3 ms·
I assume this is supposed to be somewhat tongue-in-cheek, because the argument that SoMeThInG mUsT bE dOnE aBoUt DnS because a whopping 10% of registrations wer
by 1dom 1mo ago
I assume this is supposed to be somewhat tongue-in-cheek, because the argument that SoMeThInG mUsT bE dOnE aBoUt DnS because a whopping 10% of registrations were associated with spam/scams seems silly.
There are lots of large open systems that the average person interacts with daily that would love to see <30% spam/scam volume:
- email
- paper mail
- telephone numbers
- SMS messages
- basically any social media platform
> I don't want to live in a world where I have to show my passport and pay thousands of pounds to register a domain which is only available after being vetted by private interests. But I also don't want to live in a world where scammers have effectively no deterrent from abusing millions of people.
One solution would be to have recognised verified TLDs that require some verification on some, whilst allowing others to be more lax an accessibel. The issue is we have these, e.g. .gov.uk.
Another solution would be to dissuade people from using less well known gtlds in favour of ones that have some sort of limits/controls, such as recommending people avoid .mobi domains in favour of ones with more oversight like .com. (I say this as someone with a .fun personal domain!)
I don't know. I'm not saying this isn't a problem, I'm just saying that Terence kicking this nest seems like the start of some monkey paw meme or something.
- edent 1mo agoThere are some gTLDs like .bank which require a high level of verification. The applicant has to be a financial institution etc. The problem is twofold. I've never seen a .bank domain in the wild and users generally don't looks at the TLD. Would people be fooled by "bank.uk-natwset.com"? Probably. I agree with you that this is definitely in be careful what you wish for territory.
- 1dom 1mo agoAll good thoughts, thanks for the response! Maybe the solution is in the offline world. A government funded public service announcement of tv/radio/print/busstop ads saying stuff like "never do government stuff not on .gov, never do banking stuff not on .bank". I think that would be highly effective for the sort of people who need the protection here. It would obviously require banks and gov departments to get their ducks in a row first which is a whole other problem in itself, but it might still turn out to be an economically viable improvement.
- edent 1mo agoI agree in those specific cases (and I've spent a long time inside Government trying to encourage more adoption of .gov.uk and .NHS.uk). But when you get a text with "your Amazon parcel is delayed plz visit amazaoncom.parcel-delay.info", that looks pretty official to most people.
- 1dom 1mo agoYeah, I totally agree. I think there's no 1-size-fit-all solution. I think the problem should shift onto "how many solutions do we need"? At least 2 I'd guess: 1 is going to be incomprehensibly hard and painful compared to now, but there will be maybe only a few handfuls per country. Sure you have to sacrifice your first newborn, but it will come with the full weight of government PSAs because lots of normal and vulnerable citizens depend on it. The other solution matters less so, because it's could all just be optional/nice to have things, and if people want them, they have to accept some amount of risk/competency in exchange for easy of access. The current solution getting only <50% spam/scam seems to be doing better than traditional mediums so is probably fine for that group. Maybe there's some more measure solutions between the 2 extremes, but I really don't think there can or should be 1 fix for the DNS system given the range of use cases and customers. Regardless, Dave down at the local is always going to panic click amazaoncom.paercel-delay.info regardless of what the local bus stop ad or government tell him to do. Such a Dave thing to do.
- mildred593 1mo agoThe opposite issue I had was that I already flagged as spam mails with domains that look like this (not using the official domain) only to discover later that it was legitimate when I connected.
- elcritch 1mo agoThe UX of DNS would need to be swapped with the gTLD going first. Perhaps more practical would be browsers noting the gTLD as an important piece of information. Perhaps a “Bank” tag for .bank urls.
- edent 1mo agoI dont see how org.ukpaynatwest-online is any easier to spot as a scam. Take a look at many of the domains you see in phishing emails / texts. They're all pretty obvious if you spend all day looking at domains and considering their provenance. Most people don't. I like the idea of highlighting the TLD - but I do wonder if it would just become an expensive boondoggle like EV Certificates.