Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

51–60 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#51
post #33

Earlier quoted context omitted.

The lions share of issues with domains would go away if we made squatting illegal, or at the least, extremely expensive. Tbh I'm increasingly thinking that just about any speculative instrument in the economy is just grift and drag. If you want to make money, make things. Stop trying to extract rent or exorbitant prices for land, for domains, for PS5s, etc. Feels like 9/10ths of the economy now is nothing but fucking…

>The lions share of issues with domains would go away if we made squatting illegal, or at the least, extremely expensive. How do you define squatting? Is the owner of nissan.com "squatting" on it because he wouldn't sell to the japanese car company? How much interest do you need in a given domain before it's not squatting?

It's not a particularly hard problem. Most countries have rules on what you can use as a business name or register as a trademark. Domain names are just more of the same.

And you don't really own your domain. You are just renting it from whichever authority is responsible for the TLD. If you stop paying, the authority will eventually take it back.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#52

The whole environment of the newer gTLDs just feels… gross. I rarely find a reputable business that is using anything but .com or .co.XX as the primary domain. Putting on my regular-person hat: When I see a billboard or print ad with e.g. `example.travel`, I read that as a social media handle and not a website address like `example.com` would convey. In public perception, dot com means websites. Always has. (Tangenti…

I never deal with co.xx to be honest. Most websites I visit are on ccTLDs. Whenever I see a .com link to any local business, I start out by assuming it's a scam website.

That said, .app has found plenty of adoption. Tech companies absolutely love .io and .ai is now also gaining popularity. The good American URLs have all been bought years ago so people flock to ccTLDs and gTLDs for new products and businesses. Even .engineering has a few interesting businesses on it these days.

As for .sucks, it's clearly a cash grab, but banning it hardly solves a problem. ycombinatorsucks.com is a lot cheaper than ycombinator.sucks, and if ycombinator pre-emptively buys ycombinatorsucks.com, you could just buy ycombinatorisshit.com or ycombinatorisadoodoohead.com.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#54
post #5

I have always thought the infinite proliferation of TLDs was a stupid idea. I'd be enlightened if I could think of one scenario that benefits from it outside of the registrars.

DNS should be a destination, not a utility. Every John Smith has a legitimate claim on smith.com.

DNS should offer disambiguation services. Instead, we have this awful system.

My dream is to fork a browser and replace the DNS component with an entirely new protocol that respects the notion that people in the real world share names.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#55
post #33

Earlier quoted context omitted.

>The lions share of issues with domains would go away if we made squatting illegal, or at the least, extremely expensive. How do you define squatting? Is the owner of nissan.com "squatting" on it because he wouldn't sell to the japanese car company? How much interest do you need in a given domain before it's not squatting?

It's not a particularly hard problem. Most countries have rules on what you can use as a business name or register as a trademark. Domain names are just more of the same. And you don't really own your domain. You are just renting it from whichever authority is responsible for the TLD. If you stop paying, the authority will eventually take it back.

Trademarks are specific to the field it is used on. Classic example is Apple Records vs Apple Computers, which one should get apple.com?

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#56
post #33

Earlier quoted context omitted.

>The lions share of issues with domains would go away if we made squatting illegal, or at the least, extremely expensive. How do you define squatting? Is the owner of nissan.com "squatting" on it because he wouldn't sell to the japanese car company? How much interest do you need in a given domain before it's not squatting?

I would argue if you aren't doing some combination of: - Hosting a website - Operating email accounts - Infrastructure (mail, DNS, etc.) - Misc. Services (Minecraft server, TeamSpeak server, something) Then you're squatting. Like if you own turkeyonapig.com and it's literally just a web page with a picture of a turkey sitting on a pig? Not squatting. It's odd but it's clearly doing exactly what it's meant to be doing…

And you think a domain squatter would be deterred by high pricing and not just point every single domain to a VPS with a „Hey guys buy my domains“ page? Or even just point them to any random IP, since DNS is one of the legitimate uses you named?

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#57

The implication that gTLDs are bad and new ones shouldn't be introduced because of this is a bit silly to me. The argument that they somehow have lower registration requirements makes no sense, .shop .top and .xyz registrations involve the exact same amount of verification as .com (none). Prices aren't really that different and plenty of gTLDs are more expensive than traditional ones. Registering a domain is frustrat…

I think the issue is you can register a known company name on one of these and plenty of people will think it's legit. Companies have to register on all these random domain to protect themselves. dell.shop, that's probably the dell computer I know, right?

I'm doubtful that most non-technical people familiarize themselves with TLDs/domain names. They use a search provider for whatever they need. As far as emails/phishing goes, it's a game of cat and mouse; it will never be over. Basically, don't trust unprompted email links and just go to the site if it's something you really want.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#58
post #6

Earlier quoted context omitted.

Interesting! Now that you mention it, I did buy a .luxury domain for this purpose - a Gemini server. I also bought a .ski to have a domain with my (polish) last name.

It's great to be able to get silly domains for projects, back to the old days of IRC vanity hosts, but can you imagine seeing a link to something like jackets.luxury and going "yeah that seems legit, I'm definitely giving them my card details"

The first English result on Google for a .luxury site is this: https://leon.luxury/

It looks legitimate, and it's probably enabled Leon to use their business name in the domain.

The first American site is https://roughwood.luxury/, it also looks fine.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#59

Earlier quoted context omitted.

I would argue if you aren't doing some combination of: - Hosting a website - Operating email accounts - Infrastructure (mail, DNS, etc.) - Misc. Services (Minecraft server, TeamSpeak server, something) Then you're squatting. Like if you own turkeyonapig.com and it's literally just a web page with a picture of a turkey sitting on a pig? Not squatting. It's odd but it's clearly doing exactly what it's meant to be doing…

> a web page with a picture of a turkey sitting on a pig? Not squatting GPT/Cursor will create that page for you in 5 min. I bet a NotSquattingAsAService startups will appear which will create the "not squatting" fake site for you for $2.

NotSquattingAsAService startups will appear which will create the "not squatting" fake site for you for $2.

That's an improvement. Adding $2 to $5 to the cost of a squatted domain will start to dissuade people who squat on tens of thousands of domains, if they have to suddenly have to pay $20,000 to $50,000 for the not squatting service.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#60

Earlier quoted context omitted.

There are a few options, though. The fact that .io got so popular shows that we are not forever chained to .com. It's just that a lot of the nuTLD options are honestly hilariously bad, most of them are just lame. My personal top picks are ".online" and ".software" with mention to ".network" but they're all WAY too long. I actually use ".cafe" for my personal stuff because it's short and cute. Obviously can't use that…

Unfortunately, .io is now also unsafe with the upcoming transfer away from the UK; another cautionary tale for those considering not getting a .com. I’ve been seeding government and business forms with a .io email address for years (to counter gmail dominance), and I’m quite concerned about the situation now.

That's because it's a ccTLD, not because it's not dot-com though. The powers that be could very well decide to just promote it to be a gTLD if they wanted to not destroy stuff for no reason. Actual gTLDs aren't susceptible to the same kinds of issues.
Post reply on HN