The purpose of DNS is to spread scams
Posted by CoderLim110 1 day ago
Comments
Comment by tancop 1 day ago
You start out at "suspicious" and gain trust with time. Collisions with well known names or high outgoing traffic give you a penalty but you can defeat it with enough positive votes. Domain owners with a high score would be able to vouch for other domains with an entry in `.well-known` and get them to high status faster, with penalties if they end up being scams to prevent "trust as a service" operations.
I don't know who we can trust to manage it. Mozilla can't really do it alone, Apple and Microsoft are good candidates but Google is actively making money from scams and they would try to push for ID verification if they joined.
Comment by elcritch 1 day ago
The better solution is smarter LLM filters. Most of these scams are incredibly obvious and rely on human frailty. Essentially the elderly, exhausted parents, stressed students at finals, etc.
Alternatively Apple and Android should make it easier to set DNS and content filters but not be able to provide those services themselves.
Comment by nottorp 1 day ago
Next: I don't want to live in a world where I have to show my passport and pay thousands of pounds to register a domain
Want or not want?
Plus the 900 in escrow shows a very US centric view. It's only like three Starbucks lattes over there with the current inflation right?
Comment by edent 1 day ago
As for the contradictions - yes. There's a famous aphorism "It is the mark of an educated mind to be able to entertain a thought without accepting it."
I think it is important to explore a problem and its possible solutions. It allows you to work where the issues are and prevents people saying "why didn't you consider…?".
Comment by nottorp 1 day ago
Guess 900 is 2.5 Starbucks lattes in London :)
> who is handsome
How is that relevant?
Comment by scratcheee 1 day ago
Perhaps more importantly, the “handsome and talented” sidebar was actually a tongue in cheek acknowledgment that the author himself was speaking, I suspect, compare the usernames and they match up suspiciously well.
Comment by x1798DE 1 day ago
Comment by nottorp 1 day ago
Which is why I was triggered by "handsome" too.
Comment by tancop 1 day ago
Comment by 1dom 1 day ago
There are lots of large open systems that the average person interacts with daily that would love to see <30% spam/scam volume:
- email - paper mail - telephone numbers - SMS messages - basically any social media platform
> I don't want to live in a world where I have to show my passport and pay thousands of pounds to register a domain which is only available after being vetted by private interests. But I also don't want to live in a world where scammers have effectively no deterrent from abusing millions of people.
One solution would be to have recognised verified TLDs that require some verification on some, whilst allowing others to be more lax an accessibel. The issue is we have these, e.g. .gov.uk.
Another solution would be to dissuade people from using less well known gtlds in favour of ones that have some sort of limits/controls, such as recommending people avoid .mobi domains in favour of ones with more oversight like .com. (I say this as someone with a .fun personal domain!)
I don't know. I'm not saying this isn't a problem, I'm just saying that Terence kicking this nest seems like the start of some monkey paw meme or something.
Comment by edent 1 day ago
The problem is twofold. I've never seen a .bank domain in the wild and users generally don't looks at the TLD.
Would people be fooled by "bank.uk-natwset.com"? Probably.
I agree with you that this is definitely in be careful what you wish for territory.
Comment by 1dom 1 day ago
Maybe the solution is in the offline world. A government funded public service announcement of tv/radio/print/busstop ads saying stuff like "never do government stuff not on .gov, never do banking stuff not on .bank". I think that would be highly effective for the sort of people who need the protection here.
It would obviously require banks and gov departments to get their ducks in a row first which is a whole other problem in itself, but it might still turn out to be an economically viable improvement.
Comment by edent 1 day ago
But when you get a text with "your Amazon parcel is delayed plz visit amazaoncom.parcel-delay.info", that looks pretty official to most people.
Comment by 1dom 1 day ago
At least 2 I'd guess: 1 is going to be incomprehensibly hard and painful compared to now, but there will be maybe only a few handfuls per country. Sure you have to sacrifice your first newborn, but it will come with the full weight of government PSAs because lots of normal and vulnerable citizens depend on it.
The other solution matters less so, because it's could all just be optional/nice to have things, and if people want them, they have to accept some amount of risk/competency in exchange for easy of access. The current solution getting only <50% spam/scam seems to be doing better than traditional mediums so is probably fine for that group.
Maybe there's some more measure solutions between the 2 extremes, but I really don't think there can or should be 1 fix for the DNS system given the range of use cases and customers.
Regardless, Dave down at the local is always going to panic click amazaoncom.paercel-delay.info regardless of what the local bus stop ad or government tell him to do. Such a Dave thing to do.
Comment by mildred593 23 hours ago
Comment by elcritch 1 day ago
Perhaps more practical would be browsers noting the gTLD as an important piece of information. Perhaps a “Bank” tag for .bank urls.
Comment by edent 1 day ago
Take a look at many of the domains you see in phishing emails / texts. They're all pretty obvious if you spend all day looking at domains and considering their provenance. Most people don't.
I like the idea of highlighting the TLD - but I do wonder if it would just become an expensive boondoggle like EV Certificates.
Comment by vkaku 1 day ago
Scams are run by state sponsored actors and intelligence agencies and their targets are often regular people who have nothing to do with any of this.
You can say whatever you want, DNS is the only thing preventing control by all governments. If that locks down, you find see more people pushing for alt root servers and other ways to get out of there. What might actually help is tracking finances of government agencies and the few people who are often funding all these illicit activities.
Ill-devised Internet control movements will make everything incredibly difficult to reconcile back to. Parts of the world are already creating and using their own systems for this, and further DNS control will lead to even wider adoption of Alternative DNS Roots such as OpenNIC or Handshake even. (See https://en.wikipedia.org/wiki/Alternative_DNS_root )
Eventually, given that and a list of alternative certificate authorities, we will end up with a permanently forked internet where the only saving grace might be the protocols themselves and nothing more. Some companies are already creating a way to send a list of trusted CAs via their DHCP infrastructure already (See https://info.support.huawei.com/info-finder/encyclopedia/en/... ) so I can totally see loss of control happening in the upcoming years.
You heard it here first.
Comment by sparkling 1 day ago
I feel to some degree governments are also responsible for this, by not making consistent use of *.gov domains.
Take for example sunbiz.org, the Florida business register. For 20+ years sunbiz.org was the official domain, until they switched to dos.fl.gov in 2023. The average joe may have heard about "Sunbiz", but was the domain sunbiz.com, sub.biz, sunbiz.net ... who knows?? How would anyone know? All of this could have been avoided by using *.gov everywhere in the first place.
Comment by OroPla 1 day ago
Though, seeing how there are now even more of them than there used to be, I guess that's not feasible.
Comment by ButlerianJihad 1 day ago