Scammers registering date-based domain names
shkspr.mobi
shkspr.mobi
No, that's the price we pay for using a name resolution system from the 80's (70's?) that was not built with trust validation in mind,decoupled from the infrastructure we use to establish domain ownership and authority. And also without user friendliness or of a layman's ability to independently validate authority in mind. e.g.: reverse order of hierarchy where in english you read left to right but dns has least authoritative/lowest level on the left and most authoritative on the right,why would I evaluate trust worthiness of site.com if 'secure' is evaluated first in secure.site.com (another example:google.com.site.info).
Cracked foundations make shaky buildings.
Since that looked like an SMS, I would report it to your mobile provider, let them track who sent the message.
The blame lies at the feet of the spammers.
And, I've worked for a couple of mobile providers. This spam was likely sent from a disposable pre-paid SIM. There's no realistic way to check who sent it.
Not that it would tell who sent it, but would allow to track if the same devices were used as part of ongoing campaign.
But SMS sending devices are cheap and disposable. Sure, it's illegal to alter your IMEI in the UK - but if they're already committing one crime, I don't think that'll stop them.
So, sending a couple of hundred messages is about the same price as a domain.
Of course, if you've stolen a SIM or hacked peoples' phone in order to send the messages, it's even cheaper.
Then there’s also a significant time investment in setting up accounts with those SMS services that’ll constantly be banning you.
Couple of hundred messages isn’t going to get you very many hits unless you’re collecting low value information.
Technically correct, but the thing is, spam like this is a consequence of a lot of things. Why draw attention to that specific cause out of everything else?
You could just as accurately say that spam like this is a consequence of human-readable domains. If humans weren't visually validating URLs, it would be impossible for a scammer to use unicode tricks to make a URL look legitimate.
A lack of gatekeepers means we'll have more scammers, yes. But, gatekeepers almost universally don't scale well in any system as large as the Internet, and they come with so many additional problems that they're not worth paying special attention to or prioritizing as a solution to any problem on this scale.
1) The angry/evil spammer. Doesn’t give a shit and wants make his dollars. Usually someone higher up. 2) The worker. Just his bills paid. Usually rather uncaring what they are doing, although they acknowledge its wrong 3) Playing oblivious, just ignoring and avoiding any sense of blame or justice
It’s lucrative and as long as we keep falling for it, it will stay. Making domains more expensive will make the barrier of entry higher, but the top players will likely just consolidate more resources vs little scammers.
If a domain is like an address then maybe we could or should enforce some more legitimacy, but such a thing would be hard to implement in the countries where spam usually originates from.
it kinda bugs me that letsencrypt which is a fantastic public service is being abused by scammers in this way.
Anonymity all the way down the stack...
Sadly there's no way to judge from just the URL if a site has an EV cert or just a cheap/free https cert, and by the time you opened it in the browser it might be too late.
I am not sure it really says anything about legit-ness either. It really only guarantees you and the next person you are talking to in the chain have an encrypted connection.
Hard to explain that to anyone really.
As for the domain name, that problem isn't going away. If anything, it will only get worse, as people are lazy and push UX designers to show less and less information. And the UX devs are right, the users won't know what to do with the extra info most of the time anyway.
And then there are payment processors, who also teach people BAD habits, by sending HTML messages, clickable links, etc. And that isn't going to change because it would increase customer support cases which costs them money. Banks won't implement secure authentication beyond phone MFA for the most part. I can think of a dozen ways to make this more secure, but all the ideas would be rejected as adding too much friction.
All that is left is educating the masses and that fails as well. Most people learn by making mistakes. About 40% of people will click on the scammers links. About 10% of people will enter their credentials.
That is not always true. You can have regulations which force banks to change. Banks don't like it but politicians don't like an unstable banking sector, especially if it causes sharp changes in the stock market.
As an example, the recent money laundering scandals in Sweden has caused some changes in credit card security. Politicians want to reassure the public and increase trust in Swedish banks, so the last years has seen several notable banking regulations. I would guess that they actually want noticeable friction in order to reassure the public that they have things under control.
If the incoming call or txt has an internal source number, but is coming from an external network, reject it. If its an outgoing session with an external source, drop it and follow up with the account holder.
A few weeks ago I had an argument with a few engineering students is one of the 30 top schools in the world, whether you can send an email form Gmail to Outlook or not!!
They thought it was like Messenger and WhatsApp not being able to talk to each other.
The concept of Open protocols and clients have to be taught in school.
Oh, how puzzled the looked when I showed them my Outlook email on my phone's Gmail app.
I was agitated.
If you want a phone line you have certain fees for 911 and other regulations to help pay for the infrastructure and this is very similar in terms of a naming and communication service.
Even if your solution would solve the problem, it would destroy the purpose of the system. Throwing the proverbial baby with the bath water.
