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#198
post #29

Earlier quoted context omitted.

The people who would fall for that would probably also fall for `dell.computerdealshop.com` though

I do not think so. I think if someone would have made an effort to rip off the real Dell site I would fall for it. I am just so lucky that scammer mostly prefer to go after the easier marks. I am not sure what a better solution could be. The idea of EV certificates was good but executed poorly. Maybe a way to link certificated to business IDs. I do however still prefer more gTLDs to minimize domain squatting.

> The idea of EV certificates was good but executed poorly. Maybe a way to link certificated to business IDs.

The idea was bad.

Anybody can open the Dell Flower Shop. They can call their company Dell Inc. and register the domain dell.shop and they're not doing anything wrong, because they're in a different industry and nobody is going to confuse a tulip with a laptop. And then they could get an EV cert that says Dell Inc. -- because that's who they are.

Which is why EV certs are worthless. Just because it says Dell doesn't mean it's that Dell. There can be arbitrarily many companies with the same name in different industries or locations. But then what is the certificate supposed to tell you that gives you more information than the domain name? The average person is not going to know a company's registration ID with the relevant secretary of state, or generally even what state they're incorporated in.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#199

Earlier quoted context omitted.

> Companies register all kinds of crazy domains and redirect you through them all the time That's the real problem with domain trust these days. Companies go out of their way to make sure you know to only visit official links, and then do stupid stuff like buying vanity domains for one-time deals, or make you click through mailchimp tracking URLs because marketing tracking is more important than your customers fallin…

I wholeheartedly agree. Subdomains exist for a reason. Vanity domains are so incredibly sloppy and unserious. Another issue is that they can make password management more of a chore. Every time I need to look up my Microsoft login, I have to remember to actually look up “live.com”. Except sometimes the login page is served from “microsoft.com”. Oops, you forgot your password and reset it; now your password for the ot…

This made me think I'd somehow not saved my MS password because it wouldn't show up if you searched "microsoft". I know you can combine them like the other comment mentioned but what an awful default experience.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#200
post #76

Earlier quoted context omitted.

.net and .com are still pulling 80% of their weight when it comes to cybercrime. The article states it's half that. "while .com and .net domains made up approximately half of all domains registered in the past year… they accounted for just over 40 percent of all cybercrime domains. Interisle says an almost equal share — 37 percent — of cybercrime domains were registered through new gTLDs."

> The article states it's half that. No, the article agrees with dmurray. Read again: 80% of 50% is 40%.

You seem to be implying that 80% of com/net domains are used for cybercrime, which is not a sound conclusion from those numbers. You're confusing "percent of all domains" with "percent of crime domains". You can't just divide them to get something meaningful.
Post reply on HN