Live data from Hacker News

A large collection of fraudulent web stores

chair6.net

71–75 of 75 posts

Re: A large collection of fraudulent web stores

#71
post #58

Earlier quoted context omitted.

IMO, the best solution to the problem is friction. Criminals are criminals because it's easy. If opening a fraudulent store is 90% as difficult as opening a legit one, no one is going to bother.

Organised criminal syndicates are behind most of these operations. They have immense resources from which to draw. It's another example of the saying, 'It takes money to make money.' IOW, adding friction wouldn't be a sufficient deterrent. Criminals are resourceful, and enriching themselves further is a strong motivator.

Aside from that, in today's online world, any time friction is added, people come along and make some grease for it. Making a storefront from scratch? Difficult! Using WooCommerce on Wordpress? So easy a sufficiently motivated 12 year old can figure it out.

If you add some system for site verification, first someone will make tooling to facilitate it and soon after someone will offer a service to provide it for you and in a matter of months these spam sites will be up and running just like they are now, only it will be more difficult for a legitimate newcomer to get started in the same arena.

Re: A large collection of fraudulent web stores

#72
post #58

Earlier quoted context omitted.

IMO, the best solution to the problem is friction. Criminals are criminals because it's easy. If opening a fraudulent store is 90% as difficult as opening a legit one, no one is going to bother.

I see what you're saying: if you add more startup cost then it makes it harder for spammers without legitimate business interest to profit. I think I disagree, though. Legitimate "mom and pop" businesses experience all the pain of learning the process of setting up a store, creating real products and pricing, inventory, delivery etc. They don't need more friction. These criminals on the other hand are likely automati…

Computers with built in NFC readers could allow you to pay for your purchases with your phone and use fingerprint/passcode/faceID etc. for verification.

That would be convenient enough for most people that it's usable.

Re: A large collection of fraudulent web stores

#73

Earlier quoted context omitted.

some PKI would prevent copying, the same way that no one else can pretend to be https://Google.com

There are political edge cases. Let's say I set up a site that's critical of an authoritarian government. I fund it with sales of merch and books and such. I want to be anonymous - for obvious reasons - but if I have to register my details I can't be. Also, accountability doesn't work without international authority. Some countries are more enthusiastic about accountability and the rule of law than others, and the on…

Internationally and more broadly, you're totally right. In the subthread of Germany and their existing Imprint registration system though, we have the technology for making it so the imprints can't just be copied by scammers, or at least make it harder than it currently is.

Re: A large collection of fraudulent web stores

#74
Thanks for investigating this and ultimately getting the fraudulent store taken down. I saw the same social media post regarding the fraudulent store and was surprised that a small local store was targeted with this kind of attack. A good mix of small stores and major corporations in the list. I wonder if they target the small stores because SEO is easier?

It's inspiring to see you follow up like this and help out a wonderful mountain shop. A great reminder and inspiration to be more involved in my community.

Re: A large collection of fraudulent web stores

#75
post #55
post #47

Earlier quoted context omitted.

The thing is, we tried this already. Twice. First with domain names. The domain "nissan.com" is not owned by the well-known car company but by a completely unrelated computer company. As "Nissan Motors v. Nissan Computer" settled, this is totally fine and Nissan Computer still owns the domain. Besides exact matches there are also similar-looking names. For example, a student named Mike Rowe started a small webdesign…

Your name confusion is missing the point. It's the central registration done at a national level, not a True delimitation of which domain names which companies can own. A company could use downloadfreeram.tk, as long as it's officially registered in the national company register.

So private individuals would not be allowed to register domains?

It sounds a bit like you just want WHOIS, which in practice turned out to be a bit useless.

Post reply on HN