If I want a phone line it costs me $10 to get a sim card from walmart. Most reputable TLDa cost a ton more.
I mean what is it with this lazy way of solving real problems. What's next, tax domain registrations? Require a government ID? How ridiculous, this is what happens when humans give up their basic freedoms to goverenments and ruling classes. By what authority are you even regulating my free speech here? If I put up a website, I am not engaging in commerce unless I sell or buy something using that site. It is the equivalent of me calling myself a name and making a speech in public and you want to charge me £1000 for the right to call myself a name or to label the soap box I stand on a name so others can distiguish me. The fact that scammers also stand in soap boxes and make false claims for profit does not magically give you, your ruling class or the goverenmen t authority to regulate soap box labels and tax speech.
Even if this has popular support, free speech is a natural right. You can police harmful/false speech retroactively but you can't inhibit speech proactively to deter a possible crime unless you can guarantee your measure affects only law breakers.
Having a website doesn't require a domain. DNS is a vanity layer on top to make it more user friendly and provide an abstraction layer. Domain registration costs money today. According to your argument that should be free or it is limiting your speech. I never said anything about speech or what you use the domains for. If it is yours, do whatever you want with it. Ethos bought .org for $1B. Why should a private equity company be able to own DNS suffixes? Are you okay with that?
The issue at hand is that these domains are being created specifically to deceive. This is an issue of consumer protection and greater good. The US just passed bigger fines for robo-callers. Everyone seems fine with not getting scam phone calls from their own phone number. Is this a restriction of free speech? Everyone isn't allowed to run their own tv or radio station, it is regulated. Is that limiting your free speech? You can't make up your own phone number. If you want a special 800 number that is more memorable, you have to pay the phone company lots of extra money for it. I'm merely suggesting similar.
Are you even listening to yourself? Your idea was to make domain names hard to obtain so scammers can't have them. The only way that idea will be effective is if people only go to sites that are part of the validated domain name system. This means that if you don't have a domain, nobody will go on your site (this is already true today). So why on earth are you saying those legitimate websites should look like scams?
This article somewhat supports my assertion:
https://krebsonsecurity.com/2018/06/bad-men-at-work-please-d...
saying "domains in the remaining five [out of ten] Top Bad TLDs can be had for between 48 cents and a dollar each." so I would suggest a one-off $100 fee rather than $500 or $1000 a year.
A more interesting approach would be to make the fee act as a bond, which is returned to the registrant after a year of good behaviour. Unfortunately, determining "good behaviour" is almost as hard as determining "bad behaviour", but perhaps a domain could opt in to having anonymous metrics recorded of how many users visit their site or send emails to that domain. That would put a substantial amount of trust into the hands of whichever organisations were responsible for recording these metrics, but the only harm they could do to a registrant is forcing them to pay their $100 bond to charity.
20-30 victims can easily earn the phisher $1000
Beyond that it comes down to who's being spammed, with the right demographics your link could last very long without being reported by anyone.
I hack phishing sites for fun, anything between 0-500 hits seems common for the type of phishing seen in the OP (mostly depending on the quality of the leads).
No company should send messages containing a url that requires login, payment data or the like. People should go to these places by typing the url or by using their own bookmarks.
Maybe they don't? This wouldn't help here, that's not the company sending the message. For that to work, people have to deeply know and trust the policies and resolve of each of their service providers not to do that - might as well just teach them how links work.
Right now that infrastructure is the only thing in the stack that actually does any validation (you get your cert because you have the name). There isn't any other validation infrastructure to couple it to for it to be "decoupled".
The Internet became the standard for global networking in the 1990s by being an informal trust based system where the competition was things like Al Gore's Information Superhighway - these other hypothetical systems were centralized extension of something like a cable TV network and essentially had all the bad things we decry in today's Internet and none of the good.
Which to say, the lack of centralization in DNS or whatever aspects on might name in the Internet (IP addresses, etc) allows bad actors from below to do their terrible things.
But the lack of centralization also prevents bad actors from above from doing their terrible things. Centralized DNS is already a target - cable companies were complaining to congress about firefox from enabling secure DNS and keeping them from MTM traffic.
Which is worse? I couldn't say.
`com.01-01-2020-billing.secure.hsbc` or whatever looks a hell of a lot more dodgy. But I presume it comes with a whole lot of issues of its own.
I recently got an email from them to check on a transaction that settled, the domain was:
https://click.SOMECOMPANYNAMEHEREinvestments.com/? ...
Their real domain is SOMECOMPANYNAMEHERE.COM but as you see they made a special domain just for email clicks. I thought at first this was a scam email, but then tried clicking and sorted out that it redirects to the real site and login.
But man you can't even easily trust real emails if you're paying attention, i dont know how regular people will defend against stuff like this.
