4 ms·
There are some gTLDs like .bank which require a high level of verification. The applicant has to be a financial institution etc. The problem is twofold. I've n
by edent 19d ago
There are some gTLDs like .bank which require a high level of verification. The applicant has to be a financial institution etc.
The problem is twofold. I've never seen a .bank domain in the wild and users generally don't looks
at the TLD.
Would people be fooled by "bank.uk-natwset.com"? Probably.
I agree with you that this is definitely in be careful what you wish for territory.
- 1dom 19d agoAll good thoughts, thanks for the response! Maybe the solution is in the offline world. A government funded public service announcement of tv/radio/print/busstop ads saying stuff like "never do government stuff not on .gov, never do banking stuff not on .bank". I think that would be highly effective for the sort of people who need the protection here. It would obviously require banks and gov departments to get their ducks in a row first which is a whole other problem in itself, but it might still turn out to be an economically viable improvement.
- edent 19d agoI agree in those specific cases (and I've spent a long time inside Government trying to encourage more adoption of .gov.uk and .NHS.uk). But when you get a text with "your Amazon parcel is delayed plz visit amazaoncom.parcel-delay.info", that looks pretty official to most people.
- 1dom 19d agoYeah, I totally agree. I think there's no 1-size-fit-all solution. I think the problem should shift onto "how many solutions do we need"? At least 2 I'd guess: 1 is going to be incomprehensibly hard and painful compared to now, but there will be maybe only a few handfuls per country. Sure you have to sacrifice your first newborn, but it will come with the full weight of government PSAs because lots of normal and vulnerable citizens depend on it. The other solution matters less so, because it's could all just be optional/nice to have things, and if people want them, they have to accept some amount of risk/competency in exchange for easy of access. The current solution getting only <50% spam/scam seems to be doing better than traditional mediums so is probably fine for that group. Maybe there's some more measure solutions between the 2 extremes, but I really don't think there can or should be 1 fix for the DNS system given the range of use cases and customers. Regardless, Dave down at the local is always going to panic click amazaoncom.paercel-delay.info regardless of what the local bus stop ad or government tell him to do. Such a Dave thing to do.
- mildred593 19d agoThe opposite issue I had was that I already flagged as spam mails with domains that look like this (not using the official domain) only to discover later that it was legitimate when I connected.
- elcritch 19d agoThe UX of DNS would need to be swapped with the gTLD going first. Perhaps more practical would be browsers noting the gTLD as an important piece of information. Perhaps a “Bank” tag for .bank urls.
- edent 19d agoI dont see how org.ukpaynatwest-online is any easier to spot as a scam. Take a look at many of the domains you see in phishing emails / texts. They're all pretty obvious if you spend all day looking at domains and considering their provenance. Most people don't. I like the idea of highlighting the TLD - but I do wonder if it would just become an expensive boondoggle like EV Certificates.