[HN Gopher] The new .zip TLD is going to cause some problems
___________________________________________________________________
The new .zip TLD is going to cause some problems
Author : edent
Score : 123 points
Date : 2023-05-13 11:56 UTC (11 hours ago)
(HTM) web link (shkspr.mobi)
(TXT) w3m dump (shkspr.mobi)
| gravitronic wrote:
| Here's the files you requested: https://attachment.zip
| tialaramex wrote:
| Thanks, that is exactly what I was looking for.
| MandieD wrote:
| Thank heavens the person who bought that domain is Chaotic
| Good.
| hakube wrote:
| damn. You got me
| sashk wrote:
| YouTube ad killed "you got me".
| computerfriend wrote:
| Use an ad blocker.
| tialaramex wrote:
| Or pay for Premium.
| wand3r wrote:
| I'm not sure you can on iOS? Or not in a straightforward
| way. If you can block YT ads on ios, would love to know
| jachee wrote:
| A combo of StopTheMadness and a pi-hole works well for
| me.
| takoid wrote:
| Using YouTube in Safari with AdGuard works. Not sure if
| it's possible to block ads in the YouTube app.
| Dwedit wrote:
| Rickrolling in 2008: Boisterous Synth Music and Rick Astley
|
| Rickrolling in 2023: Video is initially paused with a full
| title card visible, If you attempt to play it, you get 5
| seconds of an AD playing before you can manually click a Skip
| button, then finally the synth music comes in...
|
| Yeah, it just doesn't work anymore.
| HeladeraDragon wrote:
| Rickrolls work fine for me tho. There are versions of the
| video without ads, rickrolling still works.
| toast0 wrote:
| Look on the bright side, https://badday.mov/ works now.
| circuit10 wrote:
| I wonder how many people will send this link by accident now
| whoibrar wrote:
| The only good use of this domain.
| bityard wrote:
| It's only going to cause problems for software which tries to be
| too smart for its own good. Applications should not try to guess
| what the user meant in ambiguous situations because they will
| often get it wrong.
| pornel wrote:
| Until now they were mostly getting it right, and unintended
| links were more of a minor annoyance than a risk (e.g. it
| happens when talking about Perl or Rust files, but programmers
| aren't an easy phishing target).
| waboremo wrote:
| No, it was mostly so cautious it only worked under very
| strict conditions (ie https and www had to be present or only
| certain domains) to the point of being useless. Others got
| quite a lot wrong such as reddit regularly cutting off valid
| links that left you having to manually copy the entire link
| anyways.
|
| The same exact security issues that are present here with
| .zip are also possible with unintended links.
| perk wrote:
| images.zip was available a couple of hours ago, now it's taken.
| jwilk wrote:
| Yesterday:
|
| https://news.ycombinator.com/item?id=35920336 ("The .zip TLD
| sucks", >290 comments)
| brookst wrote:
| How is this different from .com, which was also a common file
| extension?
| pornel wrote:
| It's not a commonly used extension, and it's a dangerous file
| type, so users shouldn't be opening received .com files either
| way. OTOH .zip is quite common and has legitimate uses.
| xigoi wrote:
| .zip files can also be dangerous.
|
| https://en.m.wikipedia.org/wiki/Zip_bomb
| pavel_lishin wrote:
| .com file weren't typically emailed to people, and there was no
| expectation that clicking on them would do something harmless
| like display some files or a document.
| Jasper_ wrote:
| It was common to see viruses spread by someone sending an
| executable attachment called "amazon.com" or similar and have
| people click the link to open it. Most email providers now flat
| out strip attachments with .com extensions.
| ComputerGuru wrote:
| There was no omnibar five decades ago.
| [deleted]
| gmuslera wrote:
| .exe is a more recently used file extension, luckily there
| isn't (yet) any TLD with that. Belize have .bz (and the domain
| tar.bz exists), but both the extension used is usually .bz2,
| and is not so commonly used for transmitting files, .gz would
| had more impact.
