6 ms·
> I suppose the real lesson to be learned is to ...never, ever buy or even take anything from anyone who approaches you without you being the original initiato
by beefield 6y ago
> I suppose the real lesson to be learned is to
...never, ever buy or even take anything from anyone who approaches you without you being the original initiator of the communication. Simple rule that applies to both online and real world and makes your life simpler and safer.
- toxicFork 6y agoAlso works nicely against advertising too, a good principle ;)
- spurdoman77 6y agoReally nice guideline for work. Should spread it around.
- _jahh 6y agoexcept he clicked the link, he did initiate the communication so your bizarrely overly paranoid guidance doesn't apply. Not taking anything from anyone certainly closes you off to the generosity that can be found in humans.
- jonplackett 6y agoYeah, but they SENT the link. That was the initiation.
- _jahh 6y agoI see your position, but I don't view placing an ad as an initiation. He still initiated the conversation by clicking on the ad like he would've if he had called a phone number or anything else and therefore could still have been scammed.
- chuckSu 6y agoYawn
- zentiggr 6y agoWhen I'm curious about something that I might have to click through, I DDG it and find source material. It's not overly paranoid, it's been good advice for decades. Telephone charity calls are exactly the same way in my world, and started me down that handling path. If I look your org up and you look legit, and I'm interested, we'll see. You having called me isn't always strike one, but it often is.
- spazmoose 6y agoLegitimate organizations are not always a safe bet either. For instance, today I received a phone call supposedly from the Breast Cancer Research Foundation soliciting donations. The organization itself is legit, and the number they appear to be calling from could also be legit, but the number they're calling from could be spoofed. Personally, I prefer to follow the OP's advice, and only provide information if I initiate the call. Or, more specifically, I'm willing to provide only the information you could find in a phone book, such as name, phone number, and address, and if they truly want my donation, they can mail me something for the request. Still, it could result in mail fraud, but the likelihood is pretty low at that point.
- stallmanite 6y agoThis is my strategy as well. If I want something I initiate a search. Incoming sales attempts do not exist in my universe.
- forgotmypw17 6y agoBe careful which search result you click: https://wp.josh.com/2019/05/06/breaking-news-google-adwords-exploit-seen-in-the-wild-yikes/ https://wp.josh.com/2019/05/06/breaking-news-google-adwords-...
- coronadisaster 6y agoIf you want to see where Google search results really point to, you can right click it and then hover over it to get the real destination... it's been like this for 15+ years (google changes the destination on-click).
- forgotmypw17 6y agoThanks, I'll be sure to explain this to all my friends and family, right after I teach them what onclick, "real destination", "hover", etc. mean.
- coronadisaster 6y agoI think that it is pretty screwed up that browsers allow this "feature"...
- exikyut 6y agoJust checked; and while they did indeed use to change the URL (on mousedown (!) - which was infuriating, because right-clicking to copy URLs produced a mess I'd then have to pass to data:text/plain,... in a new tab to extract the URL-encoded... agh), they currently really do just leave the link alone now. They just fire off a request to google.com/url?... to track the click before letting you on your merry way. Sigh
- 6y ago
- TedDoesntTalk 6y agoThis is an old tip my father gave me 40+ years ago that applies to banking, mortgages, insurance, investing, credit cards, and all personal finance.
- AndrewUnmuted 6y agoAlso a very good rule of thumb for recreational drugs and other illicit activities.
- mritchie712 6y agomeh, he calls out the exact mistake he made. If I see an ad and like the product, I go to the domain. If the domain is legit (e.g. not developgameonline@gmail.com), you can start to feel pretty good about it. We run ads. If you google my companies name ("seekwell"), the entire first page is properties that we've owned for years. This includes podcasts and youtube videos. It's ok for the initial pull to be an ad, but only buy from the source.
- headmelted 6y agoNot at all fool-proof. What if they can register a very similar / regional domain that you didn’t set up already? Normal rules don’t apply when you’re a criminal so spoofing SSL cert names is something you might as well do too. It’s just not practical to examine and confirm the cert manually of every company you interact with online. These internets are dangerous, even if you know what you’re doing.
- tialaramex 6y ago> Normal rules don’t apply when you’re a criminal so spoofing SSL cert names is something you might as well do too SAN dnsNames in certificates in the Web PKI are verified by the issuer - these days using one of the Ten Blessed Methods. It would certainly be possible to obtain certificates for a name you don't actually own, but it's a bit beyond the usual casual crooks that run scams like this. We see what appear to be nation state adversaries doing it, as part of wider targetted hijack schemes (e.g. to intercept IMAP credentials for a foreign government agency) but it's definitely not something you see an ad scammer doing. Any vaguely competent modern browser checks the certificate is trusted in the Web PKI and that it matches the SAN dnsNames to the FQDN in the URL exactly so there's no room for any funny business there. And human readable names in end entity certificates are largely irrelevant. Nobody looks at them, who cares?
- hal9000-tng 6y agoYou are replying to a point that the GP didn't make. This was the precursor for the might-as-well-go-for-letsencrypt statement: "What if they can register a very similar / regional domain that you didn’t set up already?" In other words, they register fakebook.com and then just go get a TLS cert for it. If you're not looking carefully, you might not notice the difference. Whether the CA system, with fungible, interchangeable certificates that can be issued by dozens of CA's (pinning excepted), is worth sinking lots of trust into is an entirely different matter ;)
- aplummer 6y agoThere's a current scam going on right now where people are getting calls to get in on the ground floor of the "Stripe IPO"...
- zmmmmm 6y agoThe sad thing is, this is simultaneously the only way to stay safe AND also the underpinning of almost the entire ad industry - and in turn about half of the money that funds what we think of as "the internet" today. It really sucks that it seems like we've built the most important infrastructure of our generation effectively on quicksand.