I think the only reasonable and fair solution is building a reputation system on top of DNS. Browsers and message apps would show a warning if the score for a domain is low and completely block those that are rated "known scam" unless you turn on developer settings.
You start out at "suspicious" and gain trust with time. Collisions with well known names or high outgoing traffic give you a penalty but you can defeat it with enough positive votes. Domain owners with a high score would be able to vouch for other domains with an entry in `.well-known` and get them to high status faster, with penalties if they end up being scams to prevent "trust as a service" operations.
I don't know who we can trust to manage it. Mozilla can't really do it alone, Apple and Microsoft are good candidates but Google is actively making money from scams and they would try to push for ID verification if they joined.
We’d just end up in the same situation email has where only the big email providers can reliably send email.
The better solution is smarter LLM filters. Most of these scams are incredibly obvious and rely on human frailty. Essentially the elderly, exhausted parents, stressed students at finals, etc.
Alternatively Apple and Android should make it easier to set DNS and content filters but not be able to provide those services themselves.
Oh, look, more state sponsored control propaganda disguised as protection.
Scams are run by state sponsored actors and intelligence agencies and their targets are often regular people who have nothing to do with any of this.
You can say whatever you want, DNS is the only thing preventing control by all governments. If that locks down, you find see more people pushing for alt root servers and other ways to get out of there. What might actually help is tracking finances of government agencies and the few people who are often funding all these illicit activities.
Ill-devised Internet control movements will make everything incredibly difficult to reconcile back to. Parts of the world are already creating and using their own systems for this, and further DNS control will lead to even wider adoption of Alternative DNS Roots such as OpenNIC or Handshake even. (See https://en.wikipedia.org/wiki/Alternative_DNS_root )
Eventually, given that and a list of alternative certificate authorities, we will end up with a permanently forked internet where the only saving grace might be the protocols themselves and nothing more. Some companies are already creating a way to send a list of trusted CAs via their DHCP infrastructure already (See https://info.support.huawei.com/info-finder/encyclopedia/en/... ) so I can totally see loss of control happening in the upcoming years.
The author (who is handsome and talented) is based in the UK - so tries hard not to be US centric. Hence the use of €.
As for the contradictions - yes. There's a famous aphorism "It is the mark of an educated mind to be able to entertain a thought without accepting it."
I think it is important to explore a problem and its possible solutions. It allows you to work where the issues are and prevents people saying "why didn't you consider…?".
It was in parentheses, that does usually imply irrelevant sideband information.
Perhaps more importantly, the “handsome and talented” sidebar was actually a tongue in cheek acknowledgment that the author himself was speaking, I suspect, compare the usernames and they match up suspiciously well.
I see the article as saying there is no easy fix that can fully remove scams without also making it expensive to register a domain, or even dangerous if your ID becomes public. These things are supposed to contradict each other because they contradict in real life.
I assume this is supposed to be somewhat tongue-in-cheek, because the argument that SoMeThInG mUsT bE dOnE aBoUt DnS because a whopping 10% of registrations were associated with spam/scams seems silly.
There are lots of large open systems that the average person interacts with daily that would love to see <30% spam/scam volume:
- email
- paper mail
- telephone numbers
- SMS messages
- basically any social media platform
> I don't want to live in a world where I have to show my passport and pay thousands of pounds to register a domain which is only available after being vetted by private interests. But I also don't want to live in a world where scammers have effectively no deterrent from abusing millions of people.
One solution would be to have recognised verified TLDs that require some verification on some, whilst allowing others to be more lax an accessibel. The issue is we have these, e.g. .gov.uk.
Another solution would be to dissuade people from using less well known gtlds in favour of ones that have some sort of limits/controls, such as recommending people avoid .mobi domains in favour of ones with more oversight like .com. (I say this as someone with a .fun personal domain!)
I don't know. I'm not saying this isn't a problem, I'm just saying that Terence kicking this nest seems like the start of some monkey paw meme or something.
Maybe the solution is in the offline world. A government funded public service announcement of tv/radio/print/busstop ads saying stuff like "never do government stuff not on .gov, never do banking stuff not on .bank". I think that would be highly effective for the sort of people who need the protection here.
It would obviously require banks and gov departments to get their ducks in a row first which is a whole other problem in itself, but it might still turn out to be an economically viable improvement.
The opposite issue I had was that I already flagged as spam mails with domains that look like this (not using the official domain) only to discover later that it was legitimate when I connected.
Yeah, I totally agree. I think there's no 1-size-fit-all solution. I think the problem should shift onto "how many solutions do we need"?
At least 2 I'd guess: 1 is going to be incomprehensibly hard and painful compared to now, but there will be maybe only a few handfuls per country. Sure you have to sacrifice your first newborn, but it will come with the full weight of government PSAs because lots of normal and vulnerable citizens depend on it.