|
| But in the end, is about applications, that may be
| showing/using 2 different things, URLs and filenames, with
| different namespaces and use cases, in a pretty similar way.
| Aardwolf wrote:
| Also cute is the .sh domain, for when you want to curl your
| shell scripts
| brudgers wrote:
| When .com became a common top level domain, search tools did
| not commingle the file:// and http:// protocols.
|
| This was probably for two reasons. Bandwidth was precious.
| Searching file systems was slow.
|
| Maybe business ethics played a role as well.
|
| Maybe not.
| toast0 wrote:
| Auto linkifying wasn't happening in the olden times. And there
| was a shortage of octets for tlds in those days, so .com was
| all that could be spared.
| c7DJTLrn wrote:
| Meh, seems like an overreaction. ICANN being bribed into making
| company-specific TLDs is a bigger issue that nobody is talking
| about.
| cobertos wrote:
| Had this issue yesterday. Wanted to Google the docs for
| `console.group` but who would've guessed that .group was a gtld
| prmoustache wrote:
| First thing I do when configuring a browser is disabling search
| in the url bar and activating the dedicated search bar.
|
| Not only it is less ambiguous but I don't want
| google/duckduckgo or whichever search engine I am using all the
| domains, url and possibly credentials I am using and I am
| pretty sure I will do a typo once in a while.
|
| It should be a best practice in any business entity yet I
| haven't seen any company enforcing this. Apparently everybody
| is fine leaking internal stuff.
| janalsncm wrote:
| Dumb question, what _exactly_ is the reason we can't have
| arbitrary TLDs? Why shouldn't I be able to register a domain like
| ilike.tacos?
|
| I'd really like to use my last name as a TLD so I can do
| firstname.lastname.
| toast0 wrote:
| Arbitrary and numerous TLDs would make the root servers job a
| lot harder. As-is, the root servers serve a nearly static zone,
| and high traffic domains are distributed somewhat over several
| TLD's servers. It wouldn't be impossible to smoosh that all
| into one cluster, but it would be a bigger challenge than the
| status quo. You would also have a lot more administrative
| tension; there are several organizations that each run one or
| two letters of the root servers; getting them to all coordinate
| real time changes to a massive zone would be challenging. (I
| believe all the TLDs, and certainly all the majors are each run
| by one organization)
| anaganisk wrote:
| Because the big guy in the middle wants $$$. If you are able to
| achieve worldwide switching DNS, ICANN to another set of rules
| you could.
| motoxpro wrote:
| So instead of downloading a malicious file it takes me to... a
| webpage?
| rickstanley wrote:
| Now it may be a malicious webpage _gasp_
| p4bl0 wrote:
| Funny that this is said from a .mobi website, which is also a
| file extension. Granted, .mobi files are much less used and much
| less standardly shared than .zip files, but still it made me
| smile.
| [deleted]
| [deleted]
| anecdotal1 wrote:
| .com .sh
|
| There are many file extension collisions with TLDs and the sky
| didn't fall yet
| partiallypro wrote:
| Neither of those are used by general consumers on a regular
| basis. Those are used by people that are generally
| knowledgeable. I don't know why people can't wrap their head
| around this. .zip is used every day by people that aren't the
| best at understanding computer security. Massive difference.
| [deleted]
| waboremo wrote:
| The category of "tech literate enough to use zips but not
| enough to know not to blindly click links in emails and
| also aren't covered by their company's security policy" is
| a pretty niche group. Your grandpa isn't compressing zips
| and sending them around to family. Vast vast vaaaaast
| majority of people just use direct file uploads.
|
| This is going to be a problem, but not for the average
| folk, but rather for IT teams with unstable rules and other
| software teams like Gmail who are likely to signal larger
| differences between attachments and just links.
| hulitu wrote:
| We need an xlsx and docx TLD.
