Why Is .US Being Used to Phish So Many of Us?
krebsonsecurity.com
krebsonsecurity.com
Amoral monsters who will do anything for money can't be trusted to do anything other than make money. It's bad enough they're able to register domains with other TLDs, but we should probably not allow them to manage .US at all given their track record.
I've often wondered why the FBI don't have a website where I, a random citizen, can get hold of SSN's, credit cards, bank accounts etc. to give to any scammer who asks me.
The FBI would then trace all uses of those numbers and use them like a honeypot.
It might work on a small scale though. They could give a few of those numbers out to security researchers and internet abuse desks.
Usually you find the mailer script (for spamming), a web shell, and a few different phish kits all under some directory. Also usually the captured credentials, etc.
Sloppy work from the crooks, but it works.
What kind of audit? And was it conducted by DNB? If so, some audit it must have been.
I can't speak to the time before, but these days, DNB is a scam in and of itself. Just last year, the FTC finalized its order against them for deceptively selling a junk business credit monitoring service and failing to correct errors on business credit reports--even today, they'll tell you they don't know who provided the data that they themselves collected in the first place.
It was conducted by the company issuing the SSL certificate. Getting your initial cert could take anywhere from 24hours to a few days. Once you were set up renewals weren't a big deal.
Nowadays its all automated of course, anybody can get a cert easily and thats great!
No, .us is special; the OP sums it up well enough:
> Under NTIA regulations, the administrator of the .US registry must take certain steps to verify that their customers actually reside in the United States, or own organizations based in the U.S.
Such restrictions aren't unique to .us, and I've worked with other ccTLDs that have similar restrictions. Generally, AIUI, they're supposed to be for the people of that nation, who can then do as they see fit. Maybe that's free access to whoever pays for it, maybe that's "only our people", such as is closer to the case here.
> Content problems are the business of the FBI and other law enforcement agencies.
If GoDaddy actually did the job they were supposed to be doing here, it might actually be possible for that to happen, since there'd be a door on US soil to bust down, but if the bad actor is just in some far-away nation that was never supposed to have been permitted to register that domain in the first place, the bar goes up a bit.
Like how are you selling amaz0n.us and NOT figuring out that someone is up to shady shit? How are you approving thousands of emails with Amazon in the subject line and not realizing you are not Amazon's provider? How are you hosting pages clearly duplicated off legitimate websites that this one IS ABSOLUTELY NOT and just shrugging your shoulders?
I'm not even saying we need continuous monitoring on all these fronts but like, if you get an inordinate number of spam reports on a client, maybe take a freaking look? Maybe take a look at what your hosting servers are publicly serving? Maybe give the mildest of a shit about promoting a healthier Internet, considering you're selling the tools people use to build it?
1) The Freedom of Speech and of the press by extension at the time it was created was working under the assumptions of the printing press and carriage mail. I think it's long past time for a re-evaluation on this in the modern age, not only when bulk mailing can done at a scale that would make a press-printer's head spin today with modern machinery, but also and especially with regard to email, which is basically free minus the trivial cost of electricity to send a truly mind bending amount of spam messages.
2) I think it's beyond ridiculous that so many people will bring up that "well having any standard of information (to prevent misinformation) can be used by bad actors, so it's better to not have the mechanism at all to review the content of things." On subjective matters of opinion, it is certainly much, much harder to determine bad-faith or say with certainty that something is misinformation. But tons and I do mean actual tons of spam can be easily flagged as misinformation: be they advertising products that are flagrantly fraudulent in nature, be they advertising 419 scams that are... scams, be they fake amazon alerts about missed shipments, etc. etc. I would go so far as to say a majority in fact of spam email can be objectively determined to be misinformation of one kind or another, even if you totally discount political things from that system which I can see the logic of even if I don't necessarily agree with it. And if you agree with that assessment, then why in the world are we permitting this communication to occur? Why have we just thrown up our hands and said "nothing to do about it" as spammers have basically ruined an entire medium of communication?
We either need laws that penalize irresponsible internet companies or we need an origination like ICANN to enforce polices that cut off bad actors. If ARIN pulled the IP space from networks that didn't clean up their mess, or stopped letting lazy domain registrars sell domains things would improve pretty quickly. Instead we're making whois increasingly worthless and a growing number of sites and services don't even have a working abuse@ address to report problems to.
They sell millions of domains and there is no human being looking at any of them.
You also have no idea what someone is going to use a domain for when they register it. How is the registrar supposed to know if amaz0n.us is intended to be a scam or some US citizen's advocacy site to protect the Amazon Rainforest, which they had to settle for because amazon.us was registered by some unrelated conglomerate in 2002? If someone is sending a lot of emails with Amazon in the subject line, maybe they're just a normal seller on Amazon communicating with their customers? Or the same advocacy group mailing people about the rainforest.
The only way to even attempt it is algorithmically, but algorithms have so many false positives that anyone who attempts it will quickly lose their legitimate customers to the horror stories of some unaccountable algorithm shutting down their sole source of income or their incredibly sympathetic charity organization.
