Phishing domains tanked after Meta sued Freenom
krebsonsecurity.com
krebsonsecurity.com
I must say it played a pivotal role in my life, it allowed me to do my passion and have a domain name in my early teens when I couldn't pay for anything. Being able to toy with a domain name led me down many rabbit holes and led to me trying out self-hosting and system administration.
Sad we can't have free things.
https://tamouse.github.io/blog/politics/2019/10/02/why-is-th...
EDIT: it could also be argued that this controversy is beneficial for the Chagossians I guess. I didn't know anything about them until I purchased a .io domain a few years ago.
But if those TLDs don't even bring them any money and they're not named after something in the Chagossian's own language, do they even own them in any meaningful sense?
Aside from the right to return to their homelands, these people should be given some actual royalties from .io domain purchases. And then maybe also a new TLD that is more meaningfully connected to them and less likely to be hijacked.
You can fantasize about the hardships the citizens suffered for the appropriation of the .io TLD and draw any analogy you want, but there are probably more pressing needs of the people you're not addressing by spending time to supply this sort of sympathy.
Worse, imagine a world where you actually advocate for the displaced indigenous people to care about this problem. Probably you'd be asking them to divert attention from real problems such as being able to afford food tomorrow.
Firstly the US never bought into it so all the original successful internet companies are ".coms". For this reason if you are a global company, chances are you would prefer a ".com" to anything else. Most companies want to address a global audience and part of the point of e-commerce is to make this happen. So they don't necessarily want a parochial-seeming national tld but would prefer a global one. This makes country-specific tlds redundant for commerce.
Secondly the people running the national TLDs are (in my experience) often doing so to further their own egos and personal interests and so tend to offer a shitty service. This is why I gave up my ".co.uk" domain some years back. The UK NIC were just annoying in a bunch of different ways.
In Europe they are working very well and are used constantly.
.de is used by most Germans. .fr french, .at etc.
For example our community schools uses a .qa domain and the biggest telecom provider among various other sites.
What you're saying does not apply to all countries.
"Never bought into is" as never bothered and never cared about other countries (main character syndrome)
german people, for example, will trust a business running on a .de domain much more than a .com one.
in most cases it is much preferred for an international company to run the country-specific website on the according ccTLD. companies that "want to address a global audience" are a specific set of companies that might prefer a "global" website, but most businesses will run country specific sites, not "global" sites.
also not sure what the UK NIC being "annoying in a bunch of different ways" has to do with anything, or even means.
seems to me like you are living in your own world, far detached from reality.
The way in which the UK nic used to be annoying that is relevant for this is that they used to make it much harder to register, transfer and renew domains. So at some point even though I had a .co.uk and a .com I just stopped trying to transfer the .co.uk and let it lapse at the next renewal date.
UK transfers are surely more complicated than they have to be (push vs. pull logic).
and I can also see where you're coming from, since in the UK it doesn't seem to be such a big thing.
but in most other non-english speaking countries (or even .com.au or co.nz), ccTLDs are actually a big trust factor. also for example high-end keyworddomains sell for a multiple of the respective .com domain price. sometimes as much as 5-10 times.
.de has more weight than .net or .com for most people in Germany.
.fr and .be are as easy to manage as any other TLD, and they have the advantage that you're probably not going to be price gouged as they are not run for profit.
I’d love to know how/why they’ve managed to keep all of those alive so long. I am very appreciative but equally surprised.
If the way to have there things is defrauding others, then they are not as free as they seem.
I'd say that a third-level domain is fine for teenage projects; was fine for me even past teens.
That wasn’t a concern in 2002 but today it should be.
yep, being a kid iterested in tech and having parents, that are not, is probably a huge pain... internet at home and a computer.. sure... giving your credit card info to your kid for some name on the internet? No way s/he's getting that.
Having a free option (and dynamic dns, and possibly even a free virtual machine somewhere) makes a lot of learning and experimenting possible for kids.
I’d guess that in many cases, being interested in tech might make people _less_ likely to do this.
They are knowingly allowing card fraud and other cybercrime groups to operate openly on there. We’re not talking about criminals that use the platform while trying to appear sneaky and flying under the radar - we’re talking about groups outright advertising their wares in the group name: https://krebsonsecurity.com/2018/04/deleted-facebook-cybercr...
> Some had existed on Facebook for up to nine years; approximately ten percent of them had plied their trade on the social network for more than four years.
> KrebsOnSecurity’s research was far from exhaustive: For the most part, I only looked at groups that promoted fraudulent activities in the English language. Also, I ignored groups that had fewer than 25 members. As such, there may well be hundreds or thousands of other groups who openly promote fraud as their purpose of membership but which achieve greater stealth by masking their intent with variations on or mispellings of different cyber fraud slang terms.
I have my own personal experience with this. I came across a page promoting Snapchat (and maybe other services) hacking services that in exchange for a fee claimed it would email you the credentials of the target account, with plenty of obviously compromised accounts posting comments claiming it works. Obviously very illegal in the vast majority of jurisdictions, but the double whammy there is that the service was itself a scam.
Reporting the aforementioned group and a few of the fake comments yielded that none of this activity goes against their community standards.
> They are knowingly allowing card fraud and other cybercrime groups to operate openly on there.
i wonder if you believe yourself when you write stuff like that? as if that company has a policy to allow fraud and cybercrime and they really believe its good for their business.
if you do... well... watch out from those black helicopters
The most annoying part is there has been zero communication from Freenom - not a single email. They also never replied when I asked what was going on.
If anyone at all has a way to combat this stuff that doesn't rely on "bad actors need disposable identities to get around blocks and don't usually have money" will basically win the internet.
> Unfortunately, the lawsuits have had little effect on the overall number of phishing attacks and phishing-related domains, which have steadily increased in volume over the years.
> Piscitello said despite the steep drop in phishing domains coming out of Freenom, the alternatives available to phishers are many.
The best list I'm seeing is: https://free-for.life/#/?id=domains
https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...
Spending couple of minutes on the site, it became obvious that it is a scam website. Confirmed further by another search on domain[2]. I wanted to report it but there is no easy way to report this. So I gave up and hope no one falls for it.
[1]: https:// littletikes . savemoney . store [2]: https://forums.dansdeals.com/index.php?topic=119138.0
Or alternatively report an abusive google ad here https://support.google.com/ads/troubleshooter/4578507
I'm not going to report hundreds of domains every month. Google needs to get their crap together.
The same is very much true for other parts of Google as well. Youtube comments are hilariously full of spam. There's a pretty good tool out there to get rid of the spam, which just runs the comments through a basic spam filter, but for big channels you can't let the tool run for too long because of API call limits.
It should be easier to report scams or phishing sites from search page, imo.