Phishers Love New TLDs Like .shop, .top and .xyz
krebsonsecurity.com
krebsonsecurity.com
Registering a domain is frustrating these days, too many already taken and a lot of them by squatters not even intending to use it. I'd love to see more options personally even if it makes it slightly easier to create a phishing domain. We need better tools than memorizing a domain name to deal with that anyways.
dell.shop, that's probably the dell computer I know, right?
That is exactly why it's so dangerous and effective versus your example.
That's the real problem with domain trust these days. Companies go out of their way to make sure you know to only visit official links, and then do stupid stuff like buying vanity domains for one-time deals, or make you click through mailchimp tracking URLs because marketing tracking is more important than your customers falling for phishing. Those vanity domains then end up expiring, and now emails and web links that used to go to an official $brand server are all ready to be swooped up by scammers. Customers never stood a chance.
This isn't a TLD problem. It's a shitty company problem.
Another issue is that they can make password management more of a chore. Every time I need to look up my Microsoft login, I have to remember to actually look up “live.com”. Except sometimes the login page is served from “microsoft.com”. Oops, you forgot your password and reset it; now your password for the other domain is out of date. Utterly ridiculous behavior from a company of their stature.
But if I saw a link tomorrow for hackernews.shop and I went there, I'd be very suspicious.
So no, I don't trust that I'm on HN because of I put any trust in the domain "news.ycombinator.com" signifying anything. I only trust that I'm on same HN that I was on yesterday because the domain matches exactly the reference value. But the domain name could be anything, as long as it is stable.
Is Hacker News asking for my credit card or impersonating any other site?
EDIT : and ninjaed...
What good does that do? It is pretty rare for companies to get an EV or OV certificate, since it is more expensive and more hassle than a DV cert, and even when they do, the name on the cert isn't always what you expect since it might be the name of the owning company, not the brand you are familiar with.
Whois on DNS isn't always reliable either, since it often just points to another company that provides a dns service (such as AWS).
I am not sure what a better solution could be. The idea of EV certificates was good but executed poorly. Maybe a way to link certificated to business IDs.
I do however still prefer more gTLDs to minimize domain squatting.
The idea was bad.
Anybody can open the Dell Flower Shop. They can call their company Dell Inc. and register the domain dell.shop and they're not doing anything wrong, because they're in a different industry and nobody is going to confuse a tulip with a laptop. And then they could get an EV cert that says Dell Inc. -- because that's who they are.
Which is why EV certs are worthless. Just because it says Dell doesn't mean it's that Dell. There can be arbitrarily many companies with the same name in different industries or locations. But then what is the certificate supposed to tell you that gives you more information than the domain name? The average person is not going to know a company's registration ID with the relevant secretary of state, or generally even what state they're incorporated in.
They may have just been shopping for a computer, maybe even a dell. Or maybe they need a computer for their kid and don't have the means to afford one and are more likely to fall for a scam advertising a good deal on a computer than for any other scam.
These all add to the probability that someone falls for a scam. Phishing is all about casting a wide enough net that the probabilities align against some of the people you hit at the time you hit them.
Victims are not just uninformed. They are also compromised, and/or incentivized to believe this particular scam, and/or unlucky enough that the scam takes place when they were recently engaged in activity that makes the scam more believable.
Seeing dell.computerdealshop.com will snap a lot of people out of it where seeing dell.shop would not have.
It isn't. People fall because probabilities align. Something can catch their eye to knock them out of it.
A bad URL is a bad probability (for the scammer) in the chain, a really good URL is another good probability. If your assessment is that both URLs look equally good/bad to you, I, of course, won't deny that claim about your own experience. But to my eye, dell.computershop.com looks pretty bad and dell.shop looks pretty good.
