Live data from Hacker News

A large collection of fraudulent web stores

chair6.net

21–30 of 75 posts

Re: A large collection of fraudulent web stores

#21

The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

The path to an China-esque ICP recordal system.

Re: A large collection of fraudulent web stores

#22

The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

In Germany we have an approach with a somewhat similar effect.

For any site with an commercial intent (which is pretty loosely defined) it is mandatory to have an Imprint with the person representing the company, the address of the HQ as well as the companies registration number and court location. It makes it somewhat more transparent what company is behind the site and gives you information you can lookup in public registries.

I hate it from a privacy perspective but it’s okay for for consumer protection.

Re: A large collection of fraudulent web stores

#23

The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

Some countries do _kinda_ have this, for registering `.no` domains you need to be a Norwegian citizen or do it through a Norwegian company. Not sure how much that actually helps tho?

Re: A large collection of fraudulent web stores

#24
post #22

Earlier quoted context omitted.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

In Germany we have an approach with a somewhat similar effect. For any site with an commercial intent (which is pretty loosely defined) it is mandatory to have an Imprint with the person representing the company, the address of the HQ as well as the companies registration number and court location. It makes it somewhat more transparent what company is behind the site and gives you information you can lookup in public…

Fraudulent websites could just add fake/copied information, no? A special domain doesn't have that issue.

Re: A large collection of fraudulent web stores

#25
post #18

Earlier quoted context omitted.

Makes me question if URL-as-all-factors is a secure way to authenticate someone/thing. Even with SSL encrypting the path , there is the risk of someone sharing that URL since it is a familiar thing to do to share links.

With third party cookies going away, URL parameters are the only way to do SSO across domains. Not much you can do about it.

With SAML IIRC the IdP request is GET (but hey that one is fairly public - no credentials have been supplied yet) and the response is POST back to the origin site.

Re: A large collection of fraudulent web stores

#26

A phish

If homophones are the pattern to follow, then (since a large collection of legitimate stores can be thought of as a "mall") perhaps the new word should be "a maul" or "a mawl" (suggestive of being something that swallows your money, and doesn't give you anything of value in return).

Maybe I should have said a phishbowl then!

Re: A large collection of fraudulent web stores

#27
post #22

Earlier quoted context omitted.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

In Germany we have an approach with a somewhat similar effect. For any site with an commercial intent (which is pretty loosely defined) it is mandatory to have an Imprint with the person representing the company, the address of the HQ as well as the companies registration number and court location. It makes it somewhat more transparent what company is behind the site and gives you information you can lookup in public…

I mean, if you sell stuff on the internet I should be able to make sure you're an actual reachable entity with legal responsibility.

Now, it they made it into a standard that could be included into the browser's UI...

Re: A large collection of fraudulent web stores

#28
post #22

Earlier quoted context omitted.

In Germany we have an approach with a somewhat similar effect. For any site with an commercial intent (which is pretty loosely defined) it is mandatory to have an Imprint with the person representing the company, the address of the HQ as well as the companies registration number and court location. It makes it somewhat more transparent what company is behind the site and gives you information you can lookup in public…

Fraudulent websites could just add fake/copied information, no? A special domain doesn't have that issue.

Oh they do copy this information! I became victim of such a fraud because the whole website looked really legitimate to me, and I am the "tech guy" in our family. Thing is: fraudsters create good looking websites and just copy all the company information from other stores, put in a non-working telephone number and email and they are good to go. There are thousands of small businesses that sell stuff online.

One would argue that there is a Handesregistereintrag (record of commerce at the officials) that might help, but it only contain information about the seller including contact details and what the does, and not domains. And the record is not needed for small businesses.

TLDR: Germany seems to have hurdles for fraudsters, but they are easily taken by simply copying information from legit stores.

Re: A large collection of fraudulent web stores

#29
post #22

Earlier quoted context omitted.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

In Germany we have an approach with a somewhat similar effect. For any site with an commercial intent (which is pretty loosely defined) it is mandatory to have an Imprint with the person representing the company, the address of the HQ as well as the companies registration number and court location. It makes it somewhat more transparent what company is behind the site and gives you information you can lookup in public…

My rude opinion: imprint is nonsense. It does not protect you from fake shops at all. It’s no brainer to copy one from another shop. As a legit seller you can be sued by shady layers for errors in imprint. Who is looking in public registers while shopping online…

Re: A large collection of fraudulent web stores

#30
post #22

Earlier quoted context omitted.

In Germany we have an approach with a somewhat similar effect. For any site with an commercial intent (which is pretty loosely defined) it is mandatory to have an Imprint with the person representing the company, the address of the HQ as well as the companies registration number and court location. It makes it somewhat more transparent what company is behind the site and gives you information you can lookup in public…

I mean, if you sell stuff on the internet I should be able to make sure you're an actual reachable entity with legal responsibility. Now, it they made it into a standard that could be included into the browser's UI...

Yes, I do think it’s absolutely sensible to make something like this mandatory for people who sell stuff or have some kind of commercial interest.

However, the law is pretty unclear about what is considered commercial interest. This effectively leads to the situation where basically any site of any kind is expected to have an imprint or otherwise, you can expect to get a nice and expensive writing from a lawyer.

Post reply on HN