The short tale of an online scam
duarteocarmo.com
duarteocarmo.com
This is good advice, as things stand right now, it is in fact the best advice we can give.
In absolute terms it is borderline useless advice. Many companies still communicate from and operate from domains other than their well-known main domain.
How is anybody supposed to know that windowsupdate.com is a legit Microsoft domain? What about windowsazure.com? How do you know that fbcdn.net belongs to Facebook, but fbabc.com does not. Why isn't gdynamic.com a Google asset like gstatic.com. lufthansa.com, lufthansa.de, lufthansa.at, lufthansa.ch are all legit, why are lufthansa.li and lufthansa.lu not?
Sure, you can check WHOIS, but that just shifts the issue one level lower.
"[..] always look at the url bar." - Please do, but don't expect it to be enough to be 100% safe. In the world we live in anyone can be phished.
Suggesting Google might do anything without ad-related motives is probably too generous, but I've always thought that this was an optimisation in the sense that it's built on optimism: when everything's working well, most of what's in the URL bar is irrelevant. So the bar is built towards working well in the best case, at the expense of becoming much less useful in the worse (and probably more common) case.
Hiding/obscuring details from the URL bar seems like much less of a big deal if the goal is to rehost someone else's content. The value statement of the URL goes down a lot in that case, and the push to drive users away from it starts to make sense.
Either which way, I still hate it - The only non-work related ticket I've put in for chromium was a request for an option to disable this behavior entirely.
It's bad form from folks who should know better.
Safari on both mobile and desktop started doing this years before AMP was a thing.
I buy it honestly.
>I buy it honestly.
phishing should look nice to the victim?
I don't know if there's any research on users to confirm that this works. It would be good to do such research before making such a change, if that's the motivation for the change. But it seems plausible to me.
What become irrelevant is the AddressBar itself for the user.
User simply doesn't look at it at all because usually it is not changing with each click. So it appears irrelevant and disconnected from the actions user takes.
It looks for non-technical person as "some name of the web site which doesn't always shows the right name, but it's ok because hey nothing works perfectly on computer anyway ... so it doesn't matter". This is how it looks to the average person. They do not even understand why it's there. "Just takes the space ... Why it's there? Site shows name anyway on the page ... " They just have no idea what is going on thanks to this wonderful idea of removing the real address bar ... Not that they were too much aware before but at least you could explain them ... not anymore.
According to my experience non-technical people just lost the concept of url completely and do not even know where it is. Even when one asks them about it specifically. These are the 'real' results of this idiotic idea which I observe in practice and I unfortunately I observe it too frequently to ignore it. But hey .. downvoters of my previous sarcastic post seems to be very happy to ignore the reality. They would rather stick to their wise decision and downvote reality if they do not like it. Good luck with that.
There are various mindsets that lead to want to do that - one designer I know calls it a debugging tool that should never have been released in the first place.
For others, it is clearly about controlling the user with various justifications.
(I consider it a canary. Its removal will be a signal that the HugeCos are comfortable relegating the non-corporate web to the fringe, Usenet-style. It will be there, and you can get to it if you go way out of your way, but what it there will mostly be automated spam and weirdness, tons of examples of specific use cases, and a few folks who have been arguing with each other since 1992.)
I've heard similar comments but I don't understand how people would be expected to navigate around the internet? Is the idea that Google's search input should replace it? So if I want to go to sec.gov I should search SEC and click the link (hopefully) provided at the top of the results rather than just go there directly? It just doesn't make sense to me.
It is often possible (if hard) to configure browsers to do traditional URL resolving, but I wouldn’t bet on it always being possible. Google certainly has every reason to disallow reconfiguring their own browser to not send data to Google.
Safari has been doing this for a while now, yet no one is up in arms about it.
The password manager didn't suggest my password, I attributed it to recently changed website domain or site quirk and quickly copied my password from the manager to the site only to get SSL certificate revoked notification.
