Rendered at 12:29:45 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
tancop 1 hours ago [-]
I think the only reasonable and fair solution is building a reputation system on top of DNS. Browsers and message apps would show a warning if the score for a domain is low and completely block those that are rated "known scam" unless you turn on developer settings.
You start out at "suspicious" and gain trust with time. Collisions with well known names or high outgoing traffic give you a penalty but you can defeat it with enough positive votes. Domain owners with a high score would be able to vouch for other domains with an entry in `.well-known` and get them to high status faster, with penalties if they end up being scams to prevent "trust as a service" operations.
I don't know who we can trust to manage it. Mozilla can't really do it alone, Apple and Microsoft are good candidates but Google is actively making money from scams and they would try to push for ID verification if they joined.
nottorp 2 hours ago [-]
First: Registrars could ask for an escrow payment. Pay €9 for the domain name put €900 in escrow
Next: I don't want to live in a world where I have to show my passport and pay thousands of pounds to register a domain
Want or not want?
Plus the 900 in escrow shows a very US centric view. It's only like three Starbucks lattes over there with the current inflation right?
edent 52 minutes ago [-]
The author (who is handsome and talented) is based in the UK - so tries hard not to be US centric. Hence the use of €.
As for the contradictions - yes. There's a famous aphorism "It is the mark of an educated mind to be able to entertain a thought without accepting it."
I think it is important to explore a problem and its possible solutions. It allows you to work where the issues are and prevents people saying "why didn't you consider…?".
nottorp 5 minutes ago [-]
> is based in the UK
Guess 900 is 2.5 Starbucks lattes in London :)
> who is handsome
How is that relevant?
tancop 1 hours ago [-]
I see the article as saying there is no easy fix that can fully remove scams without also making it expensive to register a domain, or even dangerous if your ID becomes public. These things are supposed to contradict each other because they contradict in real life.
1dom 52 minutes ago [-]
I assume this is supposed to be somewhat tongue-in-cheek, because the argument that SoMeThInG mUsT bE dOnE aBoUt DnS because a whopping 10% of registrations were associated with spam/scams seems silly.
There are lots of large open systems that the average person interacts with daily that would love to see <30% spam/scam volume:
- email
- paper mail
- telephone numbers
- SMS messages
- basically any social media platform
> I don't want to live in a world where I have to show my passport and pay thousands of pounds to register a domain which is only available after being vetted by private interests. But I also don't want to live in a world where scammers have effectively no deterrent from abusing millions of people.
One solution would be to have recognised verified TLDs that require some verification on some, whilst allowing others to be more lax an accessibel. The issue is we have these, e.g. .gov.uk.
Another solution would be to dissuade people from using less well known gtlds in favour of ones that have some sort of limits/controls, such as recommending people avoid .mobi domains in favour of ones with more oversight like .com. (I say this as someone with a .fun personal domain!)
I don't know. I'm not saying this isn't a problem, I'm just saying that Terence kicking this nest seems like the start of some monkey paw meme or something.
edent 32 minutes ago [-]
There are some gTLDs like .bank which require a high level of verification. The applicant has to be a financial institution etc.
The problem is twofold. I've never seen a .bank domain in the wild and users generally don't looks
at the TLD.
Would people be fooled by "bank.uk-natwset.com"? Probably.
I agree with you that this is definitely in be careful what you wish for territory.
1dom 14 minutes ago [-]
All good thoughts, thanks for the response!
Maybe the solution is in the offline world. A government funded public service announcement of tv/radio/print/busstop ads saying stuff like "never do government stuff not on .gov, never do banking stuff not on .bank". I think that would be highly effective for the sort of people who need the protection here.
It would obviously require banks and gov departments to get their ducks in a row first which is a whole other problem in itself, but it might still turn out to be an economically viable improvement.
sparkling 5 hours ago [-]
The (refundable) escrow payment would indeed be a possible solution.
I feel to some degree governments are also responsible for this, by not making consistent use of *.gov domains.
Take for example sunbiz.org, the Florida business register. For 20+ years sunbiz.org was the official domain, until they switched to dos.fl.gov in 2023. The average joe may have heard about "Sunbiz", but was the domain sunbiz.com, sub.biz, sunbiz.net ... who knows?? How would anyone know? All of this could have been avoided by using *.gov everywhere in the first place.
ButlerianJihad 1 hours ago [-]
I can always count on Springfield.GOV for current nuclear plant status
You start out at "suspicious" and gain trust with time. Collisions with well known names or high outgoing traffic give you a penalty but you can defeat it with enough positive votes. Domain owners with a high score would be able to vouch for other domains with an entry in `.well-known` and get them to high status faster, with penalties if they end up being scams to prevent "trust as a service" operations.
I don't know who we can trust to manage it. Mozilla can't really do it alone, Apple and Microsoft are good candidates but Google is actively making money from scams and they would try to push for ID verification if they joined.
Next: I don't want to live in a world where I have to show my passport and pay thousands of pounds to register a domain
Want or not want?
Plus the 900 in escrow shows a very US centric view. It's only like three Starbucks lattes over there with the current inflation right?
As for the contradictions - yes. There's a famous aphorism "It is the mark of an educated mind to be able to entertain a thought without accepting it."
I think it is important to explore a problem and its possible solutions. It allows you to work where the issues are and prevents people saying "why didn't you consider…?".
Guess 900 is 2.5 Starbucks lattes in London :)
> who is handsome
How is that relevant?
There are lots of large open systems that the average person interacts with daily that would love to see <30% spam/scam volume:
- email - paper mail - telephone numbers - SMS messages - basically any social media platform
> I don't want to live in a world where I have to show my passport and pay thousands of pounds to register a domain which is only available after being vetted by private interests. But I also don't want to live in a world where scammers have effectively no deterrent from abusing millions of people.
One solution would be to have recognised verified TLDs that require some verification on some, whilst allowing others to be more lax an accessibel. The issue is we have these, e.g. .gov.uk.
Another solution would be to dissuade people from using less well known gtlds in favour of ones that have some sort of limits/controls, such as recommending people avoid .mobi domains in favour of ones with more oversight like .com. (I say this as someone with a .fun personal domain!)
I don't know. I'm not saying this isn't a problem, I'm just saying that Terence kicking this nest seems like the start of some monkey paw meme or something.
The problem is twofold. I've never seen a .bank domain in the wild and users generally don't looks at the TLD.
Would people be fooled by "bank.uk-natwset.com"? Probably.
I agree with you that this is definitely in be careful what you wish for territory.
Maybe the solution is in the offline world. A government funded public service announcement of tv/radio/print/busstop ads saying stuff like "never do government stuff not on .gov, never do banking stuff not on .bank". I think that would be highly effective for the sort of people who need the protection here.
It would obviously require banks and gov departments to get their ducks in a row first which is a whole other problem in itself, but it might still turn out to be an economically viable improvement.
I feel to some degree governments are also responsible for this, by not making consistent use of *.gov domains.
Take for example sunbiz.org, the Florida business register. For 20+ years sunbiz.org was the official domain, until they switched to dos.fl.gov in 2023. The average joe may have heard about "Sunbiz", but was the domain sunbiz.com, sub.biz, sunbiz.net ... who knows?? How would anyone know? All of this could have been avoided by using *.gov everywhere in the first place.