5 ms·
The real answer is that trust isn't needed, because you just shouldn't use it. You know that 7-zip.org is the official site. You see that's where you end up af
by hyperhopper 3y ago
The real answer is that trust isn't needed, because you just shouldn't use it.
You know that 7-zip.org is the official site. You see that's where you end up after the redirect. Just bookmark and use that. No reason to add more steps.
- calvinmorrison 3y agoThe real answer is: trust is not a problem that can ever be fully mitigated by smart technology and that's why we depend on things like the wonderful package maintainers of debian and other projects to do due diligence for the rest of us!
- tstrimple 3y agoEven typing in a domain you know can be fraught. There are still plenty of popular domains with common typos registered by shady people. Most of them I encounter tend to be spam sites rather than maliciously impersonating the site they are trying to steal traffic from but that's not a far leap. See https://news.ycombinator.co https://news.ycombinator.co
- euroderf 3y agountil a Node coder withdraws a tiny-but-widely-referenced package.
- planede 3y agoThat might be the real answer, but not very satisfactory, as it suggests that this domain just shouldn't exist. At least 7-zip.org could have a list of domains that they own and control if they wish people to use these alternate domains.
- gibspaulding 3y ago> if they wish people to use these alternate domains I would have assumed the main reason to register alternate domains like this would not be so people can use them, but rather to prevent others registering them and abusing them.
- planede 3y agoMaybe, then it serves that purpose (if it's indeed their domain). But why redirect then or even point them to an HTTP server? Anyway, I would never choose to fight this battle, feels rather futile. It doesn't help that they have a dash in the name, so they have to hunt down names with 7-zip and 7zip as well.
- JohnFen 3y agoThat's the only reason that I have done it with my domains. I don't use a redirect, though, I just have the DNS records resolve all the alternate domains to the same IP address.
- bmacho 3y ago> You know that 7-zip.org is the official site. How would I know that, tho? What if 7-zip.com is the official, and 7-zip.com is a similar site with a malware?
- HelloNurse 3y agoThe squatters just need to start saying that "seven.zip" is the new home page and 7-zip.org is deprecated instead of redirecting. It only takes some SEO to make it look plausible for many users who trust Google and see "seven.zip" as the first search result.
- freedomben 3y agothen you address it by reporting/complaining. It's already perfectly possible to do that, the only change here is a name. I'm sure there's also phishing detection (that will certainly improve with ML) that can help too. either way, what's the solution to prevention? disallow the entire TLD and every possible TLD that could lead to phishing? there are already plenty of issues with .com being used for phishing. have a regulatory body do ID verification of every registrant and if it sounds like a domain that could possibly be misused then ... what?
- AstralStorm 3y agoSaid malware would also have to be code signed with the 7-zip authors' code signing certificate. However, if you're downloading it for the first time, you wouldn't know what that correct value is.
- esquivalience 3y agoJust wanted to point out that trust is already embedded in your scenario: where you say "you know", that really means that you trust, based on experience. The experience that gives rise to that knowledge is the same sort of thing that gives rise to the attack vector being suggested here.
- pjmlp 3y agoExcept the way most people end up with malware is searching for software and downloading the first result they can find.
- s3p 3y agoThe real answer is that .zip should never have been allowed as a TLD.
- _8j50 3y agoSelective/targeted redirection is possible based on geography,client.etc....