The other solution matters less so, because it's could all just be optional/nice to have things, and if people want them, they have to accept some amount of risk/competency in exchange for easy of access. The current solution getting only <50% spam/scam seems to be doing better than traditional mediums so is probably fine for that group.
Maybe there's some more measure solutions between the 2 extremes, but I really don't think there can or should be 1 fix for the DNS system given the range of use cases and customers.
Regardless, Dave down at the local is always going to panic click amazaoncom.paercel-delay.info regardless of what the local bus stop ad or government tell him to do. Such a Dave thing to do.
I dont see how org.ukpaynatwest-online is any easier to spot as a scam.
Take a look at many of the domains you see in phishing emails / texts. They're all pretty obvious if you spend all day looking at domains and considering their provenance. Most people don't.
I like the idea of highlighting the TLD - but I do wonder if it would just become an expensive boondoggle like EV Certificates.
The (refundable) escrow payment would indeed be a possible solution.
I feel to some degree governments are also responsible for this, by not making consistent use of *.gov domains.
Take for example sunbiz.org, the Florida business register. For 20+ years sunbiz.org was the official domain, until they switched to dos.fl.gov in 2023. The average joe may have heard about "Sunbiz", but was the domain sunbiz.com, sub.biz, sunbiz.net ... who knows?? How would anyone know? All of this could have been avoided by using *.gov everywhere in the first place.
Or by just not having all these choices. I always found it odd that in the English speaking world you have .org(anization), .com(mmercial), .gov(ernment), .net(work) and maybe more that I can't think of right now, but in other countries, everything is just the country code at the end. (Or one of the English ones is used.)
Though, seeing how there are now even more of them than there used to be, I guess that's not feasible.
I think the only reasonable and fair solution is building a reputation system on top of DNS. Browsers and message apps would show a warning if the score for a domain is low and completely block those that are rated "known scam" unless you turn on developer settings.
You start out at "suspicious" and gain trust with time. Collisions with well known names or high outgoing traffic give you a penalty but you can defeat it with enough positive votes. Domain owners with a high score would be able to vouch for other domains with an entry in `.well-known` and get them to high status faster, with penalties if they end up being scams to prevent "trust as a service" operations.
I don't know who we can trust to manage it. Mozilla can't really do it alone, Apple and Microsoft are good candidates but Google is actively making money from scams and they would try to push for ID verification if they joined.
We’d just end up in the same situation email has where only the big email providers can reliably send email.
The better solution is smarter LLM filters. Most of these scams are incredibly obvious and rely on human frailty. Essentially the elderly, exhausted parents, stressed students at finals, etc.
Alternatively Apple and Android should make it easier to set DNS and content filters but not be able to provide those services themselves.
Oh, look, more state sponsored control propaganda disguised as protection.
Scams are run by state sponsored actors and intelligence agencies and their targets are often regular people who have nothing to do with any of this.
You can say whatever you want, DNS is the only thing preventing control by all governments. If that locks down, you find see more people pushing for alt root servers and other ways to get out of there. What might actually help is tracking finances of government agencies and the few people who are often funding all these illicit activities.
Ill-devised Internet control movements will make everything incredibly difficult to reconcile back to. Parts of the world are already creating and using their own systems for this, and further DNS control will lead to even wider adoption of Alternative DNS Roots such as OpenNIC or Handshake even. (See https://en.wikipedia.org/wiki/Alternative_DNS_root )
Eventually, given that and a list of alternative certificate authorities, we will end up with a permanently forked internet where the only saving grace might be the protocols themselves and nothing more. Some companies are already creating a way to send a list of trusted CAs via their DHCP infrastructure already (See https://info.support.huawei.com/info-finder/encyclopedia/en/... ) so I can totally see loss of control happening in the upcoming years.
You heard it here first.
First: Registrars could ask for an escrow payment. Pay €9 for the domain name put €900 in escrow
Next: I don't want to live in a world where I have to show my passport and pay thousands of pounds to register a domain
Want or not want?
Plus the 900 in escrow shows a very US centric view. It's only like three Starbucks lattes over there with the current inflation right?
The author (who is handsome and talented) is based in the UK - so tries hard not to be US centric. Hence the use of €.
As for the contradictions - yes. There's a famous aphorism "It is the mark of an educated mind to be able to entertain a thought without accepting it."
I think it is important to explore a problem and its possible solutions. It allows you to work where the issues are and prevents people saying "why didn't you consider…?".
> is based in the UK
Guess 900 is 2.5 Starbucks lattes in London :)
> who is handsome
How is that relevant?
It was in parentheses, that does usually imply irrelevant sideband information.
Perhaps more importantly, the “handsome and talented” sidebar was actually a tongue in cheek acknowledgment that the author himself was speaking, I suspect, compare the usernames and they match up suspiciously well.
He is subtly pointing out that he (edent) is the author of the original blog post by calling himself handsome and talented.
