Live data from Hacker News

The short tale of an online scam

duarteocarmo.com

81–90 of 98 posts

Re: The short tale of an online scam

#81
post #21

"always look at the url bar" I remember reading about a scam where the URL seemed legit, and the suspicious part was pushed after so much white space that it was no longer visible in the URL bar. I don't remember the details and I'd be curious to know if anyone remembers it. I remember even sophisticated users saying they might have fallen for it.

I've seen that with an @ symbol. http://www.amazon.com@192.168.0.1/login

Scam works well since it is assisted by HN truncating the link. Then assisted by Apple because when i long press to see URL on iPhone it loads the website preview before i can see if it’s safe to click.

Re: The short tale of an online scam

#82

What's going on with .icu domains? Any idea on why they've been so prone to spam?

.icu, .club, and a few other gTLDs can often be found for sale at $1-2/year, so they are used by entities in need of low cost disposable domains.

yeah but this guy was already counting 80000+ domains, that is at least the same amount of money, or is there some deal if you buy a large number of domains?

Re: The short tale of an online scam

#83

Earlier quoted context omitted.

how they suppose to learn about it or at least be curious about it if they do not even see it? >I buy it honestly. phishing should look nice to the victim?

The idea is not to make phishing look nice to the victim, it's to make it more obvious that it's phishing to the attempted victim. The path component is irrelevant to detecting phishing, but the host component is very relevant. I don't know if there's any research on users to confirm that this works. It would be good to do such research before making such a change, if that's the motivation for the change. But it seem…

>... The path component is irrelevant to detecting phishing ...

What become irrelevant is the AddressBar itself for the user.

User simply doesn't look at it at all because usually it is not changing with each click. So it appears irrelevant and disconnected from the actions user takes.

It looks for non-technical person as "some name of the web site which doesn't always shows the right name, but it's ok because hey nothing works perfectly on computer anyway ... so it doesn't matter". This is how it looks to the average person. They do not even understand why it's there. "Just takes the space ... Why it's there? Site shows name anyway on the page ... " They just have no idea what is going on thanks to this wonderful idea of removing the real address bar ... Not that they were too much aware before but at least you could explain them ... not anymore.

According to my experience non-technical people just lost the concept of url completely and do not even know where it is. Even when one asks them about it specifically. These are the 'real' results of this idiotic idea which I observe in practice and I unfortunately I observe it too frequently to ignore it. But hey .. downvoters of my previous sarcastic post seems to be very happy to ignore the reality. They would rather stick to their wise decision and downvote reality if they do not like it. Good luck with that.

Re: The short tale of an online scam

#84
post #50

Earlier quoted context omitted.

how they suppose to learn about it or at least be curious about it if they do not even see it? >I buy it honestly. phishing should look nice to the victim?

In the case of OP, what the user would see in the bar would be 'delivery-85367.icu' which looks very suspicious.

They would see nothing becaue they do not look there anymore at all. Average person would think:"it's some bug with showing the name of the site" and would ignore it because users get used to the 'barely working everything' with computers these days.

Re: The short tale of an online scam

#85
post #49

Earlier quoted context omitted.

Non-scammers is a pretty broad set of people, most of whom are not interested in that. Who specifically do you have in mind?

people who set up websites that they don't want tracked back to them - historically speaking gay people might want to be anonymous in all sorts of scenarios and for all sorts of reasons. I'm working helping out an artistic collective in which the various members are anonymous to various degrees. There may need to be anonymity in paying for services - this is an obvious necessity nowadays - for example the whole recen…

Historical gay people aren't buying websites today. And plenty of registrars already allow private registration. Artists who remain anonymous typically solve the problem through having a trusted representative. E.g., someone like yourself.

So I don't think any of your examples hold up.

Re: The short tale of an online scam

#86
post #39
post #16

An obvious red flag for me is always an opening message with "I'm interested in X", where "X" is verbatim copied off the title of the ad.

The problem with that (at least in what I've sold online), is that older/elderly people tend to copy and paste into their messages or type it out verbatim. Again, maybe that's specific to woodworking tools and supplies, because those people tend to skew older, but I have legit asked 4 or 5 buyers, this year alone, if they were bots because that is literally their first line.

I wonder if there is any causality here and if so, what the chicken and egg is here... Do old people mimic the scammers who text them or did scammers start mimicking old people?

