[HN Gopher] The new .zip TLD is going to cause some problems
       ___________________________________________________________________
        
       The new .zip TLD is going to cause some problems
        
       Author : edent
       Score  : 123 points
       Date   : 2023-05-13 11:56 UTC (11 hours ago)
        
 (HTM) web link (shkspr.mobi)
 (TXT) w3m dump (shkspr.mobi)
        
       | gravitronic wrote:
       | Here's the files you requested: https://attachment.zip
        
         | tialaramex wrote:
         | Thanks, that is exactly what I was looking for.
        
         | MandieD wrote:
         | Thank heavens the person who bought that domain is Chaotic
         | Good.
        
         | hakube wrote:
         | damn. You got me
        
         | sashk wrote:
         | YouTube ad killed "you got me".
        
           | computerfriend wrote:
           | Use an ad blocker.
        
             | tialaramex wrote:
             | Or pay for Premium.
        
             | wand3r wrote:
             | I'm not sure you can on iOS? Or not in a straightforward
             | way. If you can block YT ads on ios, would love to know
        
               | jachee wrote:
               | A combo of StopTheMadness and a pi-hole works well for
               | me.
        
               | takoid wrote:
               | Using YouTube in Safari with AdGuard works. Not sure if
               | it's possible to block ads in the YouTube app.
        
         | Dwedit wrote:
         | Rickrolling in 2008: Boisterous Synth Music and Rick Astley
         | 
         | Rickrolling in 2023: Video is initially paused with a full
         | title card visible, If you attempt to play it, you get 5
         | seconds of an AD playing before you can manually click a Skip
         | button, then finally the synth music comes in...
         | 
         | Yeah, it just doesn't work anymore.
        
           | HeladeraDragon wrote:
           | Rickrolls work fine for me tho. There are versions of the
           | video without ads, rickrolling still works.
        
           | toast0 wrote:
           | Look on the bright side, https://badday.mov/ works now.
        
         | circuit10 wrote:
         | I wonder how many people will send this link by accident now
        
         | whoibrar wrote:
         | The only good use of this domain.
        
       | bityard wrote:
       | It's only going to cause problems for software which tries to be
       | too smart for its own good. Applications should not try to guess
       | what the user meant in ambiguous situations because they will
       | often get it wrong.
        
         | pornel wrote:
         | Until now they were mostly getting it right, and unintended
         | links were more of a minor annoyance than a risk (e.g. it
         | happens when talking about Perl or Rust files, but programmers
         | aren't an easy phishing target).
        
           | waboremo wrote:
           | No, it was mostly so cautious it only worked under very
           | strict conditions (ie https and www had to be present or only
           | certain domains) to the point of being useless. Others got
           | quite a lot wrong such as reddit regularly cutting off valid
           | links that left you having to manually copy the entire link
           | anyways.
           | 
           | The same exact security issues that are present here with
           | .zip are also possible with unintended links.
        
       | perk wrote:
       | images.zip was available a couple of hours ago, now it's taken.
        
       | jwilk wrote:
       | Yesterday:
       | 
       | https://news.ycombinator.com/item?id=35920336 ("The .zip TLD
       | sucks", >290 comments)
        
       | brookst wrote:
       | How is this different from .com, which was also a common file
       | extension?
        
         | pornel wrote:
         | It's not a commonly used extension, and it's a dangerous file
         | type, so users shouldn't be opening received .com files either
         | way. OTOH .zip is quite common and has legitimate uses.
        
           | xigoi wrote:
           | .zip files can also be dangerous.
           | 
           | https://en.m.wikipedia.org/wiki/Zip_bomb
        
         | pavel_lishin wrote:
         | .com file weren't typically emailed to people, and there was no
         | expectation that clicking on them would do something harmless
         | like display some files or a document.
        
         | Jasper_ wrote:
         | It was common to see viruses spread by someone sending an
         | executable attachment called "amazon.com" or similar and have
         | people click the link to open it. Most email providers now flat
         | out strip attachments with .com extensions.
        
         | ComputerGuru wrote:
         | There was no omnibar five decades ago.
        
           | [deleted]
        
         | gmuslera wrote:
         | .exe is a more recently used file extension, luckily there
         | isn't (yet) any TLD with that. Belize have .bz (and the domain
         | tar.bz exists), but both the extension used is usually .bz2,
         | and is not so commonly used for transmitting files, .gz would
         | had more impact.
         | 
         | But in the end, is about applications, that may be
         | showing/using 2 different things, URLs and filenames, with
         | different namespaces and use cases, in a pretty similar way.
        
           | Aardwolf wrote:
           | Also cute is the .sh domain, for when you want to curl your
           | shell scripts
        
         | brudgers wrote:
         | When .com became a common top level domain, search tools did
         | not commingle the file:// and http:// protocols.
         | 
         | This was probably for two reasons. Bandwidth was precious.
         | Searching file systems was slow.
         | 
         | Maybe business ethics played a role as well.
         | 
         | Maybe not.
        
         | toast0 wrote:
         | Auto linkifying wasn't happening in the olden times. And there
         | was a shortage of octets for tlds in those days, so .com was
         | all that could be spared.
        
       | c7DJTLrn wrote:
       | Meh, seems like an overreaction. ICANN being bribed into making
       | company-specific TLDs is a bigger issue that nobody is talking
       | about.
        
