| ▲ | walrus01 4 hours ago |
| I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose... List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt |
|
| ▲ | ddtaylor 3 hours ago | parent | next [-] |
| I'm not convinced that would help. The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain. Its just attempting to work around incompetence, which always just shows up again somewhere else. |
| |
| ▲ | walrus01 2 hours ago | parent | next [-] | | > The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain. I think this might have some parallels with the 'shadow IT' problem in large corporations and organizations. Some work group or department or project within a very large entity decides it needs to implement something (like shipment tax payment notifications, as in the linked example) and decides to DIY it rather than going through the full process to do it with their own domain. Reminds me a bit of large businesses where some sales or CRM-related department goes out and starts buying email-blasting/email-list features from some mailchimp-type company and only later on realizes they need to talk to whoever controls the domain to get approval for proper outbound DKIM in the DNS records, etc. | | |
| ▲ | SoftTalker 2 hours ago | parent [-] | | Or more likely IMO, FedEx HQ said "you can't use our domain to collect foreign tax payments" and so it got outsourced to a service in Australia. And a lot of these "collect payments as a service" sites just look and feel like something that was developed in 1995 and never updated. I run into them everywhere, from local governments to medical and legal offices, small utility companies, etc. I have no idea how they pass PCI audits. |
| |
| ▲ | reaperducer 2 hours ago | parent | prev [-] | | The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain. Just today I saw an e-mail from "onmicrosoft.com" that was completely legit. I wonder how many domains MS is running these days. It seems like each department and project gets its own. | | |
| ▲ | walrus01 2 hours ago | parent | next [-] | | At least they're not sending from contoso.com ? | |
| ▲ | Yokolos 2 hours ago | parent | prev [-] | | Every time I see a new Microsoft domain I've never seen before, I have to double check that it's actually legit. Every time I realize anew why people still fall for phishing attempts, because all these legit domains look like phishing attempts. |
|
|
|
| ▲ | userbinator 28 minutes ago | parent | prev | next [-] |
| I definitely don't trust those when they show up in search results, and even when they sometimes appear here in articles voted to the front page, I tend to ignore them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose Many-legit-sounding-hyphenated-words-domain is actually another red flag for me, as that was indeed what they did before the proliferation of TLDs. |
|
| ▲ | pibaker an hour ago | parent | prev | next [-] |
| Not helped by legitimate websites often redirecting you through weird multi tiered domains especially during log in, or legitimate businesses using link shorteners instead of their full domains, or more and more businesses themselves hopping on new TLDs, like the recent cloudflare wallet release. |
|
| ▲ | cosmic_cheese 3 hours ago | parent | prev | next [-] |
| The menagerie of TLDs is somewhat a necessary evil in my view. Prior to them it was becoming nearly impossible to get a decent domain, with most of them already having been laid claim to by squatters, big companies, and startups with VC money to burn. |
| |
| ▲ | nubinetwork 2 hours ago | parent [-] | | It didn't change anything though, if you have the money you can just buy more. | | |
| ▲ | tialaramex 2 hours ago | parent [-] | | Also this was never a real problem. "All the good names are taken" is true if you insist that every name which isn't taken is a bad name but otherwise obviously false. The same exact "Somebody already had the good ideas, it's not my fault I'm just too late" whining can be seen centuries ago. People who live in a world with no electricity, absolutely convinced that every product which will ever be wanted already exists. Morons. Way back in time I wrote an HN post where I just spotaneously came up with plausible 2LD names off the dome and every single one was available. I won't bother repeating the exercise because it was evident that everybody who could understand this was unsurprised while the people who'd previously believed all the good names were gone just dismissed these as bad names because after all, if they were good names they'd be taken already, duh. | | |
| ▲ | linkregister 2 hours ago | parent [-] | | There are plenty of Chinese domains that are just numbers. If they can build entire businesses off of that, so can anybody. There's of course a ton of risk around scammers winning SEO and adwords competitions. | | |
|
|
|
|
| ▲ | dqv 3 hours ago | parent | prev | next [-] |
| For the past 2 years I've gotten backscatter from a phishing campaign that uses a domain I own in the from address. Every single domain they try to get the victims to click on is a .com The most recent one is detention-unit.com, which probably does trick a lot of the people getting these phishing emails since the targets don't seem to speak English as a first language. As an aside, an alarming number of server admins don't check SPF so these emails are actually getting into people's inboxes. |
|
| ▲ | inigyou 3 hours ago | parent | prev [-] |
| This was a calculated project by ICANN to 1. bring lots more money to ICANN and 2. prevent decentralisation of the DNS root away from the control of the USA. |