Live data from Hacker News

Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

akamai.com

41–50 of 75 posts

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#41
post #25

Earlier quoted context omitted.

I wonder if the .com TLD is part of the GOP campaign to kill the USPS

USPS purchased the usps.com domain a long time ago specifically so they could control it and prevent phishing. The decision to replace usps.gov with the .com domain came later, with the tenure of Trump appointee Louis DeJoy. Right wingers believe that USPS should operate as a business, not a public service, so "rebranding" their website to be .com is definitely a part of that narrative.

> Right wingers believe that USPS should operate as a business, not a public service, so "rebranding" their website to be .com is definitely a part of that narrative.

Seems failing businesses is also on brand for those guys.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#42
post #32
post #24

USPS.gov redirecting to USPS.com certainly doesn't help matters. Things like this should use one of the few TLDs that actually has policies and procedures in place; then it's a simple "if it's not .gov, it's not real."

You're right that it doesn't help, but looking at regular non-technical people like my retired parents for example, I really wonder if it's a realistic expectation that people know what the important part of a URL are. They need to parse slashes, dots, colons and ats (remember URLs can contain credentials, even though I believe browser issue warnings these days), identifiy the TLD and the domain and then know what is…

That's like suggesting people don't need to know what the zip code is because it's often redundant and omitted. People are often lazy, but it's immediately obvious to anyone that omitting the full 9-digit zip code could result in the letter being misdelivered, even if I don't understand what the last 4 digits are even for.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#43
post #32
post #24

USPS.gov redirecting to USPS.com certainly doesn't help matters. Things like this should use one of the few TLDs that actually has policies and procedures in place; then it's a simple "if it's not .gov, it's not real."

You're right that it doesn't help, but looking at regular non-technical people like my retired parents for example, I really wonder if it's a realistic expectation that people know what the important part of a URL are. They need to parse slashes, dots, colons and ats (remember URLs can contain credentials, even though I believe browser issue warnings these days), identifiy the TLD and the domain and then know what is…

The root of all these things is companies, banks, and governments offloading the responsibility of security on to the worst possible person - the end user.

"Identify theft" should simply not be a thing at all - it's fraud against the bank and the person's whose "identity" was stolen shouldn't be involved. Combined with simple fraud chargebacks that make the bank accountable if they can't make their (fraudulent) customer accountable would reduce much of it.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#44
It might not change anything, but I think the criminal penalties for scams need to be significantly raised.

The idea of reaching out to someone you don't know at all and attempting to steal their money by lying and betraying their confidence is morally disgusting. The type of people who can do this hundreds or thousands of times a day are criminals of the worst and least redeemable kind, yet if caught they would likely face a smaller penalty than someone who steals a single piece of jewelry from a store.

We are slowly losing our ability to trust each other because of the prevalence of scams which adds massive transaction costs to every legitimate exchange. These costs are unseen but they make almost everything we buy slower and more expensive.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#45

I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about…

> Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about it one day" shrug This is my problem with almost every "report spam/fraud/etc" flow. It's always a digital shrug, and then nothing happens. Only one site I know of ever had it right: Instagram, up to about 2021. When you reported an account or post, you would actually be notified…

The problem with the feedback is scammers can abuse it - they report a few of their own scams and then use feedback to check on those and thus see what happened an in turn they better know when they are blocked and have a better idea how to create new accounts that are hard to block.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#46
post #32
post #24

USPS.gov redirecting to USPS.com certainly doesn't help matters. Things like this should use one of the few TLDs that actually has policies and procedures in place; then it's a simple "if it's not .gov, it's not real."

You're right that it doesn't help, but looking at regular non-technical people like my retired parents for example, I really wonder if it's a realistic expectation that people know what the important part of a URL are. They need to parse slashes, dots, colons and ats (remember URLs can contain credentials, even though I believe browser issue warnings these days), identifiy the TLD and the domain and then know what is…

If nothing else, their browser could know that.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#47
post #32

Earlier quoted context omitted.

You're right that it doesn't help, but looking at regular non-technical people like my retired parents for example, I really wonder if it's a realistic expectation that people know what the important part of a URL are. They need to parse slashes, dots, colons and ats (remember URLs can contain credentials, even though I believe browser issue warnings these days), identifiy the TLD and the domain and then know what is…

That's like suggesting people don't need to know what the zip code is because it's often redundant and omitted. People are often lazy, but it's immediately obvious to anyone that omitting the full 9-digit zip code could result in the letter being misdelivered, even if I don't understand what the last 4 digits are even for.

It's honestly not that obvious. I never knew there's a difference between the 5-digit and 9-digit versions of my zip code. Most checkout flows do not even allow me to input more than 5 digits in the first place. But upon receiving my mail, the 5-digit code is always corrected to the 9-digit one.

I had never considered that if there were multiple 9-digit expansions of a 5-digit zip code, the correction might turn out wrong unless the full 9-digit code is specified.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#48
post #44

It might not change anything, but I think the criminal penalties for scams need to be significantly raised. The idea of reaching out to someone you don't know at all and attempting to steal their money by lying and betraying their confidence is morally disgusting. The type of people who can do this hundreds or thousands of times a day are criminals of the worst and least redeemable kind, yet if caught they would like…

Increasing penalties has much less effect on crime than increasing the likelihood of them getting caught. If there is a slim chance of them getting caught it doesn't matter what the penalty is because they will do it anyway.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#49
post #32

Earlier quoted context omitted.

You're right that it doesn't help, but looking at regular non-technical people like my retired parents for example, I really wonder if it's a realistic expectation that people know what the important part of a URL are. They need to parse slashes, dots, colons and ats (remember URLs can contain credentials, even though I believe browser issue warnings these days), identifiy the TLD and the domain and then know what is…

That's like suggesting people don't need to know what the zip code is because it's often redundant and omitted. People are often lazy, but it's immediately obvious to anyone that omitting the full 9-digit zip code could result in the letter being misdelivered, even if I don't understand what the last 4 digits are even for.

The Zip+4 last four digits align to delivery zones. It can be trivially constructed from the complete address now that we have reliable digital mapping systems, and in fact this is what happens internally in the postal system.

It is not required and will likely never be required to provide a 9 digit ZIP for reliable delivery. It may, and does sometimes, impact speed of delivery due to sorting/distribution rounds.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#50
post #22
post #6

Its not just in US, it happens in every country. SMS is the main way these links are distributed. So much so that in Sri Lanka, gov planned to add a centralized SMS firewall. https://economynext.com/sri-lanka-to-study-infobip-centraliz... Google messages have a good spam filter than can filter in real time them, but I have seen some get though for a small period of time.

I periodically wonder how quickly this would end if the costs shifted to the telcos who currently see it as a profit center. Imagine if reporting a message got you an immediate $1 credit and they had to recover it from the network which originated the spam: how quickly would they be able to turn on egress filtering?

The fact that telcos are really party to these scams and for some reason aren't held accountable is amazing to me.
Post reply on HN