Re: The short tale of an online scam

#87
post #77

Earlier quoted context omitted.

> one designer I know calls it a debugging tool that should never have been released in the first place I've heard similar comments but I don't understand how people would be expected to navigate around the internet? Is the idea that Google's search input should replace it? So if I want to go to sec.gov I should search SEC and click the link (hopefully) provided at the top of the results rather than just go there dir…

In my limited experience, most browsers do what you describe already. Unless you type a 100% correct URL (and sometimes even if you do), a normal browser will send your URL string to Google (or similar entity), who will send back a redirect. The process is fast enought for you not to notice. It is often possible (if hard) to configure browsers to do traditional URL resolving, but I wouldn’t bet on it always being pos…

The url you type is 100% correct. Sure, maybe you made a typo, but the browser didn't know that. It isn't sending your url to Google and waiting for a redirect. A redirect to what? A different url?

Re: The short tale of an online scam

#88
post #85

Earlier quoted context omitted.

people who set up websites that they don't want tracked back to them - historically speaking gay people might want to be anonymous in all sorts of scenarios and for all sorts of reasons. I'm working helping out an artistic collective in which the various members are anonymous to various degrees. There may need to be anonymity in paying for services - this is an obvious necessity nowadays - for example the whole recen…

Historical gay people aren't buying websites today. And plenty of registrars already allow private registration. Artists who remain anonymous typically solve the problem through having a trusted representative. E.g., someone like yourself. So I don't think any of your examples hold up.

>Historical gay people aren't buying websites today.

it's hard for me to take that statement as having been made in good faith but at any rate when I say historically I do not mean if someone was building a website in 1950 they sure would want to be anonymous I mean that throughout history, up until the present day there are people who want to remain anonymous who are not scammers and used gay people as an example - which gay people sometimes want to remain anonymously gay but express themselves even today!

And then I linked the description of a story published last year in which the anonymous author was harassed over sexual issues.

Given the example I linked to then

>Artists who remain anonymous typically solve the problem through having a trusted representative. E.g., someone like yourself.

It might be that representatives of controversial artists or the technical help for such might like some level of anonymity themselves, given that anonymous writers can receive death threats it seems that public representatives of such can receive them as well.

Re: The short tale of an online scam

#89
post #85

Earlier quoted context omitted.

Historical gay people aren't buying websites today. And plenty of registrars already allow private registration. Artists who remain anonymous typically solve the problem through having a trusted representative. E.g., someone like yourself. So I don't think any of your examples hold up.

>Historical gay people aren't buying websites today. it's hard for me to take that statement as having been made in good faith but at any rate when I say historically I do not mean if someone was building a website in 1950 they sure would want to be anonymous I mean that throughout history, up until the present day there are people who want to remain anonymous who are not scammers and used gay people as an example -…

I asked you for examples. It was entirely in good faith for me to point out that your first example was not actually an example.

Fall was already anonymous, and her anonymity was protected by the editor, just as I described. So anonymous payment for a web presence, one that she didn't have, wouldn't have helped here. And as you point out, the anonymity didn't prevent her from getting criticism (not harassment as far as I know); indeed, one of the lessons of the Fall incident seems to be that poorly managed anonymity breeds unnecessary suspicion.

As to your last "might be", anything might be. What I'm looking for is an example of where the social harm that can come through anonymity, specifically anonymous payment, is worth putting up with to provide some social good. So far I'm still looking.

As it is, I'll note that even your well-performed outrage over fears of harassment doesn't is out of place here, as harassers often make vigorous use of anonymity. E.g., look at Near, the latest addition to the KiwiFarms kill count.

Re: The short tale of an online scam

#90
post #77

Earlier quoted context omitted.

In my limited experience, most browsers do what you describe already. Unless you type a 100% correct URL (and sometimes even if you do), a normal browser will send your URL string to Google (or similar entity), who will send back a redirect. The process is fast enought for you not to notice. It is often possible (if hard) to configure browsers to do traditional URL resolving, but I wouldn’t bet on it always being pos…

The url you type is 100% correct. Sure, maybe you made a typo, but the browser didn't know that. It isn't sending your url to Google and waiting for a redirect. A redirect to what? A different url?

No, a redirect to the correct URL, the URL you typed, or meant to type.
Post reply on HN