19 ms·
The .zip TLD sucks
- me_again 3y agoKind of an inflammatory page, but the .zip TLD doesn't seem like a great idea.
- ilikepi 3y agoEarlier discussion on Google's announcement: https://news.ycombinator.com/item?id=35917362 https://news.ycombinator.com/item?id=35917362
- avalys 3y agoThey occupy such different parts of my conceptual headspace that it never occurred to me that filename extensions could be confused with TLDs, or vice-versa. But clearly, this is a problem! Why is Google actually doing this? Presumably they have some motivation other than making a small profit on registration fees. What’s their angle here?
- _0nvm 3y agoI once heard a story about a client who thought HTML was short for "hotmail".
- bombcar 3y agoThey were almost right, the original HoTMaiL was stylized like that because the word was picked as having "mail" and "HTML" in it.
- mywittyname 3y agoThat's actually really clever.
- bombcar 3y agoSamba was named the same way: >The name "Samba" was derived by running the Unix command grep through the system dictionary looking for words that contained the letters S, M, and B, in that order (i.e. grep -i '^s.*m.*b' /usr/share/dict/words).
- eric_the_read 3y agoJust imagine if they had gone with "sombrero", how much more fun networking would be. Or smörgåsbord!
- nerdponx 3y agoWhy S M and B?
- meindnoch 3y agohttps://en.m.wikipedia.org/wiki/Server_Message_Block https://en.m.wikipedia.org/wiki/Server_Message_Block
- takeda 3y agoI think they were also one of the first web based e-mails. This was when majority people used email clients.
- _0nvm 3y agoI would argue the majority of email users back in the 90's were actually using Unix clients like Pine. Some of the first major users of email in those times were college students, all universities setup email accounts for each student, hundreds of thousands of daily email users, which could be checked at dedicated terminals in libraries, etc. Those were usually Pine. Just think of those many thousands of users all knowing the Pine keyboard shortcuts to send an email -- I think I can still remember them, actually. There was no mouse.
- _0nvm 3y agoThis client was I think a novice web designer and assumed all web files were "hotmail files" as a result of this misunderstanding.
- Xerox9213 3y ago[dead]
- tomjakubowski 3y agoPleasant memory here of being a naive kid and trying to register a domain by creating a file with extension COM.
- happytoexplain 3y agoI don't have a strong opinion on whether this TLD is a bad idea, but I just wanted to point out: Conflating TLDs and file extensions isn't even in the same universe of the most "obvious" mistakes many computer users can make. You might as well be surprised that a random person off the street might not know the difference between Vulgar Latin and Classical Latin.
- growthwtf 3y agoYeah wow this is actually pretty bad. Right now I can go buy: - wellsfargo.zip - bankinfo.zip - irs.zip - email.zip - taxreturns.zip Which — in one sense it's great that there's some new domain names. On the other hand these 5 alone would be a total phishing nightmare for some unsuspecting people.
- Cthulhu_ 3y agowinrar.zip
- indeyets 3y agowin.zip
- evan_ 3y agoWhat's the specific attack vector you're thinking of for something like wellsfargo.zip?
- woodruffw 3y agoSome of these are more tortured, but I can personally imagine a scenario in which a less-technical friend or family member is told to open a ZIP archive locally by some (trusted!) website and types that into the omnibar instead, bringing them to a random website.
- growthwtf 3y agoThere's probably better ones, literally the first one I tried, but I'm imaging someone messaging me that telling me to download a recovery package for my Wells Fargo account and that it should open in the browser. Then have UI mimicking some kind of OS prompt and asking for your social security as a password to confirm identity, or something.
- evan_ 3y agoIs that substantially different from simply messaging someone and saying "download this file:" and linking to a malicious site with a .net TLD? Is the thought that the .zip tld conveys some kind of trustworthiness that a different TLD would not? Really trying to understand this, I hope I don't come across as snarky or naïve.
- eterm 3y agoWouldn't it be easy for cloudflare and other ~~WHOIS~~ DNS providers to just not propagate the .zip domain? Isn't it time to leverage what's left of the decentralisation of the web rather than beg google?
- woodruffw 3y agoI think you meant DNS, not WHOIS. That's probably worse than the alternative: I don't think we want a world where the person in accounting can resolve hxxps://financialstatement.zip and the person triaging it in IT can't.
- eterm 3y agoI did mean DNS, thanks, been a long week.