I have logged into a phishing site mimicking the old url of Indian Govt.'s tax website. I quickly tweeted out to some journalists[1], The website went down soon enough.
I've never been phished before AFAIK(This wasn't targeted, I've protected myself from couple of targeted attacks & helped several others in the past) and even though this is embarrassing I want to state couple of reasons why my usual rationale didn't work this time.
1. The new tax website being quirky(to say the least) was on news constantly and my CA kept complaining about it for past several days. I expected a quirky website even before I logged in. Even our Finance Minister had complained publicly to the Chairman of Infosys(Who developed it) on Twitter about the issues with the site days earlier.
2. I made couple of prior searches in Google as I didn't get the website where there was login, So I think Google produced less trustworthy results on my final attempt. I've noticed this happen in the past as well in the Google i.e. When you enter the same search term couple of times, 3rd or 4th results are not same as 1st in the front page.
3. The muscle memory to check https and URL didn't help much as the site had SSL and the URL was close enough to old IT website's unmemorable subdomain URL. The 'filing' was 'filling', Domain was co.in instead of gov.in. (Which of course I didn't notice).
4. Password manager not working should've caused me to check the domain again, But (1).
I presume this was intended sequence of the events for the scammer, Especially since many are searching for old Income Tax website. But I never expected the phishing site to make it to Google front page this soon.
[1] https://twitter.com/heavyinfo/status/1409761416865746956
And now I should tell my 70+ year old mom to "always look at the url bar"? That's entirely useless.
For myself, I tend to avoid pissing off scammers. I just let the relationship wither on the vine.
I had a friend that attacked a forum hacker, and the hacker responded by completely destroying a years-old online community. They probably used a bot to register a scammer login, but the attack got their attention.
My friend would have been far better served by deleting the login, and fixing the holes in his forum.
I was barely awake, so I stammered, "huh? No I don't think so..."
Paul (Helpfully): "You filled a form out requesting this on our site?"
"No...?".
Then I started to wake up more and realize it was happening again. I must've pissed someone off somewhere a couple years ago, because I'm getting a lot of this. A hater is filling out online forms with my info. Every month I get a random call from a legitimate company responding to what I only assume is an item in their lead-gen pipeline. This morning was no different. The call came from a legit number for the HVAC company. I looked them up and they're highly-rated. But they're in Florida, I'm in California, so the 5:30am call time made sense.
Last month it was a therapist referral service in Ohio. They had my name, phone number, and email.
Elsewhere I'm constantly getting emails at an old gmail address for various shopping site "newsletters." From all over the world. A Spanish job search site in the UK. A sporting goods site in Colombia. Athletic wear from Ireland. In each case, the sites themselves are legit, but they don't do an email confirmation loop.
Should I keep Unsubscribing from these? Is there anything I can do to figure out who is doing this? I used to mess with scammers; I think I might regret that :)
My wife had a similar problem and she changed her phone number.
Unsurprisingly, the IP addresses all resolve to Russia
Of course, the link wants to authorize against my (nonexistent) gmail. Nice try.
The people I feel bad for are the elderly: I know two that have been taken in by these things. They really aren't mentally equipped for the complexities of the modern Internet.
My good bank actually has security. I'm fairly confident that I couldn't sleepwalk into giving bad guys access to the funds in that account by whatever means. I have a physical authenticator device to get into their online banking site, for example, so your scam would need to persuade me that I need to go get the authenticator and use that to sign in, all more chances for me to realise it's a scam.
But I have two other bank accounts, which both still think passwords are a pretty good level of security in 2021. One of them even lets me sign in using a numeric PIN, presumably they feel they've done enough to protect against brute force and so this is fine.
Would you be willing to make a recommendation?
However I live in the United Kingdom, so this recommendation won't be much use to people who live elsewhere. My recommendation certainly does not stretch to their parent, HSBC, once the Hongkong and Shanghai Banking Corporation which likely does operate other banks where you live.
Here's an innovative one. I got an sms impersonating my cell phone provider telling me they're going to change my plan.