> I'm not even saying we need continuous monitoring on all these fronts but like, if you get an inordinate number of spam reports on a client, maybe take a freaking look?
The scam sites do get shut down. The scammers just make new ones.
What you need is for the police to put the scammers in prison where they can't make any more websites.
Godaddy probably can do more and be closer to other country level registrars that more closely require some type of id or business registration to complete the order but fraudsters will still try and some will succeed in getting phishing domains created.
>>NTIA currently contracts out the management of the .US domain to GoDaddy, by far the world’s largest domain registrar.
>> Under NTIA regulations, the administrator of the .US registry must take certain steps to verify that their customers actually reside in the United States, or own organizations based in the U.S. But Interisle found that whatever GoDaddy was doing to manage that vetting process wasn’t working.
On reading that, my first thought was "why would anyone who has a clue expect GoDaddy to do anything resembling the right thing, especially if doing the wrong thing and/or doing it wrong will net them more money?
Evidently (in this case, well-earned negative-) reputation counts for nothing.
GoDaddy could make even more money by cutting those people off. Then they can re-sell the domain again.
Like when a restaurant shortens the amount of time diners are allowed to linger so it can turn the tables more often.
I think the issue is that as soon as scammers realized they were throwing their money away they'd stop buying up .US domains and find some other means to trick people. Probably just using other TLDs and/or registrars which means GoDaddy loses their income stream either way.
When you strip away all the PR and bull sh*t, a company's only purpose is to make money for their owners. Most won't care how that happens.
If you register one - you need to provide complete contact information, and that will be publicly available via Whois.
I still get spam calls offering “Web Design” services for the .us domain I naively bought 8 year ago, even though it’s 7 years expired.
> The NTIA recently published a proposal that would allow GoDaddy to redact registrant data from WHOIS registration records. The current charter for .US specifies that all .US registration records be public.
Clearly if all this fraud exists with the requirement in place - it’s not an effective prevention measure.
The delegated manager system truly represented the distributed, decentralized nature of the old Internet. That said, it is not completely dead; there are still a handful of delegated managers out there, and you can even convince some of them to "register" a new domain for you in the locality namespace!
This makes .us a prime target for attackers because victims tend to trust .us more than .com. Nothing GoDaddy can do will change that.
NTIA could amend the contract to require or allow a different process that doesn't so readily enable phishing. So, bribe your local legislator if you'd like to see the process changed.
Show the numbers.
Most phishing comes from .com (expected due to its size). The report says about .us:
".US is the ccTLD of the United States and had a very large number of its domains used for phishing -- almost 30,000 domains, more than 20,000 of which were registered maliciously by phishers."
Also, it seems doubtful that krebsonsecurity would be appealing to some authority without a good cause.
Ever since the false accusations accident, I've stopped trusting Krebs when he's making statements like these.
.US has a high percentage of phishing domains, but in terms of raw numbers .com, .cn, and .pw are still much bigger than .us. I do wonder about these statistics, though; I don't know where domaintools.com gets their statistics from, but that's the only source for these "total domains registered" number. TLDs like .rest and .live also have much higher phishing percentages.
The assertion that .us is unusually phishy is backed by numbers that don't seem to have a clear, verifiable source. I don't know who Interisle are, but I don't think they run any TLDs, so I wonder where they got their data from. They say they've collected their data from through https://www.cybercrimeinfocenter.org/ but that's hardly an authoritative source of domain statistics.
I used to lookup to him as a huge name in the infosec field until I found out he can be kind of a dick. I still love reading his work, but the vibe changed.
I mean, I assume that most people registering a .US domain are not registering it at the top level. Do individual states have no control over how their second-level domains are administered and delegated? Furthermore, there are so many sub-sub-domains under all that. Any one of those could be vulnerable to someone entering unauthorized DNS information and getting a host within the domain without any need to register anything at all.
.us on the other hand is freely available for anyone to use (and in my experience is usually quite cheap)
Seems ripe for abuse if such registrations aren't being securely controlled
I was mostly trying to point out that registering under .us is pretty trivial. There is no need to try and sneak something into some states’s dns records, anyone can just go on any registrar and purchase something directly under .us
No, 99% of the people are registering at the top-level. It's not like .uk where there is second-level domains that each domain falls under.
Therefore, they are rather more vulnerable than a centralized registry that has the resources to scrutinize every application for veracity.
I would object much more strongly to registrars being heavy-handed about verification for .us domains than being overly-loose about it.
Phishing/spam problems aren't going to be solved by verifying .us domains.
Passkeys are probably the solution to most phishing attempts.
I love Kreb's work but this article title is complete garbage. It has nothing to do with the domain extension and more about godaddy turning a blind eye to their customers' nefarious doings. This can happen with _any_ domain.
... and ...
"Under NTIA regulations, the administrator of the .US registry must take certain steps to verify that their customers actually reside in the United States, or own organizations based in the U.S. But Interisle found that whatever GoDaddy was doing to manage that vetting process wasn’t working."
Not every resident is citizen.