- jeroenhd 3y agoWhy rely on third parties? Setting up your own recursive DoH server with the appropriate settings (PiHole etc) is super easy. It's even free if you use the free forever VPS server Oracle will give you. The uplink being limited to 50mbps isn't an issue for DNS (and similar lightweight protocols). I'd recommend putting the DNS behind a secret subdirectory though, because my server accidentally got added to a DNS server list and a small country started querying mine at about 30k per second
- nfoz 3y agoThis is the deliberate reason why this TLD exists. ICANN sold out the internet.
- swyx 3y agocosign. come on Google, this is obviously confusing and frustrating for everybody. the money cannot mean that much to you.
- jbverschoor 3y agoWell, there's also .com which was confusing for me as a 12 year old thinking it had something to do with a .COM executable, and nobody could explain what it meant. I hereby want the .exe, .arj, and .rar TLD :-)
- jahewson 3y agoThis reminds me of being a kid in the 90s and installing the DOS version of Command & Conquer onto a parent’s laptop and then being asked to delete it. COMMAND.COM yep that must be it…
- Cthulhu_ 3y ago.jpg would make sense, if it's limited to domains only ever hosting a single image file, like goatse.jpg
- manuelmoreale 3y agoThat would be an hilarious restriction. And I’m sure it would also push clever devs to stretch the definition of what a single image file is. I now kinda want that to happen.
- 8organicbits 3y agoDomain names that are limited in their functionality by the TLD are really interesting to me. I know all of .dev is on the HSTS list, for example. I'm currently working on a subdomain registration service that only permits A/AAAA records in the private IP address ranges [1], but still supports certificate issuance over ACME DNS-01 via TXT rrecords. For jpeg, that would be a terms of service agreement? Or would the TLD manage all hosting? [1] https://www.getlocalcert.net/ https://www.getlocalcert.net/
- diarrhea 3y agoI think at least my consumer router would block such DNS on grounds of DNS rebind protection.
- deleted 3y ago[deleted]
- gjsman-1000 3y ago> The people who care are asleep at the wheel at best, some aren't with us anymore, and ICANN has failed all of us by allowing this to happen. I think ICANN has increasingly become a failure, in several ways. - Constant questionable TLD approvals (did the world really need more than the basic five? It's a scammer's dream!) - IANA mismanaging IPv4 assignment, giving 16.7 million addresses to people who didn't need them at the beginning (like, Apple, who is comfortably sitting on every address starting with 17, or Ford, with every address starting with 19). Causing, of course, IPv4 address auctions... - The whole .org domain sale fiasco to a private equity firm - The contracts with VeriSign for .com management and price increases there for no particular reason - Approving the .sucks domain, in what was widely criticized for having no public value other than to humiliate and extort corporations and individuals - Giving the .amazon TLD to the company, instead of the Amazon Cooperation Treaty Organization (ACTO) which is comprised of countries involved in the actual Amazon rainforest after a years-long battle And so forth...
- chunk_waffle 3y ago> did the world really need more than the basic five? Only because of domain squatters...
- CydeWeys 3y agoAnd, you know, the existence of countries, that speak different languages...
- chunk_waffle 3y agoFair point, in my attempt to throw shade at domain squatters I seemed to forget that countries and languages exist. (I really hate domain squatters...)
- mschuster91 3y ago> - IANA mismanaging IPv4 assignment, giving 16.7 million addresses to people who didn't need them at the beginning The US government could step in and demand that the big HODL'ers of not actively used IP space release it back to IANA. It's even worse than Nestle and others hogging onto extremely old water rights because Nestle at least makes something that people can drink... Our governments are sitting and idling around while valuable resources - IP addresses, water, food, whatever - get ever more and more scarce as large chunks are held hostage by private companies.
- benatkin 3y agoI disagree after seeing what happened with .dev. I myself was concerned about it but it turned out to be fine. This will be the same.
- skrebbel 3y agoBecause .dev is such a common filename extension?
- benatkin 3y agoI'm not seeing the attack vector. The URL of this page certainly doesn't show it.
