Live data from Hacker News

Phishers Love New TLDs Like .shop, .top and .xyz

krebsonsecurity.com

81–90 of 220 posts

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#81
post #55

Earlier quoted context omitted.

Trademarks are specific to the field it is used on. Classic example is Apple Records vs Apple Computers, which one should get apple.com?

And there are also businesses with identical names. But the basic idea was already established long before the internet. If you have a legitimate claim to a name, you have a legitimate claim to that name. There may be multiple entities with a legitimate claim to a particular name, in which case the first one that used it in a particular context gets to use it in that context. And if you think that someone is using a…

The problem is that as you note, trademarks and company names are not unique, but domain names are required to be unique. So that n to 1 relationship between trademarks/names and domain names intrisically creates problem, how to allocate the domains when there are many equally legitimate pre-existing claimants. This is not solved problem the way you portray it, because domain names have this novel uniqueness requirement.

Of course this raises valid question if using names in this way at all is a good idea. For example telephone system and lots of banking stuff is based on simple numerical identifiers, and lots of countries have also some unique (numerical) identifiers for companies and persons. So there is fairly strong precedent for using assigned ids instead of names when uniqueness/specificity is required. But somehow we have jumped to the conclusion that for example IP addresses would be too confusing to average joe, and in attempt to hide them we have created even more confusing system.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#82

Earlier quoted context omitted.

Unfortunately, .io is now also unsafe with the upcoming transfer away from the UK; another cautionary tale for those considering not getting a .com. I’ve been seeding government and business forms with a .io email address for years (to counter gmail dominance), and I’m quite concerned about the situation now.

That's because it's a ccTLD, not because it's not dot-com though. The powers that be could very well decide to just promote it to be a gTLD if they wanted to not destroy stuff for no reason. Actual gTLDs aren't susceptible to the same kinds of issues.

> The powers that be could very well decide to just promote it to be a gTLD

No, they can’t do that. Every two-letter TLD is defined to be a ccTLD, and nothing else.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#84

Earlier quoted context omitted.

The problem is the new gTLDs don't increase the useful supply of domains. For casual usage like personal blogs and whatnot? Sure, use whatever. But if I was starting a web-based business and couldn't afford the .com? I'd rename the company before I'd use .xyz - if your business takes off the squatters will notice and raise their prices, so the .com will never be cheaper. If you got an "urgent e-mail" saying your empl…

If I got an 'urgent email' I wouldn't go to any domain, I would contact my employer directly and confirm with them before doing anything. The people who would fall for this phishing scam would fall for almost any domain, because it's not about the domain.

Millions of people don't have an employer with an HR department they can call on the phone to confirm that an email is legitimate.

What if your primary source of income is Uber or Doordash or Etsy or Youtube?

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#85
post #80

Earlier quoted context omitted.

When a scam hits someone's inbox or text message, it finds them in a particular time in their life, in a particular state of mind, and in a particular context. It's not just about how gullible or uninformed or whatever they are. They may be tired, they may be drunk, they may be spending all their energy worrying about a sick relative, or trying not to. They may have just been shopping for a computer, maybe even a del…

Whether people are more easily fooled by dell.shop dell.computershop.com is a non sequitur from the rather wordy disquisition about why people fall for the scams in general. The eye sees dell first in clear letters for both urls. Their sick relative doesn’t change much here. I would honestly not be sure if either is a scam for the url alone. The improbable deal at the other end is the only meaningful signal.

> Whether people are more easily fooled by dell.shop dell.computershop.com is a non sequitur from the rather wordy disquisition about why people fall for the scams in general.

It isn't. People fall because probabilities align. Something can catch their eye to knock them out of it.

A bad URL is a bad probability (for the scammer) in the chain, a really good URL is another good probability. If your assessment is that both URLs look equally good/bad to you, I, of course, won't deny that claim about your own experience. But to my eye, dell.computershop.com looks pretty bad and dell.shop looks pretty good.