| aaron695 wrote:
| [dead]
| kzrdude wrote:
| I assume email clients will be smart and won't linkify
| random_words.zip.
| chrismorgan wrote:
| Honestly, I harbour just a smidgeon of hope that cases like this
| will nudge companies to reevaluate the whole "find text that
| _could_ be a link with a missing protocol" feature and realise
| that it's a terrible idea that causes more trouble than it
| solves. If you want a link, write a proper URL.
|
| The embedded tweet shows another problem, too:
|
| > _Grrr... Because .zip is a valid TLD, it 's impossible to know
| whether http://t.co/webB2l1Y9w should be a URL or a filename._
|
| Twitter mangle your links to use t.co _including the presented
| text_ , so that embedders have no way to determine that the text
| was supposed to be "example.zip" without following the link or
| the tweet link. There may have been some purpose to t.co quite a
| few years ago, but the reasons justifying it vanished completely
| a few years ago, leaving behind just something that is completely
| hostile to users and security common sense.
|
| (This also reminds me of Cloudflare's "email address protection"
| feature, which catches and mangles (in a you-need-to-run-our-
| JavaScript sort of way, so it doesn't actually affect most
| people) various things that aren't and can't be email addresses,
| like package-name@1.2.3.)
| iforgotpassword wrote:
| I've only ever implemented this in hobby projects, but after a
| while my simple rule to detect links that are missing the
| protocol prefix became either having a www. prefix or having a
| slash after what could be a domain name.
| [deleted]
| ttoinou wrote:
| Isnt that a proof by direct example of what the author wanted
| to show ?
| [deleted]
| dom96 wrote:
| Can someone describe a concrete vulnerability that this creates?
| hgs3 wrote:
| Message someone and mention a file with a .zip extension, like
| "Go to Trusted Bank and download financials.zip". Since .zip is
| now a TLD, software could auto-link it to
| https://financials.zip. The receiver will think the sender
| legibility linked to financials.zip for their convivence, but
| in fact they'll be redirected to a URL with a malicious zip
| file.
| gcoakes wrote:
| At least with HTML email, I can already link text to an
| arbitrary link. This whole thing doesn't seem that important
| to me.
| [deleted]
| kzrdude wrote:
| Aren't we going to fully replace .zip with something that uses
| zstd soon anyway?
| gweinberg wrote:
| Dibs on the .exe domain!
| jchw wrote:
| Honestly I think while confusing, this will ultimately not wind
| up being a big deal. As it is, I have spotted literally hundreds
| of accidental links across the internet, caused by ccTLDs and
| gTLDs. Any time someone ends a sentence with a period and doesn't
| put a space after it it's extremely easy for it to become an
| accidental link.it isn't that hard to imagine :)
|
| Doesn't necessarily mean it's great for ICANN to be granting all
| of these dumb top-level domain names, but it is a stronger
| argument against aggressive autolinking. It's always been crappy
| behavior anyways.
| emodendroket wrote:
| I think the problem is that people can squat on "obvious"
| domains like "financial-report.zip" and put malicious stuff
| there.
| tbyehl wrote:
| Weird how everyone wants to blame the TLD and not the systems
| that naively convert text into hyperlinks.
| pornel wrote:
| Because these systems and conventions were first. ICANN should
| have considered the status quo instead of passing the buck to
| thousands of other preexisting implementations.
| tbyehl wrote:
| The first TLD / file extension collision is older than that.
| galleywest200 wrote:
| This is also a very pertinent point.
|
| Side note: Outlook automatically converting addresses into Bing
| Maps links is quite frustrating when you copy+paste dozens of
| addresses a day for work.
| Akronymus wrote:
| Also, copy pasting links using the title of the page as the
| label and putting the actual link behind a "security scan"
| thingie so that it is incredibly annoying to just get a blank
| link.
___________________________________________________________________
(page generated 2023-05-13 23:02 UTC)