Live data from Hacker News

Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

akamai.com

31–40 of 75 posts

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#31
post #5

I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about…

> banks and other institutions continue to send legitimate messages that look like phishing. The Canada Revenue Agency (tax collectors) once called me up about something. They literally said "To verify your identity, please give me your social insurance number". It's hard to blame people when actual government agencies are training people to be phished.

Just curious, how did you confirm it was The Canada Revenue Agency and not scammers?

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#32
post #24

USPS.gov redirecting to USPS.com certainly doesn't help matters. Things like this should use one of the few TLDs that actually has policies and procedures in place; then it's a simple "if it's not .gov, it's not real."

You're right that it doesn't help, but looking at regular non-technical people like my retired parents for example, I really wonder if it's a realistic expectation that people know what the important part of a URL are.

They need to parse slashes, dots, colons and ats (remember URLs can contain credentials, even though I believe browser issue warnings these days), identifiy the TLD and the domain and then know what is legit and what isn't. And know that things like onmicrosoft.com is legit while atmicrosoft.com is probably not. Or whatever link shortener some legit organizations are using.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#33
post #25

Earlier quoted context omitted.

I wonder if the .com TLD is part of the GOP campaign to kill the USPS

USPS purchased the usps.com domain a long time ago specifically so they could control it and prevent phishing. The decision to replace usps.gov with the .com domain came later, with the tenure of Trump appointee Louis DeJoy. Right wingers believe that USPS should operate as a business, not a public service, so "rebranding" their website to be .com is definitely a part of that narrative.

So the ask should be to have .gov be canonical, and usps.com directing to .gov it sounds like?

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#34
post #5

Earlier quoted context omitted.

> banks and other institutions continue to send legitimate messages that look like phishing. The Canada Revenue Agency (tax collectors) once called me up about something. They literally said "To verify your identity, please give me your social insurance number". It's hard to blame people when actual government agencies are training people to be phished.

Just curious, how did you confirm it was The Canada Revenue Agency and not scammers?

I logged into the CRA website and found something.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#35

Earlier quoted context omitted.

USPS purchased the usps.com domain a long time ago specifically so they could control it and prevent phishing. The decision to replace usps.gov with the .com domain came later, with the tenure of Trump appointee Louis DeJoy. Right wingers believe that USPS should operate as a business, not a public service, so "rebranding" their website to be .com is definitely a part of that narrative.

So the ask should be to have .gov be canonical, and usps.com directing to .gov it sounds like?

Yep, but for ideological reasons they reversed it.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#36
post #32
post #24

USPS.gov redirecting to USPS.com certainly doesn't help matters. Things like this should use one of the few TLDs that actually has policies and procedures in place; then it's a simple "if it's not .gov, it's not real."

You're right that it doesn't help, but looking at regular non-technical people like my retired parents for example, I really wonder if it's a realistic expectation that people know what the important part of a URL are. They need to parse slashes, dots, colons and ats (remember URLs can contain credentials, even though I believe browser issue warnings these days), identifiy the TLD and the domain and then know what is…

The Internet has been around long enough at this point. Maybe your parents might never be able to read a URL and there will always be people who get scammed.

But we should be taking the obvious steps like enforcing government domains on .gov . Attacks and scams are getting more sophisticated, so I hope when I'm elderly I can atleast check the .gov portion and know it's an actual government website.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#37
post #6

Its not just in US, it happens in every country. SMS is the main way these links are distributed. So much so that in Sri Lanka, gov planned to add a centralized SMS firewall. https://economynext.com/sri-lanka-to-study-infobip-centraliz... Google messages have a good spam filter than can filter in real time them, but I have seen some get though for a small period of time.

RCS messaging being adopted on Android has meant that I now get added to spam group chats called "USPS" by some criminals impersonating the post office.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#38
post #25

Earlier quoted context omitted.

I wonder if the .com TLD is part of the GOP campaign to kill the USPS

USPS purchased the usps.com domain a long time ago specifically so they could control it and prevent phishing. The decision to replace usps.gov with the .com domain came later, with the tenure of Trump appointee Louis DeJoy. Right wingers believe that USPS should operate as a business, not a public service, so "rebranding" their website to be .com is definitely a part of that narrative.

It's been USPS.com branding since at least 2000, aka the Bush administration. [1]

[1] https://web.archive.org/web/20000229182038/http://www.usps.g...

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#39
post #32

Earlier quoted context omitted.

You're right that it doesn't help, but looking at regular non-technical people like my retired parents for example, I really wonder if it's a realistic expectation that people know what the important part of a URL are. They need to parse slashes, dots, colons and ats (remember URLs can contain credentials, even though I believe browser issue warnings these days), identifiy the TLD and the domain and then know what is…

The Internet has been around long enough at this point. Maybe your parents might never be able to read a URL and there will always be people who get scammed. But we should be taking the obvious steps like enforcing government domains on .gov . Attacks and scams are getting more sophisticated, so I hope when I'm elderly I can atleast check the .gov portion and know it's an actual government website.

It's not just the elderly generation though. Young people mostly use apps and might barely interact with an actual browser. Big browsers de-emphasize the URL bar more and more. Yes, you and I and probably everyone on HN will never have a problem with this, but significant portions of the population will. I think it's a hard problem.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#40
post #25

Earlier quoted context omitted.

I wonder if the .com TLD is part of the GOP campaign to kill the USPS

USPS purchased the usps.com domain a long time ago specifically so they could control it and prevent phishing. The decision to replace usps.gov with the .com domain came later, with the tenure of Trump appointee Louis DeJoy. Right wingers believe that USPS should operate as a business, not a public service, so "rebranding" their website to be .com is definitely a part of that narrative.

This does not jibe with my recollection, which is that usps.com has always been the main site. And now, after a quick interent search, I find many references[0] that show your claim is wrong -- the use of the .com domain pre-dates DeJoy by many years, going back in fact to the days when WWW was starting to get widespread use (because .com was far better known than .gov).

[0]here is just one: https://www.reddit.com/r/explainlikeimfive/comments/3piv7w/e...

Post reply on HN