I have the habit of not reading the user names, so I reply to the post not to my image of the author.
Which is why I was triggered by "handsome" too.
I see the article as saying there is no easy fix that can fully remove scams without also making it expensive to register a domain, or even dangerous if your ID becomes public. These things are supposed to contradict each other because they contradict in real life.
I assume this is supposed to be somewhat tongue-in-cheek, because the argument that SoMeThInG mUsT bE dOnE aBoUt DnS because a whopping 10% of registrations were associated with spam/scams seems silly.
There are lots of large open systems that the average person interacts with daily that would love to see <30% spam/scam volume:
- email - paper mail - telephone numbers - SMS messages - basically any social media platform
> I don't want to live in a world where I have to show my passport and pay thousands of pounds to register a domain which is only available after being vetted by private interests. But I also don't want to live in a world where scammers have effectively no deterrent from abusing millions of people.
One solution would be to have recognised verified TLDs that require some verification on some, whilst allowing others to be more lax an accessibel. The issue is we have these, e.g. .gov.uk.
Another solution would be to dissuade people from using less well known gtlds in favour of ones that have some sort of limits/controls, such as recommending people avoid .mobi domains in favour of ones with more oversight like .com. (I say this as someone with a .fun personal domain!)
I don't know. I'm not saying this isn't a problem, I'm just saying that Terence kicking this nest seems like the start of some monkey paw meme or something.
There are some gTLDs like .bank which require a high level of verification. The applicant has to be a financial institution etc.
The problem is twofold. I've never seen a .bank domain in the wild and users generally don't looks at the TLD.
Would people be fooled by "bank.uk-natwset.com"? Probably.
I agree with you that this is definitely in be careful what you wish for territory.
All good thoughts, thanks for the response!
Maybe the solution is in the offline world. A government funded public service announcement of tv/radio/print/busstop ads saying stuff like "never do government stuff not on .gov, never do banking stuff not on .bank". I think that would be highly effective for the sort of people who need the protection here.
It would obviously require banks and gov departments to get their ducks in a row first which is a whole other problem in itself, but it might still turn out to be an economically viable improvement.
I agree in those specific cases (and I've spent a long time inside Government trying to encourage more adoption of .gov.uk and .NHS.uk).
But when you get a text with "your Amazon parcel is delayed plz visit amazaoncom.parcel-delay.info", that looks pretty official to most people.
The opposite issue I had was that I already flagged as spam mails with domains that look like this (not using the official domain) only to discover later that it was legitimate when I connected.
Yeah, I totally agree. I think there's no 1-size-fit-all solution. I think the problem should shift onto "how many solutions do we need"?
At least 2 I'd guess: 1 is going to be incomprehensibly hard and painful compared to now, but there will be maybe only a few handfuls per country. Sure you have to sacrifice your first newborn, but it will come with the full weight of government PSAs because lots of normal and vulnerable citizens depend on it.
The other solution matters less so, because it's could all just be optional/nice to have things, and if people want them, they have to accept some amount of risk/competency in exchange for easy of access. The current solution getting only <50% spam/scam seems to be doing better than traditional mediums so is probably fine for that group.
Maybe there's some more measure solutions between the 2 extremes, but I really don't think there can or should be 1 fix for the DNS system given the range of use cases and customers.
Regardless, Dave down at the local is always going to panic click amazaoncom.paercel-delay.info regardless of what the local bus stop ad or government tell him to do. Such a Dave thing to do.
The UX of DNS would need to be swapped with the gTLD going first.
Perhaps more practical would be browsers noting the gTLD as an important piece of information. Perhaps a “Bank” tag for .bank urls.
I dont see how org.ukpaynatwest-online is any easier to spot as a scam.
Take a look at many of the domains you see in phishing emails / texts. They're all pretty obvious if you spend all day looking at domains and considering their provenance. Most people don't.
I like the idea of highlighting the TLD - but I do wonder if it would just become an expensive boondoggle like EV Certificates.
The (refundable) escrow payment would indeed be a possible solution.
I feel to some degree governments are also responsible for this, by not making consistent use of *.gov domains.
Take for example sunbiz.org, the Florida business register. For 20+ years sunbiz.org was the official domain, until they switched to dos.fl.gov in 2023. The average joe may have heard about "Sunbiz", but was the domain sunbiz.com, sub.biz, sunbiz.net ... who knows?? How would anyone know? All of this could have been avoided by using *.gov everywhere in the first place.
Or by just not having all these choices. I always found it odd that in the English speaking world you have .org(anization), .com(mmercial), .gov(ernment), .net(work) and maybe more that I can't think of right now, but in other countries, everything is just the country code at the end. (Or one of the English ones is used.)
Though, seeing how there are now even more of them than there used to be, I guess that's not feasible.
I can always count on Springfield.GOV for current nuclear plant status