Things like this should use one of the few TLDs that actually has policies and procedures in place; then it's a simple "if it's not .gov, it's not real."
Things like this should use one of the few TLDs that actually has policies and procedures in place; then it's a simple "if it's not .gov, it's not real."
They need to parse slashes, dots, colons and ats (remember URLs can contain credentials, even though I believe browser issue warnings these days), identifiy the TLD and the domain and then know what is legit and what isn't. And know that things like onmicrosoft.com is legit while atmicrosoft.com is probably not. Or whatever link shortener some legit organizations are using.
But we should be taking the obvious steps like enforcing government domains on .gov . Attacks and scams are getting more sophisticated, so I hope when I'm elderly I can atleast check the .gov portion and know it's an actual government website.
If I search for whatsapp, in the sponsored section there are 10+ apps with white speech-bubble style icons on green backgrounds that aren't WhatsApp
You could do a similar thing with banks. Require them to use a .bank TLD (or .bank.us, .bank.uk, etc.), only let actual, regulated banks register them, and give them special decorations. Use eminent domain if those domains are already taken.
Unlike EV cert validation, it would actually mean something if you restricted decorations to specific known regulated groups.
I had never considered that if there were multiple 9-digit expansions of a 5-digit zip code, the correction might turn out wrong unless the full 9-digit code is specified.
It is not required and will likely never be required to provide a 9 digit ZIP for reliable delivery. It may, and does sometimes, impact speed of delivery due to sorting/distribution rounds.
That depends on who you are.
If you are a regular person, then yes, 5 digits is sufficient. But if you are a sender of presorted commercial bulk mail (which is discounted from first class), you may actually be required to provide a 5 + 4 + 2 = 11 digit ZIP.
That little barcode the post office prints on your letters is actually just the 11 digit zip. The final two digits are the last two digits of the house number. So "123 Any Street, Anytown FL, 45678" the final two digits of the zip would be 23.
"Identify theft" should simply not be a thing at all - it's fraud against the bank and the person's whose "identity" was stolen shouldn't be involved. Combined with simple fraud chargebacks that make the bank accountable if they can't make their (fraudulent) customer accountable would reduce much of it.
The best solution to this is using your browsers built-in password manager (or your favourite browser-integrated password manager) then your randomly-generated password for ups.com won't auto-fill for myups.com and you at least have to think about it and wonder why you need to fish the password out of the password manager.
A lot of people look at scams and think "I'd never fall for that" because at face value something looks obvious and you think you can use these obvious filters. BUT in reality there's tons of fuckups like this that make the space confusing because the "red flags" just look like flags.
For example, in the scams where people fake a voice of a loved one people think they'd know. But there's bad connections and scammer makes it feel like an emergency so you'll let little weird things slip by. Or how every year or two Google changes its login page format (and currently I seem to hit two very different formats...). Or a week ago with the rabbit leak I said this was a reason not to push people to download a file[0] and people concentrated on the part of it being a zip and not that 1) you download something and 2) that zip has to be opened even if a zip alone can't do anything.
This really is one of the big dangers of enshitification. It becomes difficult to distinguish legitimate things from scams.
Right wingers believe that USPS should operate as a business, not a public service, so "rebranding" their website to be .com is definitely a part of that narrative.
[1] https://web.archive.org/web/20000229182038/http://www.usps.g...
[0]here is just one: https://www.reddit.com/r/explainlikeimfive/comments/3piv7w/e...
Seems failing businesses is also on brand for those guys.