- SpaghettiCthulu 3y agoProbably because it's a reasonable TLD to use internally for testing
- Spivak 3y agoWhy are you getting downvoted, that's literally what happened when it launched. A bunch of people were like shit I use .dev internally. Nobody used .test, .example, or .home.arpa
- justin_oaks 3y agoYup. It happened to me. After the .dev TLD was created, I switched all my internal dev hostnames over to .test because it's one of the reserved TLDs [1]. I also switched off of .local after learning that it's used for mDNS [2]. 1: https://www.rfc-editor.org/rfc/rfc2606.html#page-2 https://www.rfc-editor.org/rfc/rfc2606.html#page-2 2: https://en.wikipedia.org/wiki/.local https://en.wikipedia.org/wiki/.local
- CydeWeys 3y agoExcept that it's not, and never was, because it was never expressly reserved for this purpose. And it was particularly unreasonable to use for testing since 2012 when multiple applications were submitted to ICANN to create it as a gTLD.
- eganist 3y agoFor those having a hard time fathoming it, here's a rather simple attack case: someone types "product.zip" into the address bar thinking the browser will automatically google it because of course it's not a valid domain name but it turns out product.zip is a valid domain name, and it masquerades either as the product's webpage or as a delivery vector for other payloads. --- I've mistyped search terms with periods in them and seen the browser try to route me to an invalid domain, so this isn't beyond the realm of reason. --- edit: xsmasher below came up with a much more obvious attack case that deserves a read.
- whalesalad 3y agook, giving you props on coming up with a valid scenario here but in what world is someone trying to search for product.zip? Maybe my tech-illiterate boomer mom who would ask google to find a file on her desktop called product.zip but is that a case we want to optimize our TLDs for?
- bryant 3y ago> Maybe my tech-illiterate boomer mom who would ask google to find a file on her desktop called product.zip but is that a case we want to optimize our TLDs for? What percentage of the population is tech-illiterate? maybe a single-digit percentage of HN, but the vast majority of the world even today can't find the control panel on Windows. And anecdata from school systems suggests that consumption-focused devices are regressing the next generation of users such that millenials and early gen-z are probably the peak of tech-literacy.
- xboxnolifes 3y agoI don't search for zips, but searching like this is pretty good for finding pdfs. If you were looking for a zip and knew with good chance it's on the internet, why not?
- pphysch 3y agoPDF is special for a dozen reasons. Googling for "product.zip" makes no sense. Unless it's an actual website.
- armchairhacker 3y agoHonestly it would be good to just patch browsers to keep interpreting .zip and other common file extensions as a search query (.com, .org, etc can stay) You can argue that removing the .zip TLD is a better solution, but this one is immediately actionable (you control the browser)
- woodruffw 3y agoThis is more or less how I felt when typing `subprocess.run` into the omnibar and discovering that `.run` is now a valid gTLD.
- tptacek 3y agoAt some point though we have to accept that the Internet's public namespaces can't be defined by whatever random-ass file extensions different operating systems use. I can understand pushing back on ".zip" as a special case (I don't think it's going to be that big of a deal, but we'll see), but the general principle shouldn't be that TLDs have to "avoid confusion" with file formats; it's the browser's job to avoid that confusion, right?
- woodruffw 3y agoOh, I don't necessarily disagree -- it was just surprising to think that I was Googling a Python API (for the 500th time!) and all of a sudden get a DNS lookup failure instead. (It's not Google's or IANA's or whoever's responsibility to fix a namespacing problem here, but it's also maybe not ideal that less-technical users are funneled into a single "omnibar" interface for both searching and domain resolution.)
- kkarakk 3y agoit's funny how the idea of googling docs already seems quaint to me coz of chatgpt but i still do it really often
- SimonPStevens 3y agoNot sure it matters that much. Most non-technical people I know wouldn't have a clue what a .zip was. Windows has hidden file extensions by default now for decades. And having a phishing link in an email that says something.zip but links to somethingelse.com is a basic scammer 101 level technique. Why would it matter if the .zip was a real part of the URL or not. Don't get me wrong, I dislike all of the generic TLDs, and the registration process behind them. But of all the points to argue on them, this seems like the weakest and least relevant.
- mywittyname 3y agoI don't necessary agree with this argument. Normal people call some files by their extension pretty often -- pdfs, jpegs, gifs, zips, mp3s, etc. While an OS may hide extensions, not everything does. Notably, gmail shows the file extension for attachments.
- xboxnolifes 3y agoPeople call things by their common social usage and program association. If all mp3 files types got replaced with a random new standard like "fmp" overnight, id bet my life that most people would continue calling them mp3s for years. See: people calling any animated image a gif, even though many are apng or webp
- manojlds 3y agoWhich would then be the case for Zip too.