I only answer my phone if I'm in the middle of getting a loan and so expecting a call from some unknown number at any time, and even then some numbers look too phishy to answer. The last time I got a loan I got a call from a local area code near the bank, answered, and found myself talking to a scammer about a loan. It was confusing, I believed it was the bank at first! Everything needed to align for them to get that far, including the phone number looking legit to my eyes. To someone else's eyes a number halfway across the country may have looked just as legit. Or the nearby number may have looked instantly bogus. This is exactly my point!
Remember that Google was (is?) trying to remove the URL bar. Not just because it reinforces search as the main product and gateway to the web, but also because URLs are kind of hard for most people.
Which brings us to the original argument: is this a reason to ban gTLDs? Surely the cost of banning gTLDs outweighs the enormous benefits of making it easy for society's productive users to find names they like.
We also shouldn't discount the incredible benefit of having additional namespaces and markets positioned against domain name squatters. gTLDs linearly increase the costs to squatters. Good names can be found with lots of alternative gTLD offerings, which greatly increases the supply side for builders and entrepreneurs.
Ultimately gTLDs probably won't be banned simply because there's money to be made by the ICANN and registrars.
And I don't think gTLDs should be banned! But I don't like bad arguments even when they support my preference.
I now ask businesses like these "what number will you call me from" and I put that in my phone as a contact, so that my phone will ring. If they call me from any other number I won't see the call.
If you don't agree I have a computershopthatisreallycoolandcheap.com to sell you.
Would love to see citations for that.
I see this and raise you HP using domains like h30434.www3.hp.com for decades now. They only started to disappear fairly recently. Many companies will do it and people don't really care.
[0] sigh Apparently nothing is wrong with it, as it redirects to apple.com. So much for that example; take in the spirit intended.
Due to the widespread usage of 3+ common TLDs (com, org, net, etc.) and arbitrary third-level domains, people have been trained that the second-level domain is the one that matters. Now that gTLDs are more common I've needed to retrain my brain that the TLD is also a necessary heuristic for authenticating websites.
A basic personal protection is to not trust anyone who initiates contact with you, no matter who they say they are or what they know about you. Verify by contacting them independently instead.
Its really an unsolvable cat and mouse game without proper familiarising oneself with the dos and don'ts of the internet.
"Nice business you got there. Shame if a scammer bought your name on my new TLD."
For casual usage like personal blogs and whatnot? Sure, use whatever.
But if I was starting a web-based business and couldn't afford the .com? I'd rename the company before I'd use .xyz - if your business takes off the squatters will notice and raise their prices, so the .com will never be cheaper.
If you got an "urgent e-mail" saying your employer needed you to confirm you're legally allowed to work, and they directed you to experianrtw.app - would you go there and send them a photo of your passport?
Would it have been so hard to sit down and pick a couple short ones - yknow, ones people might actually use?
I’ve been seeding government and business forms with a .io email address for years (to counter gmail dominance), and I’m quite concerned about the situation now.
No, they can’t do that. Every two-letter TLD is defined to be a ccTLD, and nothing else.
What if your primary source of income is Uber or Doordash or Etsy or Youtube?
It's never a single signal, and the more legitimate a domain looks, the bigger a chance is that someone fells victim to a scam.
Tbh I'm increasingly thinking that just about any speculative instrument in the economy is just grift and drag. If you want to make money, make things. Stop trying to extract rent or exorbitant prices for land, for domains, for PS5s, etc. Feels like 9/10ths of the economy now is nothing but fucking middlemen, when we have a dearth of need of ANY middlemen at all anymore.
How do you define squatting? Is the owner of nissan.com "squatting" on it because he wouldn't sell to the japanese car company? How much interest do you need in a given domain before it's not squatting?
- Hosting a website
- Operating email accounts
- Infrastructure (mail, DNS, etc.)
- Misc. Services (Minecraft server, TeamSpeak server, something)
Then you're squatting. Like if you own turkeyonapig.com and it's literally just a web page with a picture of a turkey sitting on a pig? Not squatting. It's odd but it's clearly doing exactly what it's meant to be doing. If you own turkeyonapig.com and are doing nothing but advertising that fact, and that someone can buy it? Squatting.
