Spammers start using short .gov URLs to trick their victims
thenextweb.com
thenextweb.com
Those two practices, typing in "www.wellsfargo.com" instead of clicking on a link that suggests it will be taking you there, and never, ever, opening any attachment, cuts down on 95% of the malware attacks that these people experience.
Most non-computer users aren't sophisticated enough to understand what links they can, and cannot click on, so they are safer just typing out URLs and navigating from there. It's great advice for those people. Bookmarks make the practice a little more efficient as well.
As much as we computer sophisticates despise the "Walled-Garden" aspects of the Apple Store (and soon, the Microsoft Store) - those should also significantly reduce the amount of malware people end up installing when they add new programs. It may not eliminate it (as we saw when Path uploaded people's Address Book information onto their servers without asking the user permission) - but, between application review + client-side checks on privacy - malware infestations have experienced a radical drop on stock iOS devices vs what a user's computing experience used to be in the Bad Old days of Windows 95/XP in which even _I_ got nailed by a trojan or two.
In that vein, here's an idea for a browser feature. When someone enters something into a form that looks like a credit card number, bank account number, or bank routing number, black out the entire browser (including the url bar) and require them to type in the domain they think they're submitting to. If they get it wrong they can't submit the form (at least for a few minutes).
How is a browser supposed to detect either?
I don't really think most computer sophisticates have a problem with a walled garden, but rather a problem with a locked down garden. In linux, for example, the standard means of installing software is through a central repository maintained by whoever maintains the OS, and all of the software in that repository is reviewed before being added. The difference is that if the user wants to, they can install software not offered through the repository, and/or add 3rd party repositories.
[1] labor.vermont.gov/LinkClick.aspx?link=[spam site]
[2] http://www.google.com/search?q=site:.gov+inurl%3Aredirect
[3] http://www.google.com/search?q=site:.gov+inurl%3Alinkclick
There are also services like anonym.to for when people try and hide even the host site entirely. I've seen forums that turn all outgoing links into anonym.to links.
Of course, anyone who actually cares about infosec stuff would know better than to hand over this data to anonym.to.
The spiritually same exploit made the rounds on cgi forms (form to mail) 15 years ago, and on mail servers (open relay) 20 years ago.
$ ping 1249739877
PING 1249739877 (74.125.132.101) 56(84) bytes of data.
64 bytes from 74.125.132.101: icmp_req=1 ttl=41 time=395 ms
...
Looks like a Google IP. $ nslookup 74.125.132.101
Server: 127.0.0.1
Address: 127.0.0.1#53
Non-authoritative answer:
101.132.125.74.in-addr.arpa name = wb-in-f101.1e100.net.
...
Sure is. And Google redirects wb-in-f101.1e100.net to its main page.At least the bit.ly service means that the traffic can be gathered and analysed (and presumably those links disabled) to get data about spam clicks.