They'd decided which one is the best for me but I have until next month to chose one 'of the new plans' clicking on a bit.ly link. That links points to an Amazon affiliated link, and it's totally unrelated to my provider.
I remember reading about a scam where the URL seemed legit, and the suspicious part was pushed after so much white space that it was no longer visible in the URL bar. I don't remember the details and I'd be curious to know if anyone remembers it. I remember even sophisticated users saying they might have fallen for it.
Again, maybe that's specific to woodworking tools and supplies, because those people tend to skew older, but I have legit asked 4 or 5 buyers, this year alone, if they were bots because that is literally their first line.
Might've been better to send in two or three a day, and ramp it up slowly until you get caught.
I've done this with college scammers requesting email + passwords, loads of fun. Would highly recommend as it turns an O(1) operation (db full of valid stolen credentials) back into O(n) (randomly guess which credentials you stole are valid).
More work, but with potential to waste more of the scammer’s time, would be to fake up requests corrupted in a way that suggests your browser config exposes some subtle bug, say a race condition, in his scripts. Might keep him busy for days …
delightfully devilish!
That being said, I fell for another shipping scam in DK, seems it's quite common these days. Bank cancelled the card and transactions easily, though.
The attacker can be a man-in-the-middle and make the victim authorize a costly transaction (say $100), with the victim seeing a cost of $1.
These is an example video here: https://blog.cmpxchg8b.com/2020/07/you-dont-need-sms-2fa.htm...
Of course, the real transaction can be seen from the bank.
But since the article mentions confirming the bank balance, couldn't that be basically sending a pay request for the entire bank account balance?
They seem to be the preferred DNS provider for this sort of thing.
Certain TLDs (like those under .uk, .cn, .jp, or .sg for example) requires more documents in theory - and at least with other domain name providers like Gandi, they asked for my ID and a letter from my company stating that I indeed was authorised to be a representative for that company, plus proof that the company exists (it's easy in the UK because it's already in a public database anyway, so we just send our company number and proof that we're that company), to verify that it is indeed me, authorised by my company, when registering at .uk (and similar arrangements for ccTLDs with similar requirements).
Namecheap on the other hand... well, they just trust you, period.
They allow anonymous payments and they're slow to respond to takedown requests.
They've started monitoring registrations now - so you can't register domains like `hsbc-co-uk.biz` without going through some extra checks.
things that might also be liked by non-scammers.
I'm working helping out an artistic collective in which the various members are anonymous to various degrees. There may need to be anonymity in paying for services - this is an obvious necessity nowadays - for example the whole recent situation over the 'I sexually identify as an attack Helicopter' story https://en.wikipedia.org/wiki/I_Sexually_Identify_as_an_Atta...
so - off the top of my head:
often abused or oppressed minorities.
artists.
on edit: obv. slow to takedown is important for artists or controversial people as well.
So I don't think any of your examples hold up.
it's hard for me to take that statement as having been made in good faith but at any rate when I say historically I do not mean if someone was building a website in 1950 they sure would want to be anonymous I mean that throughout history, up until the present day there are people who want to remain anonymous who are not scammers and used gay people as an example - which gay people sometimes want to remain anonymously gay but express themselves even today!
And then I linked the description of a story published last year in which the anonymous author was harassed over sexual issues.
Given the example I linked to then
>Artists who remain anonymous typically solve the problem through having a trusted representative. E.g., someone like yourself.
It might be that representatives of controversial artists or the technical help for such might like some level of anonymity themselves, given that anonymous writers can receive death threats it seems that public representatives of such can receive them as well.
Fall was already anonymous, and her anonymity was protected by the editor, just as I described. So anonymous payment for a web presence, one that she didn't have, wouldn't have helped here. And as you point out, the anonymity didn't prevent her from getting criticism (not harassment as far as I know); indeed, one of the lessons of the Fall incident seems to be that poorly managed anonymity breeds unnecessary suspicion.