> Is the owner of nissan.com "squatting" on it because he wouldn't sell to the japanese car company?
I mean, it depends. One would argue that people going to nissan.com are clearly looking for the Japanese car company, so it's in the public's interest that that domain be sold to them. On the other hand, if someone owns it and is using to run a Nissan fan website? Well I suppose that's trickier, but that would also probably be better suited to something like nissanfans.com.
It's a tricky thing but not impossible to figure out.
GPT/Cursor will create that page for you in 5 min. I bet a NotSquattingAsAService startups will appear which will create the "not squatting" fake site for you for $2.
But also like, then you aren't advertising it for sale. So I'm wondering how many offers you're going to get to sell that domain, which is the point of squatting it.
That's an improvement. Adding $2 to $5 to the cost of a squatted domain will start to dissuade people who squat on tens of thousands of domains, if they have to suddenly have to pay $20,000 to $50,000 for the not squatting service.
There's no way static site hosting and a email service costs $2-$5 per year per domain, especially for bulk users. Even if we take that price at face value, a .com domain already costs around $10/year. A 20%-50% increase will only change behavior at the margins. It won't make chat.com magically become available, and at best will make some D tier domains available. Ironically the introduction of gTLDs probably had the same effect. Squatting harrisonburgrealty.com is suddenly going to be less profitable when there's harrisonburg.{realty,realestate,realtor,homes,house,place,properties,rent,apartments} available as well.
See my example of turkeyonapig.com.
Good to hear. So after that you'll be sorting out world peace - right?
Squatters are a massive blight on the internet.
Is not unique to domains, this is why the world is uts.
First past the post is "good enough" for me if the intrinsic value of the domain to you is greater than the domain registration fee of like 3-10 bucks a month.
There shouldn't be a major reselling market, that would be like if the majority of space in the yellow pages was just advertisements that said "your business ad here!"
If you get caught, the domain is blacklisted. Ownership transfer is public, so there is little incentive for buyers to go with this route.
cloudflare offers free website hosting and email forwarding, so it's basically free for a squatter to check those boxes.
>I mean, it depends. One would argue that people going to nissan.com are clearly looking for the Japanese car company, so it's in the public's interest that that domain be sold to them.
So you basically want the Kelo v. City of New London decision to be applied to domains as well? You own "erictrump.com" but aren't the president-elect's son? Well tough luck because it's "in the public's interest" that president-elect's son gets it rather than you.
Sure. But it still takes time, or as someone else suggested, a GPT query. Putting literally even the tiniest amount of work in front of squatting will reduce the amount of squatting.
> So you basically want the Kelo v. City of New London decision to be applied to domains as well? You own "erictrump.com" but aren't the president-elect's son? Well tough luck because it's "in the public's interest" that president-elect's son gets it rather than you.
I mean, it is. And putting the phrase in scare quotes isn't a counterpoint.
One could argue in fact that one of the multitude of reasons for the rise of platforms is that it's so hard to find anything on the actual internet, and part of that in turn can be blamed squarely on squatting.
It doesn't matter if you're just a dude or a corporation, you play by the same rules. There isn't anything to solve here. These problems are solved between those those 2 parties and no one else.
Good Lord. It's in the public's interest it remains this way.
Another person here had it right, companies have been playing with fire with their URL shenanigans. From one time TLDs to abusing tracking parameters. Not to mention browsers in their insane quest to strip useful information out off their UIs, making you CLICK to see who owns the place. Clown world really.
And you don't really own your domain. You are just renting it from whichever authority is responsible for the TLD. If you stop paying, the authority will eventually take it back.