I should have realized this earlier but: it's also important to have anything that displays clickable URLs (like a messaging app) to also style the URL to help it be more obvious what domain is being linked to.
The problem of better stylized URLs is so much bigger than browser URL bars that show where you are right now; it's also everywhere that displays clickable URLs.
It has a high concentration of technical users, only supports public posts (where technical users will notice and comment on such urls), and has very active moderation.
Texting apps seem like the most important place to implement it... judging by the spam that I get.
Websites don't display clickable URLs, they display clickable links.
Browsers used to show the URL in the status bar, but then started hiding that too.
Anyway, links don't matter much, because if clicking a link is dangerous, your browser is broken. The destination location is what matters.
That should not be, and should never have been considered the main line of defense against that.
This guy has it backwards. The problem is not that it's affordable or accessible. It's that there's no clear alternative to user vigilance to truly avoid these scams.
The domain referenced would have been: https://info.billing-update-jan02.uk.co.ee/ vs https://uk.co.ee/billing-update-jan-02
Sigh.
Given that finding the '/' is not always trivial (broken screen example in the article) and doing this requires you to think a lot of people won't do it.
https://ee.co.uk.billing-update-jan02.info
https://ee.co.uk/billing-update-jan02.info
There's just a single character difference. The layperson will think they mean the same thing. Now look at these 2: https://info.billing-update-jan02.uk.co.ee
https://uk.co.ee/billing-update-jan02.info
There's a big difference there. People can easily see something is abnormal. https://uk.co.ee/billing-update-jan02.info
https://uk.co.ee-billing-update-jan02/info
Would be more likely.Perhaps an animation showing both would help.
This is a classical arms-race and will only intensify. With domains that look generic enough and only serve malicious traffic when hit with the right URL, parameters, user-agent and geographical location, blocking will have to rely on sourcing these URLs directly from the targeted endpoints (e.g. SMS/WhatsApp/Email), rather than "crawling" or relying on users to report these. Another approach is to do some of the blocking locally, which of course means pushing the detection logic to the client and thus exposing the classification mechanism. Neither approach is sustainable long-term in my opinion.
This could be sold as an add-on for a certificate, or something like that, with a just high enough barrier for proving authenticity. Known-good domains could then additional treatment, like a blue padlock or one with a star (ok, I'm not an icon designer).
Of course you can argue against it on a freedom basis, but I think for protecting vulnerable web users it'd be pretty useful.
The problem is always the political one. What does, say, Microsoft vouching for a site actually mean?
There's other tricks that scammers pull though, like compromising legitimate domains with a certain reputation and then adding their scammy subdomains, but that's a lot harder to pull off than just registering 100 free domains everyday and hoping one sticks.
So if they have solved the problem why are we still complaining about it? All you need to do is show a big warning message for domains that are younger than 1-2 days.
If there were some way of bootstrapping new domains with some sort of positive trust signal (e.g. links from domains that have been in use for a long time?) then it might be possible to preemptively blacklist domains, as you say, but there are potential anti-trust issues with any such system that dissuades people from accessing the websites of new companies, for example.
> // Microsoft Corporation : http://microsoft.com > // Submitted by Justin Luk <juluk@microsoft.com> > azurecontainer.io > azurewebsites.net > azure-mobile.net > cloudapp.net
Cannot confirm. I registered my .de-Domain in 2005. That was 15 years ago. It wasn't that difficult, and quite cheap (imho 12€ for a year). So the tech barriers vanished a long time ago.
Spammers are in business. When certain costs fall, it makes their enterprise more profitable.
UK fullz can go for like 40usd a pop.
The date is sometimes used to confuse people when they're reading it so they think it's part of the URL and not the actual domain name.
It only temporarily solves the problem and ruins it for the rest of the customers. There are other ways to address scammers that do not involve making the entire market more expensive for expensive's sake.
Once security keys become ubiquitous, they should also provide some protection. But right now setting up 2FA for every site they use is impractical.
The system sounds pretty safe to me, even with its warts.
Users need to stop clicking on links they get out of the blue over E-mail, and legitimate companies need to stop sending links they expect customers to click, which encourages this risky behavior. Easy to say, but behavior is hard to change.
I agree with the first part, but how is the second part supposed to work? We're using links to easier guide people in the "right" direction (depending on who "you" are, changes what "right" means), what could an alternative be?
So, a X just finished, and the user can now use it. In my notification to the user, how to guide them to that specific X?
On the other hand, "Hi! We noticed there is a scary-sounding problem with your account, please click here to fix it!" No legitimate company should be sending users something like this out of the blue, and users should be trained to immediately think fraud/scam when they receive this.
The incentive from the senders side is to get the person receiving it to do something. If that's good or bad, it's harder to say than draw a line in the middle. Currently, bunch of companies and other entities are finding the whole clickbait super useful, and it's only natural that bad actors take advantage of this. But who is the bad actor? Turns out a lot of them, but on different levels.