- xboxnolifes 3y agoYes, but my point is is has nothing to do with the extension. It could be a zip, rar, tar.gz, whatever. If they could all be opened in a default windows zip program, most people would call them all zip files.
- Swizec 3y ago
- jamespo 3y agoAh well, .*\.zip$ added to pi-holes regex blacklist
- Spivak 3y agoJust like .info.
- frou_dh 3y agoIf you're looking for things to be OUTRAGED about then you'll find them.
- version_five 3y agoWait, isn't that the point of the ad-supported internet?
- danem 3y agoNo ads on HN, and yet there's still rage-bait here on a daily basis.
- version_five 3y agoHN is an ad for ycombinator. It's just that it's better than 99.9% of ads, but there's still the trap of needing eyeballs, which directed rage provides.
- dang 3y agoWe've been trying to de-direct rage for 16+ years! it's fortunately part of whatever HN's business model is
- eli 3y agoI get the concern at a high level, but it seems weird to not have any specific examples or a PoC. Couldn't you already send someone an email or direct them to a webpage where the text "financialstatement.zip" is linked... anywhere?
- yafbum 3y agoIt's a dumb TLD for sure, but can someone explain what the security problem is? Is there a segment of users who'd be confused enough not to see the difference between a URL and a file name, but smart enough to be able to make that distinction if only the .zip TLD didn't exist?
- yeldarb 3y agoThe worst would be a .js TLD; everyone looking for web frameworks like `angular.js` would end up on a website (that probably is not affiliated with that tool) instead of a search result page. Would make it incredibly easy to trick people into installing malicious dependencies.
- saltminer 3y agoThankfully, a .js TLD is out of the question since you cannot create a 2-letter gTLD [0]. But who knows, maybe some private equity firm will try and bribe a nation to change names so they can get a new country code. [0] https://newgtlds.icann.org/en/applicants/global-support/faqs/faqs-en https://newgtlds.icann.org/en/applicants/global-support/faqs...
- Marsymars 3y agoThat doesn’t seem to be that much a problem with the .net TLD and various .net products. (asp.net, quartz.net, yamldotnet, docker.dotnet, ssh.net, handlebars.net, etc. - from a quick search of these, asp.net is the only one where the asp.net website actually belongs to the product in question.)
- jobigoud 3y agoWhat about an .htm or .html TLD?
- arsome 3y agoBy this (ridiculous) standard, DOS com executables make ".com" the worst offender. Or how about shell scripts and ".sh"?
- grishka 3y agoApple application bundles and .app, too
- pierat 3y agoEh, not really. It's all a mistake how we *interpret* domain names. From https://www.rfc-editor.org/rfc/rfc1034 https://www.rfc-editor.org/rfc/rfc1034 3.6.1 , we see ---------------------- For example, we might show the RRs carried in a message as: ISI.EDU. MX 10 VENERA.ISI.EDU. MX 10 VAXA.ISI.EDU. VENERA.ISI.EDU. A 128.9.0.32 A 10.1.0.52 VAXA.ISI.EDU. A 10.2.0.27 A 128.9.0.33 ---------------------- Notice it's not ISI.EDU , but it's ISI.EDU. for an absolute fully-qualified domain name. You can also notice weirdnesses here when you go to https://news.ycombinator.com https://news.ycombinator.com. (copy and paste with period), like you're not logged in due to cookies not sharing. But requiring absolute FQDN's would solve this https://financialstatement.zip https://financialstatement.zip -> https://financialstatement.zip https://financialstatement.zip. and remove the ambiguity.
- 8organicbits 3y agoThat's pedantic. We're not going to teach the world to include the root '.'
- pierat 3y agoIts absolutely not pedantic, when you consider that TLDs of any language can be a thing. Its really nice to see a foreign language TLD, and know how to separate them appropriately. The "." at the end also serves another level of defense. When you provide a URL without a . at the end, I can append .someotherdomain.com. and redirect traffic. And I've seen that in the wild before. And the difference between "pedantic" and "technically correct" is how you get hacked. But feel free to throw insults. I know one of us is right, and it aint you.