Of course this raises valid question if using names in this way at all is a good idea. For example telephone system and lots of banking stuff is based on simple numerical identifiers, and lots of countries have also some unique (numerical) identifiers for companies and persons. So there is fairly strong precedent for using assigned ids instead of names when uniqueness/specificity is required. But somehow we have jumped to the conclusion that for example IP addresses would be too confusing to average joe, and in attempt to hide them we have created even more confusing system.
Also, what's the difference between a squatter and a personal blogger?
That wasn't what the article stated. The article stated that the problem is that the new TLDs are so cheap as to be disposable, and the registration requirements are lax. The combination makes them attractive to criminals.
It's literally the first sentence of the article:
"Phishing attacks increased nearly 40 percent in the year ending August 2024, with much of that growth concentrated at a small number of new generic top-level domains (gTLDs) — such as .shop, .top, .xyz — that attract scammers with rock-bottom prices and no meaningful registration requirements, new research finds."
It feels like there should be some way of determining if a domain is actively being used, to combat squatters, but when ever someone tried to make a rule it ends up being something stupid, like not having a website.
Putting on my regular-person hat: When I see a billboard or print ad with e.g. `example.travel`, I read that as a social media handle and not a website address like `example.com` would convey. In public perception, dot com means websites. Always has.
(Tangentially, the `.sucks` TLD in particular should never have been allowed. How many brands out there have to maintain a perfunctory registration there just to prevent somebody else from doing so?)
That said, .app has found plenty of adoption. Tech companies absolutely love .io and .ai is now also gaining popularity. The good American URLs have all been bought years ago so people flock to ccTLDs and gTLDs for new products and businesses. Even .engineering has a few interesting businesses on it these days.
As for .sucks, it's clearly a cash grab, but banning it hardly solves a problem. ycombinatorsucks.com is a lot cheaper than ycombinator.sucks, and if ycombinator pre-emptively buys ycombinatorsucks.com, you could just buy ycombinatorisshit.com or ycombinatorisadoodoohead.com.
.co.xx is common in Britain (.co.uk), Japan (.co.jp), New Zealand (.co.nz) and probably others. It's perfectly legitimate for a site linked to those countries.
My suspicion is that it was due to abuse; a long time ago, I noticed some university had registered IIRC .co.br (our correct equivalent to the .com gTLD is .com.br; this is a notable exception to the assertion above that "I rarely find a reputable business that is using anything but .com or .co.XX as the primary domain", since plenty of reputable businesses use .com.br as their primary domain, not .co.br which doesn't exist).
What about all the other ccTLDs? Okay, maybe not .ly, .by, .ru and friends, but what do you have against .it, .fr, .de, es?
https://www.mos.ru (Moscow's city site), https://www.belarus.by/ (Belarus' tourism site) and https://libyaobserver.ly (Libyan newspaper) are three examples.
And I'd be almost as suspicious of buy-viagra-pills.de as I would be of buy-viagra-pills.ru.
1. https://domainnamewire.com/2024/08/28/radix-sets-record-for-...
* withholding tons of domains to watch them go up in value means people can't get those domains (scammers, regular people)
* registries do not make a high price when they sell high-value domains (registries)
* there's only so many words / groups of words that are easily typeable (everyone)
* reducing scarcity reduces the value of digital real estate (domain squatters / traders)
Which of these issues / values / interested parties are more important to help than others, and what, if anything, should change?I, personally, tend to be in favor of reducing the impact of scalpers by increasing total available volume. As a consequence, I'm also willing to accept some terms for the registries that they get to set higher prices for the most premium of their domains to:
* sweeten the pot for both registries and registrars to even support all these new domains
* reduce a squatter / trader / speculator / scalper's ability to sit on vast tracts of digital land.If you go from a standard registration price of $12 / year to a first year premium of $132, you double the 10 year carrying cost of a domain. That, naively, means domain investors can only speculate on half as many domains.
By having a first year premium price and then dropping domains back into the 'standard' tier, you also leave registrants with a semblance of price protections via section 2.10c of the registry agreement. As-is, premium domains have zero guarantees when it comes to premium renewal pricing.
