Live data from Hacker News

Gone (Almost) Phishin'

ma.tt

81–90 of 93 posts

Re: Gone (Almost) Phishin'

#81
post #77

Earlier quoted context omitted.

Handy tip: all two-letter TLDs are country code TLDs. Doesn't matter if they're trendy in website names (.nu, .cc, .io, .co, .it, .at, .cx, youtu.be and so on) In fact, here we have the ma.tt website, where the ".tt" is Trinidad and Tobago. Is Matt Mullenweg from Trinidad? No!

It's kind of crazy that the IRS (among other United States government agencies) uses ID.me for account management. The .me domain belongs to Montenegro.

I think ID.me is a private company. So yeah, it’s especially fucking stupid that they use that in the first place. Any gov login should be required to go through a .gov tld. At least reverse proxy it or something!

Re: Gone (Almost) Phishin'

#82
post #31

> Apple Support lives on apple.com and getsupport.apple.com, nowhere else. Meanwhile: “Microsoft support uses the following domains to send emails: microsoft.com microsoftsupport.com mail.support.microsoft.com office365support.com techsupport.microsoft.com” [1] [1] https://learn.microsoft.com/en-us/troubleshoot/azure/general...

Also, Microsoft regularly sends me legitimate emails regarding "Microsoft Rewards" that are absolutely indistinguishable from phishing, like "Total Prize Drop is here! Your chance to win 1,000,000 USD cash grand prize or one of three customizable Mercedes-Benz cars!", complete with links to login pages and everything. So like this one, just as mail: https://xcancel.com/bing/status/2034720189003231410 The first time I…

I’m a lucky duck, because Microsoft ONLY sends me emails in Spanish. Password reset? Spanish. Ad? Spanish. ToS update? Spanish. When I log in, it’s English, and I’ve never been able to find any setting anywhere in my account saying to use English. It’s so funny, I can’t even understand their ads.

Re: Gone (Almost) Phishin'

#83

Earlier quoted context omitted.

the .su domain was made when the soviet union was still around, so that doesn't really break the rules. I would prefer for top level domains to be eternal for a great multitude of reasons

The possible annoyance with eternal country-code TLDs would be the dissolution of one country, and the creation (or renaming) of another country resulting in an eventual exhaustion of two-letter country codes. Eternity is a rather long duration.

Before exhaustion, you're likely to have new countries where they have to have suboptimal two letter codes, because a dissolved country is squating on it.

Re: Gone (Almost) Phishin'

#84

Earlier quoted context omitted.

Though not all country codes point to a country. See .eu, .ac .su as different examples of stuff that breaks the rules.

the .su domain was made when the soviet union was still around, so that doesn't really break the rules. I would prefer for top level domains to be eternal for a great multitude of reasons

> so that doesn't really break the rules

At the time it did not break the rules. It's breaking the rules now because by the original rules it should have been phased out. What makes it survive is a special arrangement.

Re: Gone (Almost) Phishin'

#85
post #83

Earlier quoted context omitted.

The possible annoyance with eternal country-code TLDs would be the dissolution of one country, and the creation (or renaming) of another country resulting in an eventual exhaustion of two-letter country codes. Eternity is a rather long duration.

Before exhaustion, you're likely to have new countries where they have to have suboptimal two letter codes, because a dissolved country is squating on it.

An interesting one is .uk, because the UK's country code is actually GB (the ccTLD is delegated, but unused).

And that's before we get into the really weird not-a-proper-country ones like .im or .pn.

Re: Gone (Almost) Phishin'

#86

I’ve found that just not answering any calls from unknown numbers (and having my phone just silence those calls so I don’t even see them) prevents all of this. If the caller is legitimate (e.g., new dentist office regarding an appointment) they can leave a voicemail. And if it isn’t spam and they aren’t willing to leave a voicemail and have me call the back, it probably wasn’t important in the first place. Sure, I ma…

Seconded. Even if one unknown number call isn't a scam, they will almost certainly pass on your number to ones that are. I made the mistake of answering one last week and since then I've been absolutely drowned in spam calls. Some of them even call a second time immediately after the first attempt, presumably to try to break through DND.

Re: Gone (Almost) Phishin'

#87
post #12

Earlier quoted context omitted.

Mike Tyson once said "Everyone has a plan until they get punched in the mouth". I think you are underestimating the underhanded tactics and emotional tools available to scammers to keep you on the line.

When I'm at home with the old man (mam is unfortunately in a care home), it _really_ irritates me how many scam calls he gets some days. Most of them are obvious: they just hang up when you pick up, the line is very bad or the caller is otherwise barely intelligible (i.e. they are speaking their 4th language), they refer to an account that doesn't exist or a fictitious government agency. But the occasional one is ver…

It may be worth looking into getting him a phone that only allows trusted numbers to call him.

But regarding scammers, asking "is your mother proud that she raised a thief?" really annoys them.

One of them threatened to come over and rape my sister.

I don't have a sister.

Re: Gone (Almost) Phishin'

#88
post #52
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

> senior citizens and tried to explain how to parse the domain Why would you want end users, senior citizens or not, to mentally parse URLs? The rule is: If the bank, or paypal, or your landlord, or anyone else really emails you that you have to complete some information to your account or pay the latest bill or whatever, you GO TO THEIR WEBSITE and login normally. If it is important they will have the same informati…

And yet, a multitude of banks, credit card companies, stores, etc. routinely send promotional emails where the only way to do what they want you to do is either click on the link (5 seconds) or try to log in through their home page and then find the same option among approximately 9000 menu items, banners and popups.

Are those things important? Well, never life-or-death important, for sure. Is getting 20% off your next order worth the risk of getting your account stolen? Probably not, but I suspect the majority of the population would still act as if it were.

Re: Gone (Almost) Phishin'

#89

Phishing has gotten really good , lately. As he noted, they will often re-use legit templates from the actual corporation. The email will be 99.9% legit, with maybe only one link being dodgy. I don’t think they can pass DMARC, though. My wife was almost scammed, a few years ago. What tipped her off, was how extremely good the “tech support” was. Real tech support is generally someone on a scratchy line, with a heavy…

It's sad how often the best way to recognize a scam is "the real company would never care that much about me or my account".

Re: Gone (Almost) Phishin'

#90

Earlier quoted context omitted.

the .su domain was made when the soviet union was still around, so that doesn't really break the rules. I would prefer for top level domains to be eternal for a great multitude of reasons

The possible annoyance with eternal country-code TLDs would be the dissolution of one country, and the creation (or renaming) of another country resulting in an eventual exhaustion of two-letter country codes. Eternity is a rather long duration.

if we run out of 2 letter TLDs, move to 3 letter ones. it really wouldn't be that hard. Also, that's assuming our current system stays in place
Post reply on HN