Live data from Hacker News

Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

akamai.com

51–60 of 75 posts

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#51
post #32

Earlier quoted context omitted.

You're right that it doesn't help, but looking at regular non-technical people like my retired parents for example, I really wonder if it's a realistic expectation that people know what the important part of a URL are. They need to parse slashes, dots, colons and ats (remember URLs can contain credentials, even though I believe browser issue warnings these days), identifiy the TLD and the domain and then know what is…

That's like suggesting people don't need to know what the zip code is because it's often redundant and omitted. People are often lazy, but it's immediately obvious to anyone that omitting the full 9-digit zip code could result in the letter being misdelivered, even if I don't understand what the last 4 digits are even for.

I'm 38, live in the SF Bay area, and have never given anyone more than the first 5 digits in my life. Online some might auto correct, but I've never learned them in my life and never even considered I should.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#52
post #39

Earlier quoted context omitted.

The Internet has been around long enough at this point. Maybe your parents might never be able to read a URL and there will always be people who get scammed. But we should be taking the obvious steps like enforcing government domains on .gov . Attacks and scams are getting more sophisticated, so I hope when I'm elderly I can atleast check the .gov portion and know it's an actual government website.

It's not just the elderly generation though. Young people mostly use apps and might barely interact with an actual browser. Big browsers de-emphasize the URL bar more and more. Yes, you and I and probably everyone on HN will never have a problem with this, but significant portions of the population will. I think it's a hard problem.

Isn't the simple solution to this to encourage everyone to use the USPS app (and apps for banking, etc.)? Most young people probably do this already.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#53
post #25

Earlier quoted context omitted.

I wonder if the .com TLD is part of the GOP campaign to kill the USPS

USPS purchased the usps.com domain a long time ago specifically so they could control it and prevent phishing. The decision to replace usps.gov with the .com domain came later, with the tenure of Trump appointee Louis DeJoy. Right wingers believe that USPS should operate as a business, not a public service, so "rebranding" their website to be .com is definitely a part of that narrative.

fake news ... i love how people always blame dejoy even tho he is one of the better PMG's we've had... and then right wingers somehow enter the picture? I've been working at usps in tech for 15 years...this has nothing to do with dejoy or right wingeres and .com has existed for a very long time as the main external facing website for customers

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#54
post #52
post #39

Earlier quoted context omitted.

It's not just the elderly generation though. Young people mostly use apps and might barely interact with an actual browser. Big browsers de-emphasize the URL bar more and more. Yes, you and I and probably everyone on HN will never have a problem with this, but significant portions of the population will. I think it's a hard problem.

Isn't the simple solution to this to encourage everyone to use the USPS app (and apps for banking, etc.)? Most young people probably do this already.

This just moves the mimicry to the app stores. Admittedly there's some curation but it's far from perfect

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#56

Earlier quoted context omitted.

Just curious, how did you confirm it was The Canada Revenue Agency and not scammers?

I logged into the CRA website and found something.

"Contact the suspicious person back through the official number or website" is always a good heuristic, especially since it works pretty well as advice for non-technical relatives.

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#57

Earlier quoted context omitted.

USPS purchased the usps.com domain a long time ago specifically so they could control it and prevent phishing. The decision to replace usps.gov with the .com domain came later, with the tenure of Trump appointee Louis DeJoy. Right wingers believe that USPS should operate as a business, not a public service, so "rebranding" their website to be .com is definitely a part of that narrative.

It's been USPS.com branding since at least 2000, aka the Bush administration. [1] [1] https://web.archive.org/web/20000229182038/http://www.usps.g...

I meant Clinton administration

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#58
post #43
post #32

Earlier quoted context omitted.

You're right that it doesn't help, but looking at regular non-technical people like my retired parents for example, I really wonder if it's a realistic expectation that people know what the important part of a URL are. They need to parse slashes, dots, colons and ats (remember URLs can contain credentials, even though I believe browser issue warnings these days), identifiy the TLD and the domain and then know what is…

The root of all these things is companies, banks, and governments offloading the responsibility of security on to the worst possible person - the end user. "Identify theft" should simply not be a thing at all - it's fraud against the bank and the person's whose "identity" was stolen shouldn't be involved. Combined with simple fraud chargebacks that make the bank accountable if they can't make their (fraudulent) custo…

[deleted]

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#59
post #24

USPS.gov redirecting to USPS.com certainly doesn't help matters. Things like this should use one of the few TLDs that actually has policies and procedures in place; then it's a simple "if it's not .gov, it's not real."

This is a problem I have a REALLY hard time with when discussing with people, often about scams.

A lot of people look at scams and think "I'd never fall for that" because at face value something looks obvious and you think you can use these obvious filters. BUT in reality there's tons of fuckups like this that make the space confusing because the "red flags" just look like flags.

For example, in the scams where people fake a voice of a loved one people think they'd know. But there's bad connections and scammer makes it feel like an emergency so you'll let little weird things slip by. Or how every year or two Google changes its login page format (and currently I seem to hit two very different formats...). Or a week ago with the rabbit leak I said this was a reason not to push people to download a file[0] and people concentrated on the part of it being a zip and not that 1) you download something and 2) that zip has to be opened even if a zip alone can't do anything.

This really is one of the big dangers of enshitification. It becomes difficult to distinguish legitimate things from scams.

[0] https://news.ycombinator.com/item?id=40135671

Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself

#60
Reminds me of the fake police station in Do Androids Dream of Electric Sheep [1]. In order to keep up the pretense for three years, the androids have to take crime reports, do paperwork, and arrest perpetrators. In other words, they have to run an actual real police station. So perhaps the fake USPS sites should just start delivering the post!

[1] https://en.wikipedia.org/wiki/Do_Androids_Dream_of_Electric_...

Post reply on HN