There's a lot of room between squeezing domain investors and asking registrants to pay $100-1000+ per year for premium domains.
Though I can also definitely understand why, for example, "lawyer.lawyer" would cost $$$$ every year, too, at least myself.
This is where I think the new gTLDs registries could do better. Using your domain as a handle on Bluesky is a perfect example of something they could push for to grow the industry, but they seem to think the status quo with a sprinkle of price discrimination is the winning formula.
Most of the new gTLDs work great as domain verified social media handles, but no one is going to use them for that if all the good keywords are classified as premium with $100+ annual renewal fees. However, if you make them too cheap and they get popularized, domain investors will register everything good and try to flip them.
I think first year premium pricing strikes a good balance that doesn't limit novel, non revenue generating use cases too much. Charging $100-200 for the first year causes a very large increase in the amount of capital domain flippers need to invest to acquire a large portfolio of good names.
If Bluesky catches on I think we could hit a point where non-technical people are suddenly shocked when the see someone "using their social media handle for a website." Getting back to having people understand there's more than just Facebook and Twitter would be a step in the right direction IMO, so it would be nice to see Bluesky continue to gain popularity.
The entire reason for allowing that TLD is a presumption that brands are not entitled to prevent the registration of domains which exists specifically to criticize them.
> .com and .net domains made up approximately half of all domains registered...they accounted for just over 40 percent of all cybercrime domains.
Hardly earth shattering. .net and .com are still pulling 80% of their weight when it comes to cybercrime. And the article concludes that the main reason the new TLDs are disproportionately used is because you can sometimes buy them cheap in bulk.
Maybe the real story here is that the ccTLD registrars, who weren't mentioned, are disproportionately good at deterring cybercrime.
I think that some ccTLDs requiring positive identification, usually as a side effect of residency or nationality requirements, immensely help here (versus most gTLDs requiring f***-all identification).
The article states it's half that.
"while .com and .net domains made up approximately half of all domains registered in the past year… they accounted for just over 40 percent of all cybercrime domains. Interisle says an almost equal share — 37 percent — of cybercrime domains were registered through new gTLDs."
No, the article agrees with dmurray. Read again: 80% of 50% is 40%.
He's from pre-gold-rush Internet, and still making the net better: https://en.wikipedia.org/wiki/John_R._Levine
Why only make money once by selling apple.com if you can also sell apple.biz, apple.xyz, apple.froom etc ad infinitum?
apple.* takes time to gather revenue. *.apple gathers an infinite amount of money quicker.
Why shouldn't they be able to buy a domain name which contains their name?
Is it useful to be able to differentiate between McDonald's the restaurant and McDonald's the legal firm and McDonald's garage?
Why shouldn't each of those industries get their own TLD?
The original list of TLDs aren't some platonic good written by ineffable sages. It's OK for things to change.
>Why shouldn't they be able to buy a domain name which contains their name?
I fail to see how johnsmith[insert number here].com is any worse than johnsmith.[insert TLD here]. If anything a number is less likely to get mixed up than tlds, which have confusing pairs like ".tech" and ".technology", or ".engineer" and ".engineering".
If the whole EV certificates thing would have been set up in a way that it wasn't just a money extraction racket, that would be the way forward. Let user agents convey whether a site is trusthworthy, and what entity it is connected to.
DNS should offer disambiguation services. Instead, we have this awful system.
My dream is to fork a browser and replace the DNS component with an entirely new protocol that respects the notion that people in the real world share names.
You can build reputation and trust using a handle, even if it's not associated with your real world identity. For example, I know that if 'ryao' replies to a question about ZFS, the response can be considered trustworthy. I don't know who that is or even what country they live in, but I know they're a contributor that isn't speculating or guessing when they reply and that's all that matters to me.
