Earlier quoted context omitted.
I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?
I wonder if we could add some type of verification registry. It would be nice if browser's could have a big indicator saying that this website is verified to associated with Dell inc.
Phishers Love New TLDs Like .shop, .top and .xyz
191–200 of 220 posts
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#192Earlier quoted context omitted.
There is no domain trust problem, because there is no trust to be had on domains.
do you trust that you are on Hacker News right now?
But if I saw a link tomorrow for hackernews.shop and I went there, I'd be very suspicious.
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#193Earlier quoted context omitted.
I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?
The people who would fall for that would probably also fall for `dell.computerdealshop.com` though
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#194When I used to run my own email, .top and .xyz received an automatic -10 on spam evaluation. I can't remember a single legitimate website that I actually used and would have had an account on from these TLDs; all I ever saw was spam.
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#195The whole environment of the newer gTLDs just feels… gross. I rarely find a reputable business that is using anything but .com or .co.XX as the primary domain. Putting on my regular-person hat: When I see a billboard or print ad with e.g. `example.travel`, I read that as a social media handle and not a website address like `example.com` would convey. In public perception, dot com means websites. Always has. (Tangenti…
>(Tangentially, the `.sucks` TLD in particular should never have been allowed. How many brands out there have to maintain a perfunctory registration there just to prevent somebody else from doing so?) The entire reason for allowing that TLD is a presumption that brands are not entitled to prevent the registration of domains which exists specifically to criticize them.
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#196Earlier quoted context omitted.
The people who would fall for that would probably also fall for `dell.computerdealshop.com` though
Have you seen the domains Microsoft uses? Half the time I am not sure if they are genuine or not, it's actually crazy. Sometimes they use .com, other times .ms. Sometimes Microsoft is in the top-level other times it's in the second-level. Sometimes they have no subdomain, sometimes they have two. It's utterly inconsistent and it's insane to me how close some of them look to actual phishing domains...
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#197The correct way to identify the entity in the address bar is to display the O= (and country, if it differs from the requester) from the X.509 certificate. URLs following a pattern is not a good way to authenticate a site.
For millions of sites, including this one, that would just show "Let's Encrypt, US".
There is a standard, reliable register of business entities (typically called “Secretary of State”) and it should be trivial to know if the domain I’m talking to is owned by/part of that entity, that the X.509 matches, and so forth.
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#198Earlier quoted context omitted.
The people who would fall for that would probably also fall for `dell.computerdealshop.com` though
I do not think so. I think if someone would have made an effort to rip off the real Dell site I would fall for it. I am just so lucky that scammer mostly prefer to go after the easier marks. I am not sure what a better solution could be. The idea of EV certificates was good but executed poorly. Maybe a way to link certificated to business IDs. I do however still prefer more gTLDs to minimize domain squatting.
The idea was bad.
Anybody can open the Dell Flower Shop. They can call their company Dell Inc. and register the domain dell.shop and they're not doing anything wrong, because they're in a different industry and nobody is going to confuse a tulip with a laptop. And then they could get an EV cert that says Dell Inc. -- because that's who they are.
Which is why EV certs are worthless. Just because it says Dell doesn't mean it's that Dell. There can be arbitrarily many companies with the same name in different industries or locations. But then what is the certificate supposed to tell you that gives you more information than the domain name? The average person is not going to know a company's registration ID with the relevant secretary of state, or generally even what state they're incorporated in.
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#199Earlier quoted context omitted.
> Companies register all kinds of crazy domains and redirect you through them all the time That's the real problem with domain trust these days. Companies go out of their way to make sure you know to only visit official links, and then do stupid stuff like buying vanity domains for one-time deals, or make you click through mailchimp tracking URLs because marketing tracking is more important than your customers fallin…
I wholeheartedly agree. Subdomains exist for a reason. Vanity domains are so incredibly sloppy and unserious. Another issue is that they can make password management more of a chore. Every time I need to look up my Microsoft login, I have to remember to actually look up “live.com”. Except sometimes the login page is served from “microsoft.com”. Oops, you forgot your password and reset it; now your password for the ot…
Re: Phishers Love New TLDs Like .shop, .top and .xyz
#200Earlier quoted context omitted.
.net and .com are still pulling 80% of their weight when it comes to cybercrime. The article states it's half that. "while .com and .net domains made up approximately half of all domains registered in the past year… they accounted for just over 40 percent of all cybercrime domains. Interisle says an almost equal share — 37 percent — of cybercrime domains were registered through new gTLDs."
> The article states it's half that. No, the article agrees with dmurray. Read again: 80% of 50% is 40%.