- kortex 3y agoAnd the difference between "technically correct" and "how things actually work in practice" is what keeps the world turning in the face of slight mismatches. See for example the URI/URL naming war. "URL" is a valid term for URI-like identifiers, even if they aren't locators. No one (within a rounding error of 0%) will change how they enter, use, or program systems to work with, URLs to use the FQDN. The incompatibility nightmare it would cause would be insurmountable.
- CPLX 3y agoI mean if you're old then there was a time when .com was the most common file extension at all.
- gambiting 3y agoI mean, that was a good rant, except I still don't understand why this is a problem
- sn_master 3y agoWhat's next? We'll have a .exe TLD? Even if the OS will prioritize local files, there's no guarantee all the 3rd party apps old and new will use the same rule.
- gondaloof 3y agoYou know it's coming. .exe is so s.exy
- foul 3y agoProbably the final aim from which this nerdy offer arise is to pollute the URL bar
- grozzle 3y agoJust today, I had a no-https warning from a .so site when I was trying to search for information about some linux library file. libfooblah.so or something like that, i dare not post the actual name because of course it's gotta be something sketchy as a website.
- renewiltord 3y agoIMHO the real problem was having domains go backwards in most-significant to least-significant. subdomain.domain.tld/root/to/sub/path That goes inwards-out. If we had started with tld.domain.subdomain/root/to/sub/path it all goes from top-level to bottom. Therefore I propose we fix nothing until we deal with this.
- netsharc 3y agoEven with that fixed, people will argue why do other countries' have to have their country prefix? Shouldn't a US website be e.g. us.com.walmart to be fair? And what do you do with multi-nationals, de.com.mercedesbenz and us.com.mercedesbenz? com.mercedesbenz/de (and /us accordingly?). Or de.com.mercedesbenz/us (as well as /de) because it's a German company? Face it, it's legacy, and just like QWERTY, it's never going to be fixed. I see TV ads where the narrator just says "Search for $BRAND_NAME" expecting you to google it, AOL keywords all over again.
- deleted 3y ago[deleted]
- yieldcrv 3y agoHave we ever seen tld’s revoked or cease having registration possibility?
- mavili 3y agoErm, clearly this person is angry lol. I sense that they must be an older person because they think about files being shown as links/underlined texts and therefore people will mistake a domain name to a file. I think today's systems and software are more user-friendly and most of the time links and file names are displayed differently enough for people to know which one is which. Also as others have commented, those not so tech savvy would probably not know what .zip or .mov files are anyway, and therefore their first instinct will be that they're links to sites rather than the other way around.
- dheera 3y agoOh this is an awesome TLD. If I want to share a file with friends I should just share it as https://somefile.myname.zip https://somefile.myname.zip
- mholt 3y agoHey mom, here's the photos from our last family get-together: familyphotos.zip (go ahead, click it) Depending on platform, this is even more fun with command lines with commands like: `open familyphotos.zip` But the point is, unless you are technically skilled, you probably can't tell whether you're about to go to a trusted file or download something random. Depending on the context you would probably expect to be taken to a local file on the disk, you would never think this would download something new unless you were already in a context to do so. Note that Google is also doing this for .mov. Both are file formats which can execute code (zip and mov both have exploits). These TLDs should at least be removed from the PSL. Edit: Here's a PoC screenshot: https://twitter.com/mholt6/status/1657133439546695680 https://twitter.com/mholt6/status/1657133439546695680
- reqrbHVPetKGE57 3y agoPlease name a platform where `open` will treat a non-link as a link? I just tested the ones I have access to and none did.
- deleted 3y ago[deleted]
- SCUSKU 3y agoWow this is scary. This really drives the point home, I wasn't sure with OP's article but this convinced me.
- psacawa 3y agoA phishing strategy this enables: confusing the https:// https:// URI scheme with the file:// pseudo-URI scheme. For example, we receive a phishing email which reads "This is the bank with your financial statement attached. It's a password protected zip file encrypted with your online banking credentials for security." We click to download and end up at https://financialstatement.zip https://financialstatement.zip, where a JS prompt asks us for the decryption password. We think we're interacting with the file system and get owned. Crucially, i) some browsers don't display the URI scheme in the address bar, and ii) people are used to the idea of a password-protected zip file, and iii) people are used to opening files with their browser.
- psacawa 3y agoThe website can further strengthen the illusion of interacting with the FS by using HTML+CSS that imitates the browser's builtin file browser. It knows what it might look like by examining User-Agent and Accept-Language headers.