I only answer my phone if I'm in the middle of getting a loan and so expecting a call from some unknown number at any time, and even then some numbers look too phishy to answer. The last time I got a loan I got a call from a local area code near the bank, answered, and found myself talking to a scammer about a loan. It was confusing, I believed it was the bank at first! Everything needed to align for them to get that far, including the phone number looking legit to my eyes. To someone else's eyes a number halfway across the country may have looked just as legit. Or the nearby number may have looked instantly bogus. This is exactly my point!

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#86
post #6

Earlier quoted context omitted.

Interesting! Now that you mention it, I did buy a .luxury domain for this purpose - a Gemini server. I also bought a .ski to have a domain with my (polish) last name.

It's great to be able to get silly domains for projects, back to the old days of IRC vanity hosts, but can you imagine seeing a link to something like jackets.luxury and going "yeah that seems legit, I'm definitely giving them my card details"

But then I remember it's just a pointer to 19.124.217.99 and I have no idea if it's legit or not, just like all the .coms.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#87
post #24

Earlier quoted context omitted.

They're different. Companies register all kinds of crazy domains and redirect you through them all the time. Why is it crazy that some marketing person at Dell thought it would be cool to link people to 'dell dot shop'? I would check the certificates, but honestly only as a precaution. If the website looks correct that isn't such an insane thing. That is exactly why it's so dangerous and effective versus your example…

> Companies register all kinds of crazy domains and redirect you through them all the time That's the real problem with domain trust these days. Companies go out of their way to make sure you know to only visit official links, and then do stupid stuff like buying vanity domains for one-time deals, or make you click through mailchimp tracking URLs because marketing tracking is more important than your customers fallin…

I wholeheartedly agree. Subdomains exist for a reason. Vanity domains are so incredibly sloppy and unserious.

Another issue is that they can make password management more of a chore. Every time I need to look up my Microsoft login, I have to remember to actually look up “live.com”. Except sometimes the login page is served from “microsoft.com”. Oops, you forgot your password and reset it; now your password for the other domain is out of date. Utterly ridiculous behavior from a company of their stature.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#88
post #81

Earlier quoted context omitted.

And there are also businesses with identical names. But the basic idea was already established long before the internet. If you have a legitimate claim to a name, you have a legitimate claim to that name. There may be multiple entities with a legitimate claim to a particular name, in which case the first one that used it in a particular context gets to use it in that context. And if you think that someone is using a…

The problem is that as you note, trademarks and company names are not unique, but domain names are required to be unique. So that n to 1 relationship between trademarks/names and domain names intrisically creates problem, how to allocate the domains when there are many equally legitimate pre-existing claimants. This is not solved problem the way you portray it, because domain names have this novel uniqueness requirem…

Many countries already solved this problem with their ccTLDs decades ago. It only required taking the established practices and applying them to a new class of names. There are always some edge cases, but domain name assignment is pretty much a solved problem.

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#89

Earlier quoted context omitted.

I never deal with co.xx to be honest. Most websites I visit are on ccTLDs. Whenever I see a .com link to any local business, I start out by assuming it's a scam website. That said, .app has found plenty of adoption. Tech companies absolutely love .io and .ai is now also gaining popularity. The good American URLs have all been bought years ago so people flock to ccTLDs and gTLDs for new products and businesses. Even .…

This is very regional. .co.xx is common in Britain (.co.uk), Japan (.co.jp), New Zealand (.co.nz) and probably others. It's perfectly legitimate for a site linked to those countries.

NZ didn't allow registration of raw .nz domains until 2014 so anything registered before that was a .co.nz or similar. It's still more common than .nz due to inertia / muscle memory I guess. I get weird looks when I give people my (name).nz email address - usually people ask if I meant .co.nZ

Re: Phishers Love New TLDs Like .shop, .top and .xyz

#90

The whole environment of the newer gTLDs just feels… gross. I rarely find a reputable business that is using anything but .com or .co.XX as the primary domain. Putting on my regular-person hat: When I see a billboard or print ad with e.g. `example.travel`, I read that as a social media handle and not a website address like `example.com` would convey. In public perception, dot com means websites. Always has. (Tangenti…

I’m disappointed at the arbitrary decision-making that lets the registrars deem certain domains to automatically be “premium” and mark them up appropriately. It feels like that’s an additional layer of extortion on top (doubly so when the premium price carries into the full renewal price, too).
Post reply on HN