New ZIP domains spark debate among cybersecurity experts
bleepingcomputer.com
bleepingcomputer.com
> "The risk of confusion between domain names and file names is not a new one. For example, 3M’s Command products use the domain name command.com, which is also an important program on MS DOS and early versions of Windows. Applications have mitigations for this (such as Google Safe Browsing), and these mitigations will hold true for TLD’s such as .zip.
> At the same time, new namespaces provide expanded opportunities for naming such as community.zip and url.zip. Google takes phishing and malware seriously and Google Registry has existing mechanisms to suspend or remove malicious domains across all of our TLDs, including .zip. We will continue to monitor the usage of .zip and other TLDs and if new threats emerge we will take appropriate action to protect users." - Google.
Good thing google never gets any of this stuff wrong, and has a great appeal process for people flagged in error /s
What's really stupid about this is a huge number email systems just outright block things like .com and .exe attachments of any kind to avoid direct executable content. Zip content is generally allowed, but typically scanned.
Well, not to maximize user confusion we're adding a new context to one of the most common file extensions in email and downloads there is. Yay Google, thank you very much.
And then there's the fact that the younger generation has such little experience with filesystems and files due also to default hidden file extensions in Windows etc, they wouldn't even know what zip was ....
Ends up just down to the browser/OS to block malicious downloads etc if the domains are clicked.
I think this is the primary reason why this is getting so much negativity: it’s something a bunch of people in the internet community will need to spend time thinking about but is mostly an exercise in collecting rent from a handful of companies like 7-Zip and WinZip.
They're actually PE executables or whatever, so they're .com in name only.
There's probably little potential for confusion with the domain, though, considering that people without significant experience probably never encounter those com executables in the first place and wouldn't even know they exist.
Even people who do know enough have to ask if they're even named that way anymore.
Edit: Also 16-bit processors weren't the point where com executables became replaced. PCs have been at least 16-bit since the beginning (8086) and actual com executables were still a thing.
This makes sense given the old .com format was really just a binary blob that would be loaded into a single 64k memory segment. Keeping backwards compatibility for running them on modern 64bit processors would be difficult. At the same time Microsoft wouldn't want to break people's batch files if it can be avoided. By replacing the .com file's contents with logically equivalent code in a more modern executable format they can keep those batch files running without having to actually support legacy .com executable format.
(note, that's all guesswork, Microsoft could have had a different reasons for doing it :) )
Way back in the IE3/4/5 days visiting a .com website would commonly leave files with a .com extension in your temporary internet files with random non executable content inside the files, which made anti-virus really happy. Microsoft went about hiding the temporary internet files in more convoluted fashion over time also so the end user would not stumble upon it.
Now with the .zip domain, we're getting back into new and fun issues with file:// vs https:// context.
https://news.ycombinator.com/item?id=35927509 ("The new .zip TLD is going to cause some problems", 80 comments)
https://news.ycombinator.com/item?id=35917362 (".zip is now available as a TLD", >90 comments)
https://news.ycombinator.com/item?id=35920336 ("The .zip TLD sucks", >300 comments)