Live data from Hacker News

A large collection of fraudulent web stores

chair6.net

31–40 of 75 posts

Re: A large collection of fraudulent web stores

#31
post #29
post #22

Earlier quoted context omitted.

In Germany we have an approach with a somewhat similar effect. For any site with an commercial intent (which is pretty loosely defined) it is mandatory to have an Imprint with the person representing the company, the address of the HQ as well as the companies registration number and court location. It makes it somewhat more transparent what company is behind the site and gives you information you can lookup in public…

My rude opinion: imprint is nonsense. It does not protect you from fake shops at all. It’s no brainer to copy one from another shop. As a legit seller you can be sued by shady layers for errors in imprint. Who is looking in public registers while shopping online…

I actually do know quite a few people who look up the imprint before shopping there, especially when they buy stuff as a business. You’re obviously right but it’s fairly easy to copy an imprint, and the whole shady lawyer thing for minor errors also is absolutely a pain.

I don’t think it’s completely useless, but it’s certainly not perfect either. As the parent comment suggested having a business register It’s legit domains would probably makes sense from a consumer protection point of view.

However, with the current state of the digital administration in Germany this change would introduce so much overhead that it would lead to a lot of justified opposition.

Re: A large collection of fraudulent web stores

#32
post #28

Earlier quoted context omitted.

Fraudulent websites could just add fake/copied information, no? A special domain doesn't have that issue.

Oh they do copy this information! I became victim of such a fraud because the whole website looked really legitimate to me, and I am the "tech guy" in our family. Thing is: fraudsters create good looking websites and just copy all the company information from other stores, put in a non-working telephone number and email and they are good to go. There are thousands of small businesses that sell stuff online. One would…

Yes copying that information is obviously fairly easy and allows the scammer to make at least short term legit looking websites.

Adding the legit domains to the Handelsregister doesn’t seem like the worst idea to me. However, as the digital access to government services is still basically non-existent this would lead to a whole lot of additional bureaucracy and slowed down processes.

Re: A large collection of fraudulent web stores

#33
post #28

Earlier quoted context omitted.

Fraudulent websites could just add fake/copied information, no? A special domain doesn't have that issue.

Oh they do copy this information! I became victim of such a fraud because the whole website looked really legitimate to me, and I am the "tech guy" in our family. Thing is: fraudsters create good looking websites and just copy all the company information from other stores, put in a non-working telephone number and email and they are good to go. There are thousands of small businesses that sell stuff online. One would…

some PKI would prevent copying, the same way that no one else can pretend to be https://Google.com

Re: A large collection of fraudulent web stores

#35

The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

To register a .com.au or .net.au domain, you have to provide your ABN (Australian Business Number). The problem with that, however, is you don't have to prove you have the authority to do so. You can enter any business's ABN.

Re: A large collection of fraudulent web stores

#37
post #31
post #29

Earlier quoted context omitted.

My rude opinion: imprint is nonsense. It does not protect you from fake shops at all. It’s no brainer to copy one from another shop. As a legit seller you can be sued by shady layers for errors in imprint. Who is looking in public registers while shopping online…

I actually do know quite a few people who look up the imprint before shopping there, especially when they buy stuff as a business. You’re obviously right but it’s fairly easy to copy an imprint, and the whole shady lawyer thing for minor errors also is absolutely a pain. I don’t think it’s completely useless, but it’s certainly not perfect either. As the parent comment suggested having a business register It’s legit…

Family members as commercial buyers not only read imprints, but also check the seller and his company in various scoring portals. In commercial domain nice consumer protection does not exist anymore.

Re: A large collection of fraudulent web stores

#38

The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

> To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain.

I think this can just add layers of bureaucracy that don't address the problem anyway.

In the early days of widespread internet use in Sweden it was quite difficult to register a .se web-address: not only were company documents needed, but the authority that granted use of the address also split your right to it geographically within Sweden, so that if you wanted the address to stretch across the whole country you needed to make multiple applications (using a subdomain system).

This process just made it almost impossible for a small personal startup to own a Swedish domain, and it was completely impossible to register a domain on a 'try-it' basis, to see if a nascent business idea would take-off.

In other words it just entrenched the dominant position of incumbents.

What happened instead, was that Swedes registered .com addresses, or .nu ('now' in Swedish), or other variations. And the same sort of thing would happen now: the international fraudulent sites would still be possible - just legitimate registrations would become much harder.

A little like what happens with pirating, where people using pirated software often have to jump through fewer hoops than legitimate users, who've paid for their installs, but need to constantly dial-up to be allowed to keep using the tools they've bought.

tldr; more bureaucracy for legitimate businesses, but doesn't address the core problem for end-users.

Re: A large collection of fraudulent web stores

#39

Earlier quoted context omitted.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

> To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. I think this can just add layers of bureaucracy that don't address the problem anyway. In the early days of widespread internet use in Sweden it was quite difficult to register a .se web-address: not only were company documents needed, but the authority that granted use of the address…

I'm not saying that you need to be a company to have your own domain. I'm saying that if your domain represents a company there should be some way to automatically check that against a database of registered businesses

Re: A large collection of fraudulent web stores

#40
post #29
post #22

Earlier quoted context omitted.

In Germany we have an approach with a somewhat similar effect. For any site with an commercial intent (which is pretty loosely defined) it is mandatory to have an Imprint with the person representing the company, the address of the HQ as well as the companies registration number and court location. It makes it somewhat more transparent what company is behind the site and gives you information you can lookup in public…

My rude opinion: imprint is nonsense. It does not protect you from fake shops at all. It’s no brainer to copy one from another shop. As a legit seller you can be sued by shady layers for errors in imprint. Who is looking in public registers while shopping online…

For well known shops: Probably nobody. But if I find a good price on an unknown (to me) shop I'll check the tax ID from the imprint on Google.

CRT.sh is also nice to figure out how long an operation has been using SSL (e.g. mtz-elektronik[dot]de is used by scammers on hacked Amazon shops since a few days).

Post reply on HN