- benatkin 3y agoAnyone can do that now. <a href="https://anydomainname.com/">financialstatement.zip</a> If it's a plain text email, attachments show up in a separate area. If it's an HTML email, you could potentially fake the attachment area with or without a .zip TLD, just by adding a carefully constructed image.
- thefifthsetpin 3y agoThat's not going to get through even the most rudimentary anti-phishing filters, and at least some email clients still hint to you what's going to happen when merely hovering over that link.
- pimlottc 3y agoWhy is Google involved in something like this in the first place?
- javajosh 3y agoBecause they haven't bought ARIN and ICANN yet? Sorry, that's a bit too cynical perhaps but it's the same reason Google spends perhaps hundreds of millions of dollars on Chromium that they give away: vertical integration. They want to own every component required for your online experience, from hardware, os, browser, and hidden infrastructure like DNS. It's a slow-moving battle with Microsoft and Apple, who have similar goals. (Not really sure what FB is doing - trying to do an end-run with Meta and Oculus I suppose. Which takes guts, but will probably fail.) It's eye-opening to read about, for example, the stated geopolitical goals of the United States, who like every nation-state seeks total invulnerability, which in turn requires total dominance. Individuals aren't used to thinking in these terms - its extremely unsentimental and matter-of-fact game theory stuff that will curdle milk. TBH I'm guessing. I don't really see how expansion of tlds helps Google with this goal - maybe they just want more namespace to control as a registar? That doesn't make sense. Hopefully I've nerd-sniped someone who knows more.
- m4jor 3y agoIt's cheap to do. I think to apply for a TLD it's only like ~$185k and you get your $ back if your application is denied. Probably something fresh and some PR for their Google Domains department or etc.
- deleted 3y ago[deleted]
- AviationAtom 3y agoFun read about the usage of CORP as the default domain for Windows Active Directory domains and the chaos that might have come had Microsoft not ponied up for the domain: https://krebsonsecurity.com/2020/02/dangerous-domain-corp-com-goes-up-for-sale/ https://krebsonsecurity.com/2020/02/dangerous-domain-corp-co...
- 8organicbits 3y agoWhat's the legitimate reason we need a .zip TLD? Namecheap says: > Why choose a .ZIP domain? > Build your brand fast with a .zip. The .zip top-level domain (TLD) is the perfect fit for organizations specializing in file sharing, storage, and download technology, or for anyone offering speedy and efficient online service. > Is a .ZIP domain extension right for me? > Use your .zip TLD to showcase your expertise in the field of file compression software or impress your clients with turbo-charged customer service. Really? https://www.namecheap.com/domains/registration/gtld/zip/ https://www.namecheap.com/domains/registration/gtld/zip/
- bandyaboot 3y agoThere is only one correct solution to this. It's to completely remove any and all of these egregious filename extension TLDs with no questions asked, and punish the people who pushed for this. I’m really curious to know what this person has in mind.
- phpnode 3y agoThat is definitely not the solely correct solution and I’m really curious to know what kind of punishment you think is appropriate here.
- bandyaboot 3y agoThe first paragraph was a quote from the website which I mistakenly didn’t indicate as a quote. My question was the same as the one you’re asking.
- andrewstuart 3y agoIt’s a weird tld given that zip files are a key malware and hacking vector.
- iforgotpassword 3y agoHuh, I clicked on news.ycombinator.com the other day thinking I'd launch an MS-DOS application and ended up here. Have been stuck posting comments ever since.
- fareesh 3y agoSame argument could be made for .com Speaking of which, who owns command.com ?
- syngrog66 3y agoabout as wise as having ".EXE" as a TLD
- NotYourLawyer 3y ago> Throughout the 2010s, Google has easily been one of the most insidiously corrupting forces on the internet, rivaled by none. Its takeover of the modern web through utter domination of the search engine market, chokehold over web standards, and near complete monopolization of web browsers has rendered much of the world beholden to it. Preach!
- alecbz 3y agoI think I'd find this page much more convincing without the moralism and general anti-Google commentary. I'd be much more persuaded by a direct, simple explanation of the security hole here. That might because I don't think Google is evil (I'm biased because I used to work there), but I think even if I did, a dispassionate description of the problem would be as or more persuasive.
- SoftTalker 3y agoThe original mistake was tieing filename "extensions" to content. A ".zip" is just four characters at the end of the filename. It conventionally means it's a ZIP compressed file, but it could contain anything. Same with any other filename, .pdf, .doc, .wav, .jpg, etc. They are conventions but that's all they are.
