Live data from Hacker News

A large collection of fraudulent web stores

chair6.net

41–50 of 75 posts

Re: A large collection of fraudulent web stores

#41

Earlier quoted context omitted.

> To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. I think this can just add layers of bureaucracy that don't address the problem anyway. In the early days of widespread internet use in Sweden it was quite difficult to register a .se web-address: not only were company documents needed, but the authority that granted use of the address…

I'm not saying that you need to be a company to have your own domain. I'm saying that if your domain represents a company there should be some way to automatically check that against a database of registered businesses

Wasn't that what the higher tier SSL certificates effectively aimed to do?

Re: A large collection of fraudulent web stores

#42
I wonder if the best bet would be to hash the main site and its images. Then retroactively scan sites with similar HTML hash and flag them?

Fairly sure you could do a HTML search with Google, 7 stores having extremely similar HTML and images seems rather unlikely.

Effectively, it's virus total but for copycat sites.

Re: A large collection of fraudulent web stores

#43

Earlier quoted context omitted.

I'm not saying that you need to be a company to have your own domain. I'm saying that if your domain represents a company there should be some way to automatically check that against a database of registered businesses

Wasn't that what the higher tier SSL certificates effectively aimed to do?

Yes, EV(Extended Validation) was for that, the certificate authority had to verify you're a legitimate business with that name. However it didn't really work well: https://arstechnica.com/information-technology/2017/12/nope-...

Re: A large collection of fraudulent web stores

#45
post #40
post #29

Earlier quoted context omitted.

My rude opinion: imprint is nonsense. It does not protect you from fake shops at all. It’s no brainer to copy one from another shop. As a legit seller you can be sued by shady layers for errors in imprint. Who is looking in public registers while shopping online…

For well known shops: Probably nobody. But if I find a good price on an unknown (to me) shop I'll check the tax ID from the imprint on Google. CRT.sh is also nice to figure out how long an operation has been using SSL (e.g. mtz-elektronik[dot]de is used by scammers on hacked Amazon shops since a few days).

I think their argument was that anybody can just copy the imprint of a legitimate business.

It doesn't stop the fraudulent "potato-shop.de" from trying to look like the real "potatoshop.de".

Re: A large collection of fraudulent web stores

#46
post #30

Earlier quoted context omitted.

I mean, if you sell stuff on the internet I should be able to make sure you're an actual reachable entity with legal responsibility. Now, it they made it into a standard that could be included into the browser's UI...

Yes, I do think it’s absolutely sensible to make something like this mandatory for people who sell stuff or have some kind of commercial interest. However, the law is pretty unclear about what is considered commercial interest. This effectively leads to the situation where basically any site of any kind is expected to have an imprint or otherwise, you can expect to get a nice and expensive writing from a lawyer.

It shouldn't be mandatory. You should just be able to attach all your domains to your entry in the commercial register.

Then browsers could query it and show that's it legitimate.

But it's probably really hard to implement for technical and legal and organisational reasons.

Re: A large collection of fraudulent web stores

#47

The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

The thing is, we tried this already. Twice.

First with domain names. The domain "nissan.com" is not owned by the well-known car company but by a completely unrelated computer company. As "Nissan Motors v. Nissan Computer" settled, this is totally fine and Nissan Computer still owns the domain.

Besides exact matches there are also similar-looking names. For example, a student named Mike Rowe started a small webdesign company called MikeRoweSoft, which drew the attention of Microsoft, leading to "Microsoft v. MikeRoweSoft" - which was settled out of court and resulted in the domain being transferred to Microsoft.

Second are Extended Validation domains - which used to show the company name in the URL bar. As Ian Carroll demonstrated[0] this isn't really worth a lot, and browsers no longer bother showing it at all[1].

Company names also often overlap when they are active in different areas, such as Apple Corp (record label founded by The Beatles) and Apple Inc. (tech multinational) - which over the years have shifted towards a rather impressive market overlap! Some companies are split with both sides keeping the original name, such as Motorola Inc.'s split into Motorola Solutions and Motorola Mobility. Sometimes products are sold under a completely different brand name, such as HMD selling Nokia-branded smartphones, or TP Vision selling Philips-branded televisions while MMD sells Philips-branded gaming monitors!

The thing is, reality is just too complicated for a "very simple" register. How are you supposed to fit in all of the scenarios listed above while still keeping it usable?

[0]: https://arstechnica.com/information-technology/2017/12/nope-... [1]: https://www.troyhunt.com/extended-validation-certificates-ar...

Re: A large collection of fraudulent web stores

#48

Isn't this something that Extended Validation certificates were designed to address?

Ish. But there are two significant flaws for ecommerce:

1. Knowing that the company using the certificate is who they say they are, doesn't necessarily mean you can trust them not to be fraudulent traders.

2. Control of the domain names and associated certificates can change hands after the fact, officially through buyouts/merges or via more nefarious means, just like any other certificate.

and of course the other key question to address which is:

3. How do you trust those validating the certificate. The average user is not going to know/care that a rogue CA exists and it might take some time for their actions to be noticed and for appropriate revocations to happen.

However they were intended to be used, HTTPS and certificates for it are used to protect data in transit and not really for identity assurance.

----

There is also the more cynical view that the main thing EV certs addressed was the desire for CAs to bring in some revenue, especially as standard certs became more and more a commodity item (now effectively free) with low or zero margins.

Re: A large collection of fraudulent web stores

#49

The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

Even better, let's get rid of names as identifiers. We all know names are problematic.

We could use government-issued tokens, maybe on a government-run blockchain.

And we could use the same for our personal (corporate) selves, such that all of our economic interactions were moderated through a government-run identity blockchain.

I want the mark on my forehead please, not the wrist, so I can pay by bowing my head to the money-god instead of just laying my wrist on the sensor.

What could possibly go wrong?

Re: A large collection of fraudulent web stores

#50

The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

[deleted]
Post reply on HN