Domains can be used as verifiable, globally unique handles which simplifies things for the average user because it makes it easier to help users avoid impersonation and confusion if you can point them to something simple and verifiable. For example, look at Bluesky [1].
I've been wanting domain based namespaces and handles for a solid 5 years because it just makes sense. Here's my oldest mention of it (asking why package managers don't use domain verified namespacing) I have on HN [2]:
> It seems like a waste to me when I'm required to register a new identity for every package manager when I already have a globally unique, extremely valuable (to me), highly brandable identity that costs $8 / year to maintain.
You can tell it's old because .com domains only costed $8 back then. IMHO, domain based handles are the #1 reason to use Bluesky over X/Twitter. People used to spend $10-15k buying "noteworthiness" via fake articles, etc. to get verified on Twitter. I can't find any links because search results are saturated with talk of X wanting $1000 per month for organization validation (aka a gold check mark). Domain validation is just as good as that kind of organization validation, at least for well known individuals and organizations.
Given that, I think there would be a bigger market for domains if domain validated identities catch on. It could even spawn specialty gTLDs that do extra identity or notoriety checks (if that's allowed) or maybe attestations would become a big thing if there were an easy way to do them against a domain verified handle.
1. https://bsky.social/about/blog/3-6-2023-domain-names-as-hand...
With a new crypto-friendly administration coming in, it's going to get much worse. If you haven't been following this, there's a whole industry pushing "meme coins" via pump and dump operations. Some even admit they are pump and dump operations.
She's retired and it could have ruined her financially. I don't think she realizes how close she was to this.
The software they used bypassed windows defender because it was legitimate software called 'screen connect'. I was able to remove it pretty easily. It looked like a reverse-shell attached to a windows service (small .exe with no front-end).
There’s a lot of trust in a namespace system that doesn’t deserve it, although odds are you personally can use it to be immune to scams. What do we do for everyone else?
the city centre is overcrowded and super-expensive, while the new neighbourhoods in the suburbs are a mixed bag.
while some become instant hits and sometimes cost more than inside the city (like .ai lately), while you got these tlds that only bring pain.
not to forget you are always leasing, and own nothing in the end.
My biggest complaint is that some large retailers/services completely refuse to believe it is a valid domain. (I'm looking at you, Walgreens. You blocked me during a pandemic from signing up for a vaccine with my actual email address, which is why fuckwalgreens@myother.domain is now my email in your system.)
They also don't offer any programs for trusted third parties so we have to spend a lot of time bypassing and paying for services that skip Cloudflare instead of taking down phishing sites.
there's nothing that makes .top or .xyz more problematic than .net or .org. if the assertion is that it's too confusing for people to pay attention to all the parts of a domain name, then why do domain names continue to have multiple parts? let's just deprecate everything other than .com and be done with it.
After that I decided to only get .xyz domains for internal usage like infra domains or for internal self hosted apps.
URLs following a pattern is not a good way to authenticate a site.
There is a standard, reliable register of business entities (typically called “Secretary of State”) and it should be trivial to know if the domain I’m talking to is owned by/part of that entity, that the X.509 matches, and so forth.
https://en.wikipedia.org/wiki/Extended_Validation_Certificat...
So far zero issue - somewhat to my surprise (was expecting delivery issues). Even got some compliments from people that thought it’s great
(If you used "https" and made it a full URL, that's different.)
Everything outside that just looks like a scam, even if it isn't.
It looks legitimate, and it's probably enabled Leon to use their business name in the domain.
The first American site is https://roughwood.luxury/, it also looks fine.
In the TikTok and Instagram community people are spending billions not only on random domains (like tiedyeshirts.xyz) but often to venmo or zelle listed on profiles. My sister and thousands like her send money to faceless profiles to buy mystery boxes.
I think there's a generational divide here, the older people seem to distrust more recent TLDs for some reason while younger people don't really care about them.
Holy shit. CAUCE is a name I haven't heard in a long time. He's been around for a while and is one of the good ones.