4 ms·
A big reason why .top is used so much is because it is so cheap. Phishers can rotate through many more domains using .top compared to other domains. IMO this i
by nulld3v 2y ago
A big reason why .top is used so much is because it is so cheap. Phishers can rotate through many more domains using .top compared to other domains.
IMO this isn't a particularly big problem, it's cool to let people buy cheap domains. It also doesn't really save the phishers that much money. You aren't going to solve the problem by making domains more expensive, it might impact phishers' margins but they will continue phishing.
- Retr0id 2y agoImpacting phishers' margins is all we can do, really.
- inetknght 2y agoStronger investigative and enforcement actions is something we can do. But it's something that we don't stomach. I wonder why. I suppose it's because the modern business-centric Internet is centered on the ability to scam people out of money. Investigations and enforcements would open the floodgates to every "normal" business too.
- mschuster91 2y agoThe problem is it's cross-border. Domestic law enforcement will almost always run into dead ends, maybe they'll catch some money mule that got conned into the job, but that's it. The real dent would be to get India (for US scammers) and Turkey (for German scammers) to cooperate, the way to do it would be to threaten devastating sanctions ("clean up your scammer scenes, or else"), but that cannot be done as it is important for geopolitical reasons to appease India (a significant portion of the world's pharmaceutical base compounds originate from there, not to mention the Ukraine conflict) and Turkey (same reason, Ukraine conflict + about 2 million Syrian refugees that Erdogan already abused as a political weapon once).
- inetknght 2y ago> The problem is it's cross-border That's a feature. And the great thing of this feature is that it's opt-out. You can block connections from outside of jurisdictions you care about.
- Cyphase 2y agoRelated: https://www.bitsaboutmoney.com/archive/optimal-amount-of-fraud/ https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra... > To prevent this conversation from being painfully abstract, let’s scope it to one particular type of fraud against one particular type of actor: the bad guy steals a payment credential, like a credit card number, and uses it to extract valuable goods or services from a business. This is an extremely common fraud, costing the world something like $10 to $20 billion a year, and yet it is actually fairly constrained relative to all types of fraud. > This fraud is possible by design. The very best minds in government, the financial industry, the payments industry, and business have gotten together and decided that they want this fraud to be possible. That probably strikes you as an extraordinary claim, and yet it is true.
- inetknght 2y agoIndeed! However, I would add that this article focuses on fraud perpetrated against businesses. While it does give good perspective I'm actually more concerned about fraud perpetrated by internet businesses against consumers.
- adsarescams 2y ago> I suppose it's because the modern business-centric Internet is centered on the ability to scam people out of money. Shhh, dont say the quiet part loud. The fact the internet is a pyramid scheme is supposed to be a "conspiracy".
- smolder 2y ago> "conspiracy" A better term here would be "fringe theory", since it's unclear who would even be conspiring.
- creeble 2y agoBut it’s somethhing that happens too late. Phishers benefit from low domain prices because they can churn them faster than you can investigate them. Scams are fast, investigation slow. Worse, you investigate only to find that the scammer is out of your jurisdiction (which I submit is the #1 problem with “enforcement”) and there is very little you can do. Also, if they can churn domains quickly, the thread that connects them is harder to find, so you only have the remnants of one or two scam domains where there may be hundreds more by the same perpetrator.
- efilife 2y agoAnd harm everyone else who wants a cheap domain.
- Retr0id 2y agoIf they can't price-in effective anti-abuse measures, then maybe the price should be higher.
- efilife 2y agoLet's not punish normal people because others scam. Punish the scammers
- lolinder 2y agoI'm sure we're all open to suggestions. How would you go about punishing scammers in arbitrary jurisdictions while still allowing responsible individuals in arbitrary jurisdictions to buy domains? We normally settle on "have an anti-abuse team and charge money for domains to pay for them" as the least-bad option, but if you have a better idea I'm all ears.
- Xelynega 2y agoHow does that make any sense? If increasing the price hasn't decreased the abuse, why would increasing it more decrease the abuse?
- chedabob 2y agoWhen we went to war against someone using our name in a recruitement scam, by the time they moved on, it seemed like they were up 5x on what it costs them in domains. It's all heavily automated, and I suspect there's some credit card fraud involved too. I also reckon there's a few unscrupulous registrars that are helping them.