As to your last "might be", anything might be. What I'm looking for is an example of where the social harm that can come through anonymity, specifically anonymous payment, is worth putting up with to provide some social good. So far I'm still looking.
As it is, I'll note that even your well-performed outrage over fears of harassment doesn't is out of place here, as harassers often make vigorous use of anonymity. E.g., look at Near, the latest addition to the KiwiFarms kill count.
well, I used the phrase historically speaking which normally when I see it used in the manner in which I used it the meaning is "this has happened in the past therefore we should be wary of it happening in the future" but you seemed to take it to mean "this has happened in the past but the past is a foreign country and thus we don't need to worry about it happening again." So yes, if you assume that similar things to things that have happened in the past cannot happen today then my example wouldn't be one. But otherwise you didn't really point out my first example wasn't one.
>So anonymous payment for a web presence, one that she didn't have, wouldn't have helped here.
I guess we must think in very different ways because I was just making an example of how artists might want to be anonymous because otherwise they can have bad effects from releasing their art. I chose the most recent example I could think of, and also I chose this one because the attacks were generally from the left while I tend to think of retaliation for homosexuality as stemming from the right.
>As to your last "might be", anything might be.
ok so we're in agreement then that there might be people who are not scammers who want to be anonymous. And since you bring it up also not harassers.
>What I'm looking for is an example of where the social harm that can come through anonymity, specifically anonymous payment, is worth putting up with to provide some social good.
Ok well I don't know if I can provide that, as I don't know how to calculate the social harm and how to calculate the social good. I just know some people who would like to be anonymous for non-scamming purposes.
>I'll note that even your well-performed outrage
whatever.
on edit: obviously I believe in order to have an anonymous identity one has to be able to pay anonymously, so despite my not writing anonymous payment each time I wrote anonymous I assume the ability to pay anonymously is wrapped up in the ability to be anonymous on the internet.
Sorry, but this phrase illustrates your lack of good faith in this discussion.
Is online harassment a big problem? Yes, and it's one I spend my days working to solve. Is the inability to anonymously pay for a domain name a significant part of that problem? No, it isn't.
Is it really so hard to believe that there are legitimate reasons for wanting to anonymously acquire a domain name? One of the selling points of crypto currencies is the ability to do anonymous payments. That's multi-billion dollars big (even if one considers most of that somewhere between "scam" and "bubble"). All sorts of people desire anonymity in what they do, not just criminals. The GP may not have made the case very well, but minorities are certainly weary of being tracked, so are one example of a group that may desire an extra layer of protection.
It's not hard to imagine other groups. Dissidents, folks who want to keep focus on message instead of messenger, whistleblowers, .. It may be hard to see this from a privileged point of view (mine certainly is), but that doesn't mean it's not real or that only criminals want anonymity.
Nice, but it's effectiveness depends on the completeness of the list.
It may be registered with fraudulent intent, but the business transaction used to register it is likely perfectly legitimate.
If I wanted to sell some furniture and somebody wanted to use a mover service, that somebody would be paying for it, right?
Why did OP ever proceed with a form that wanted HIS payment details?
Produce a mobile app which uses the camera to scan QR codes, or even watermarked/"invisible" elements placed in reasonable locations on the user interface.
Release an API/SDK which allows for any network participant to quickly wire up a security verification front on their webapp (this would be a bit of js).
App and API obviously both talk to your back-end, wherein the network participants have submitted substantial business/entity verification documentation prior to being added to the network. The service is pretty damn simple - just cryptographic signatures that rotate every few seconds or something. Keep track of last ~100 to account for clock drift. No need to make it hard.
Provide application as free service to users. Monetization possible via a few routes. Ads on the user app itself, B2B contracts with network participants, etc.
Use case A: Get to final payment screen on https://www.bhphotovideo.com. User wants to be 200% sure they are not about to bank wire five figures to Putin due to some UTF8 technicalities. User takes their iPhone out, taps "my magic verification app", points at payment screen, app dings with big green check mark, post verification ad experience, et. al.