Is this need real though? I can't think of a legit example where out of nowhere (i.e. not in the context of some transaction I'm currently doing with them), a company would suddenly need me to fix something, do something for them, or provide them information.
At a bare minimum, show me a warning when an SMS comes through containing a risky URL. I just don’t see why these giant companies with billions in profit can’t connect the dots here.
SMS has the problem that since you don’t have a spam folder filters have to be lenient because it’s more of a problem when they get a false positive.
I am not aware of any device side filtering, which IMHO is where it should live.
Although routing information isn't protected either way and is probably fundamentally unsafe.
Screens also get more shatter resistant all the time, but at the same time the industry seems to constantly find new phone geometries that look very prone to fall damage, so that probably balances out.
Unless you're after fashion accessories. Cracked screens are no go for fashion accessories. Can't let other people think you're too poor to buy an un-cracked phone.
Having a crack in the display is an enormous functional detriment on the device. Holding it as a fashion element is absolutely ludicrous.
(Only ended up replacing that phone because it started just not picking up calls and texts for days at a time)
Beyond dropping, as far as I can tell, there are two other common causes of screen breakage. One, sitting on it (a lot of people carry their phones in their back pockets, which is something I cannot understand; beyond accidents, this makes them vulnerable to pickpocketing). Two, women sometimes crush their phones in their purses (especially when they are in hard covers that act as levers when an item gets between it and the cover).
I've endured zero cracked screens. Ever. A couple of my kids are old enough to have had smartphones for a couple of years now (kids these days) -- they've had zero cracked screens as well.
This is one of those posts that tend to raise people's ire, but I'm just pointing out that a lot of us manage to never have cracked screens. It isn't just a normal that we all tolerate. And yes, I've always used a case -- I have a case in hand before I even take the phone out of the box. It seems insane to not have a case. Maybe when phones are unbreakable I can enjoy the sleek design, but until then it's a Spigen 100% of the time.
I don’t see many cracked screens in the US anymore, but I see them all the time in Vietnam.
I do agree that failure to use a case is insane for a device that's as expensive as a smartphone. But, I see lots of people will to risk a $100+ screen over buying/installing a $30 case. My son does this. He probably breaks one screen/year. Whatever, he's 25 and it's his money.
Not it’s not. billing-jan-2020.info looks suspicious as hell. Recognizing domain names from url is very 101 Internet security.
Here's some examples I've collected of people clicking on links in suspicious texts:
https://twitter.com/edent/status/1193147685370552322 https://twitter.com/edent/status/780317797855395841
I could see this weird domain name being slightly confusing and looking like a full URL in a browser that normally hides the path part.
It would be much easier if browsers just cut the crap and displayed the full URL (including the protocol) consistently. It's just one thing everyone can learn and then apply across all platforms & browsers.
There is nothing being exploited here like a display bug in the URL bar, TLS vulnerability, etc - it is completely obvious that you are not connecting to EE.co.uk and instead to some weird domain.
There's only so much we can do to fix stupid and natural selection (or in this case financial selection) can take care of the rest. Banks refunding every instance of fraud (even when the user is obviously at fault and failed for an obvious scam) don't help either as it means people still don't understand the importance of being vigilant and actually taking the time to learn some basics in order not to fall for these very obvious scams.
I would guess that if this scam was performed over snail mail it would have vastly higher success rates than SMS spam.
Granted, domains are "backwards", and browsers could be made to match known banking sites against every URL to warn of scams. But at the point where people are clicking scammy bit.ly links too, the domain part doesn't seem to be so key anymore.
In HTML (emails) you can make the url look like the real thing onscreen. Should GMail alert when anchor text is a different link than it actually links to? (Maybe it already does?)
The TLDR is that apparently they send all their marketing texts from "+90 (007) 000 38 64". You can opt out on their website and now I don't get these anymore. It's nice. But sad that my $120 a month isn't enough money for them, and they have to text me at 3AM to get me to buy a new phone. (And sell my browsing data.)
> Is there any way to stop this? No, not really. [...] There are no technical gatekeepers to keep us safe. We have to rely on our own wits
He is pointing out that this a danger to be aware of, and that the only thing we can do is be careful not to fall for it
Why not just https://ee.co.uk.billing.info/jan-02 ? I mean if someone does not notice it is a domain name and not path would they really notice where the info part is?
If you do your payments in a crowded train while standing and using an outdated, broken Android phone, you're a dumbass who deserves to get ripped off.
The price can remain the same but whenever someone wants to purchase a domain, they need to go through an additional audit of some sort. Add more entry to barrier. Legit folks will be a little inconvenienced but it will help weed out the scammers a bit more. Yes I know dedicated scammers will still bypass at times but it will surely deter them. Thoughts ?
It's not his wife, it's him who needs to be protected.