- diebeforei485 3y agoSome of the ccTLD's have gone way up in price (especially the .ai domain, which was around $20 but I cancelled when I saw it would cost nearly $150 to renew). To some extent this has also affected the popular .io domains. I've instead gone with .dev for my personal domain. It was a bit annoying updating my email everywhere, but I'm a lot happier with this.
- jacooper 3y agoPersonally i see country-TLDs to be a great choice for personal domains/blogs. Unless you're migrating soon, you are always going to be citizen of that country.
- graiz 3y agoOn windows you can have a .com file as an attachment too. Should we ban .com sites? Is the issue that you can fool people to open a website rather than a file? I'm not sure I follow how a TLD makes that easier. Even if you didn't have a top level TLD a non-experienced user isn't going to be able to tell because they don't look at file extensions anyway, just change the FAV icon and you're set.
- RektBoy 3y agoWho cares anyway? Old people or young people, doesn't matter. Everyone WANTS to be scammed. Because they're scared too much, or they're greedy or they respect authorities too much. Disable zip TLD and you left with like 100million ways how to scam people. What did you actually achieve?
- dmcq2 3y agoThey'd obviously hate me too! I've got directories called <name>.html which have an index.html in them which I use to have an equivalent to <name.pdf with all the image files and fonts included in them. But yes it does seem like troublemking to have a .zip directory that doesn't act like a zip file
- arlattimore 3y agoWhen this TLD was announced, I was honestly shocked that someone suggested it and that it was approved - seems like such a daft idea to me to even entertain the idea of adding more confusion in this space.
- trollian 3y agoStandard PC executables end in .com, so we should probably get rid of that one too. Maybe Poland should change its name so Perl programmers don't get confused.
- ipaddr 3y agoCan't wait for the .exe extention or the null extension .
- WirelessGigabit 3y agoThis reminds me of when eBay had '.dll' in their URL and our overzealous webfilter thought we were downloading a '.dll' versus trying to win the bid on that highly coveted Pokemon card.
- mgaunard 3y ago.com is also a valid file extension. Just learn to parse a URI.
- deleted 3y ago[deleted]
- varenc 3y agoI feel like the core message on this page is really weakened by including a broader critique of Google. It shouldn't matter who owns the TLD. Even if Google wasn’t the .zip owner, or if you don’t believe they’re an insidiously corrupting force, you can still agree that .zip domains are overly confusing and ripe for abuse and attacks. This argument stands on its own, and focusing on the Google aspect just muddles the issue. (Though I agree with some of the sentiment)
- jacobsenscott 3y agoIf you've been using .foo in your tests or whatever, that's on you. You shouldn't have a license to work on software that touches a network if you haven't seen https://www.rfc-editor.org/rfc/rfc2606 https://www.rfc-editor.org/rfc/rfc2606
- deleted 3y ago[deleted]
- biofunsf 3y agoThis page is 90% an inflammatory rant again Google. Why does it matter who owns .zip? These domains can be abused no matter what. This page is almost actively harmful to the cause by making it seem like the entire motivation is just being anti-Google. edit: I found Google's application to ICANN for the .zip gTLD. Abuse is mentioned a bunch but it seems pretty boiler plate. I don't yet see anything acknowledging the risk of .zip domains in particular: https://gtldresult.icann.org/applicationstatus/applicationdetails/535 https://gtldresult.icann.org/applicationstatus/applicationde... (pointing out something lacking in Google's .zip gTLD application seems a stronger footing for getting ICANN to take action)
- jug 3y agoI agree. This is pretty terrible because it even circumvents what has so far been assumed to be "safe" methods of reading e-mail -- by stripping them down to plain text. Even avoiding <a href="actual">fake</a> attacks won't help by showing "actual" because that will be the attack vector itself. Ugh!!
- dools 3y agoI don’t see what additional attacks this enables.
- hgs3 3y agoThere is an excellent explanation on proggit [1] that describes an attack vector for .zip TLDs. More specifically, it explains how a trusted source might inadvertently link to a malicious file. [1] https://reddit.com/r/programming/comments/13fsvl5/the_zip_tld_sucks_and_it_needs_to_be_immediately/jjxivcp/ https://reddit.com/r/programming/comments/13fsvl5/the_zip_tl...