Live data from Hacker News

A large collection of fraudulent web stores

chair6.net

51–60 of 75 posts

Re: A large collection of fraudulent web stores

#51

Earlier quoted context omitted.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

Even better, let's get rid of names as identifiers. We all know names are problematic. We could use government-issued tokens, maybe on a government-run blockchain. And we could use the same for our personal (corporate) selves, such that all of our economic interactions were moderated through a government-run identity blockchain. I want the mark on my forehead please, not the wrist, so I can pay by bowing my head to t…

A database of businesses already exists.

Businesses usually have domain names just like they have physical addresses.

If the database were to include the domain names we could make automatic checks to give the user more assurances.

Your reply is mind boggling and totally foreign to the topic.

Re: A large collection of fraudulent web stores

#52

Earlier quoted context omitted.

Even better, let's get rid of names as identifiers. We all know names are problematic. We could use government-issued tokens, maybe on a government-run blockchain. And we could use the same for our personal (corporate) selves, such that all of our economic interactions were moderated through a government-run identity blockchain. I want the mark on my forehead please, not the wrist, so I can pay by bowing my head to t…

A database of businesses already exists. Businesses usually have domain names just like they have physical addresses. If the database were to include the domain names we could make automatic checks to give the user more assurances. Your reply is mind boggling and totally foreign to the topic.

What database are you referring to? Is there an international database for all businesses registered in every single country that everyone universally signs up for when they incorporate?

Re: A large collection of fraudulent web stores

#53

Earlier quoted context omitted.

A database of businesses already exists. Businesses usually have domain names just like they have physical addresses. If the database were to include the domain names we could make automatic checks to give the user more assurances. Your reply is mind boggling and totally foreign to the topic.

What database are you referring to? Is there an international database for all businesses registered in every single country that everyone universally signs up for when they incorporate?

Every nation has its own. Nations that want to make their citizens safer when surfing the web could open up a standard API to make such automated queries

Re: A large collection of fraudulent web stores

#54
post #16

The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

In practice consumers just go straight to Amazon because they're afraid of the wider internet and depend on the return policy to save them when they get scammed. Doubt any "opt-in validation, ring of trust, p2p feedback and rating" will change that in the next decade.

This and the fact that they have your cc and shipping already on file, which makes things a lot easier. More than once I have found a product on some site and then purchased it from Amazon just because it is so much easier.

Re: A large collection of fraudulent web stores

#55
post #47

Earlier quoted context omitted.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

The thing is, we tried this already. Twice. First with domain names. The domain "nissan.com" is not owned by the well-known car company but by a completely unrelated computer company. As "Nissan Motors v. Nissan Computer" settled, this is totally fine and Nissan Computer still owns the domain. Besides exact matches there are also similar-looking names. For example, a student named Mike Rowe started a small webdesign…

Your name confusion is missing the point. It's the central registration done at a national level, not a True delimitation of which domain names which companies can own. A company could use downloadfreeram.tk, as long as it's officially registered in the national company register.

Re: A large collection of fraudulent web stores

#56
post #55
post #47

Earlier quoted context omitted.

The thing is, we tried this already. Twice. First with domain names. The domain "nissan.com" is not owned by the well-known car company but by a completely unrelated computer company. As "Nissan Motors v. Nissan Computer" settled, this is totally fine and Nissan Computer still owns the domain. Besides exact matches there are also similar-looking names. For example, a student named Mike Rowe started a small webdesign…

Your name confusion is missing the point. It's the central registration done at a national level, not a True delimitation of which domain names which companies can own. A company could use downloadfreeram.tk, as long as it's officially registered in the national company register.

OK. What do you do in the United States where every state (and territory and the federal administrative district) has its own company register? Or where a vast number of businesses are sole proprietorships that have registered their trade name in their local county office?

Re: A large collection of fraudulent web stores

#57
post #55

Earlier quoted context omitted.

Your name confusion is missing the point. It's the central registration done at a national level, not a True delimitation of which domain names which companies can own. A company could use downloadfreeram.tk, as long as it's officially registered in the national company register.

OK. What do you do in the United States where every state (and territory and the federal administrative district) has its own company register? Or where a vast number of businesses are sole proprietorships that have registered their trade name in their local county office?

Sounds like there might be some kind of solution for this that - just spitballing here - uses networked computers.

Re: A large collection of fraudulent web stores

#58

The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe. In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.

As weird as it sounds, it is still the best. If we have centralised "licensing" solution it is abused by large capital to wash off smaller - there is plenty of examples. If we have decentralised solution (which is basically what review is) - it is immediately abused by "marketers". There is no simple and easy solution to the problem.

IMO, the best solution to the problem is friction. Criminals are criminals because it's easy. If opening a fraudulent store is 90% as difficult as opening a legit one, no one is going to bother.

Re: A large collection of fraudulent web stores

#59
post #47

Earlier quoted context omitted.

To me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.

The thing is, we tried this already. Twice. First with domain names. The domain "nissan.com" is not owned by the well-known car company but by a completely unrelated computer company. As "Nissan Motors v. Nissan Computer" settled, this is totally fine and Nissan Computer still owns the domain. Besides exact matches there are also similar-looking names. For example, a student named Mike Rowe started a small webdesign…

.uk has .ltd.uk and .plc.uk which are only available to registered companies. No one uses them

Re: A large collection of fraudulent web stores

#60
post #28

Earlier quoted context omitted.

Oh they do copy this information! I became victim of such a fraud because the whole website looked really legitimate to me, and I am the "tech guy" in our family. Thing is: fraudsters create good looking websites and just copy all the company information from other stores, put in a non-working telephone number and email and they are good to go. There are thousands of small businesses that sell stuff online. One would…

some PKI would prevent copying, the same way that no one else can pretend to be https://Google.com

There are political edge cases.

Let's say I set up a site that's critical of an authoritarian government. I fund it with sales of merch and books and such.

I want to be anonymous - for obvious reasons - but if I have to register my details I can't be.

Also, accountability doesn't work without international authority. Some countries are more enthusiastic about accountability and the rule of law than others, and the ones who aren't can make money by selling "credible" domains to bad actors.

Of course after a while those domains will become less credible. But there are a lot of TLDs out there now, which makes the system very difficult to police without international cooperation.

In reality I can run a scam operation from a beach in Thailand, bank the money, shut it down, then run a very similar scam operation from a beach in Vietnam or Costa Rica. That won't change until there's some kind of international cyberpolice agency which will hunt me down across borders.

But then you get the anonymity problem.

Not simple, and no registration system will fix this.

Post reply on HN