.new is altogether a weird TLD experiment. Over $400 per year, and you can basically only use it as a short URL to somewhere on your own site that creates something. (See the rules at https://www.registry.google/policies/registration/new/.) If you don’t think https://dashboard.stripe.com/invoices/create is nice enough (that being what https://invoice.new redirects to), why not instead do something like https://stripe.com/new/invoice? It’s cheaper, probably requires less maintenance, and is a URL that I can be confident about, because it’s on stripe.com rather than “invoice.new” which could be considered an untrustworthy domain.
When I say untrustworthy: how can you tell whether invoice.new is controlled by Stripe? The only two possibilities I can think of are whois records and name servers. Whois is unsurprisingly completely useless here (it’s all “REDACTED FOR PRIVACY”). Name servers are of the form ns-*.awsdns-*.* which I presume is AWS. I’m not familiar with what AWS DNS servers are, but it’s the same set of four as stripe.com, which is a good sign. So I’m going to assume that yes, this is run by Stripe. But a phishing attack is quite plausible: someone registers invoice.new, making it redirect to Stripe, socially engineers a lowly employee they have connections with into making mention of it in docs or product or something, increasing in scale over time until it’s common knowledge and thought to be official by employees and public alike (still trying to sneak under the radar a bit to avoid notice by someone who actually controls Stripe’s domains); and then finally, stop redirecting and start serving a counterfeit login page.
(On the HTTP point, there are typically 0–2 http: links on the HN front page out of 30, with old things overrepresented. Plus the Legal and Apply to YC links in the footer are http: but should be https:. On the topic of unwisely-http: links, it’s very common in marketing/transactional emails, which is sometimes concerning when you have sensitive information and potentially auth tokens in the URLs. I notice these things because I have Firefox’s HTTPS-only mode enabled and a user stylesheet via Stylus, `:link[href^="http:"]::after { content: " [http]"; color: red; text-decoration: none; }`, because I’m curious.)