       | cobertos wrote:
       | Had this issue yesterday. Wanted to Google the docs for
       | `console.group` but who would've guessed that .group was a gtld
        
         | prmoustache wrote:
         | First thing I do when configuring a browser is disabling search
         | in the url bar and activating the dedicated search bar.
         | 
         | Not only it is less ambiguous but I don't want
         | google/duckduckgo or whichever search engine I am using all the
         | domains, url and possibly credentials I am using and I am
         | pretty sure I will do a typo once in a while.
         | 
         | It should be a best practice in any business entity yet I
         | haven't seen any company enforcing this. Apparently everybody
         | is fine leaking internal stuff.
        
       | janalsncm wrote:
       | Dumb question, what _exactly_ is the reason we can't have
       | arbitrary TLDs? Why shouldn't I be able to register a domain like
       | ilike.tacos?
       | 
       | I'd really like to use my last name as a TLD so I can do
       | firstname.lastname.
        
         | toast0 wrote:
         | Arbitrary and numerous TLDs would make the root servers job a
         | lot harder. As-is, the root servers serve a nearly static zone,
         | and high traffic domains are distributed somewhat over several
         | TLD's servers. It wouldn't be impossible to smoosh that all
         | into one cluster, but it would be a bigger challenge than the
         | status quo. You would also have a lot more administrative
         | tension; there are several organizations that each run one or
         | two letters of the root servers; getting them to all coordinate
         | real time changes to a massive zone would be challenging. (I
         | believe all the TLDs, and certainly all the majors are each run
         | by one organization)
        
         | anaganisk wrote:
         | Because the big guy in the middle wants $$$. If you are able to
         | achieve worldwide switching DNS, ICANN to another set of rules
         | you could.
        
       | motoxpro wrote:
       | So instead of downloading a malicious file it takes me to... a
       | webpage?
        
         | rickstanley wrote:
         | Now it may be a malicious webpage _gasp_
        
       | p4bl0 wrote:
       | Funny that this is said from a .mobi website, which is also a
       | file extension. Granted, .mobi files are much less used and much
       | less standardly shared than .zip files, but still it made me
       | smile.
        
         | [deleted]
        
         | [deleted]
        
         | anecdotal1 wrote:
         | .com .sh
         | 
         | There are many file extension collisions with TLDs and the sky
         | didn't fall yet
        
           | partiallypro wrote:
           | Neither of those are used by general consumers on a regular
           | basis. Those are used by people that are generally
           | knowledgeable. I don't know why people can't wrap their head
           | around this. .zip is used every day by people that aren't the
           | best at understanding computer security. Massive difference.
        
             | [deleted]
        
             | waboremo wrote:
             | The category of "tech literate enough to use zips but not
             | enough to know not to blindly click links in emails and
             | also aren't covered by their company's security policy" is
             | a pretty niche group. Your grandpa isn't compressing zips
             | and sending them around to family. Vast vast vaaaaast
             | majority of people just use direct file uploads.
             | 
             | This is going to be a problem, but not for the average
             | folk, but rather for IT teams with unstable rules and other
             | software teams like Gmail who are likely to signal larger
             | differences between attachments and just links.
        
       | hulitu wrote:
       | We need an xlsx and docx TLD.
        
       | aaron695 wrote:
       | [dead]
        
       | kzrdude wrote:
       | I assume email clients will be smart and won't linkify
       | random_words.zip.
        
       | chrismorgan wrote:
       | Honestly, I harbour just a smidgeon of hope that cases like this
       | will nudge companies to reevaluate the whole "find text that
       | _could_ be a link with a missing protocol" feature and realise
       | that it's a terrible idea that causes more trouble than it
       | solves. If you want a link, write a proper URL.
       | 
       | The embedded tweet shows another problem, too:
       | 
       | > _Grrr... Because .zip is a valid TLD, it 's impossible to know
       | whether http://t.co/webB2l1Y9w should be a URL or a filename._
       | 
       | Twitter mangle your links to use t.co _including the presented
       | text_ , so that embedders have no way to determine that the text
       | was supposed to be "example.zip" without following the link or
       | the tweet link. There may have been some purpose to t.co quite a
       | few years ago, but the reasons justifying it vanished completely
       | a few years ago, leaving behind just something that is completely
       | hostile to users and security common sense.
       | 
       | (This also reminds me of Cloudflare's "email address protection"
       | feature, which catches and mangles (in a you-need-to-run-our-
       | JavaScript sort of way, so it doesn't actually affect most
       | people) various things that aren't and can't be email addresses,
       | like package-name@1.2.3.)
        
         | iforgotpassword wrote:
         | I've only ever implemented this in hobby projects, but after a
         | while my simple rule to detect links that are missing the
         | protocol prefix became either having a www. prefix or having a
         | slash after what could be a domain name.
        
           | [deleted]
        
         | ttoinou wrote:
         | Isnt that a proof by direct example of what the author wanted
         | to show ?
        
         | [deleted]
        
       | dom96 wrote:
       | Can someone describe a concrete vulnerability that this creates?
        
         | hgs3 wrote:
         | Message someone and mention a file with a .zip extension, like
         | "Go to Trusted Bank and download financials.zip". Since .zip is
         | now a TLD, software could auto-link it to
         | https://financials.zip. The receiver will think the sender
         | legibility linked to financials.zip for their convivence, but
         | in fact they'll be redirected to a URL with a malicious zip
         | file.
        
           | gcoakes wrote:
           | At least with HTML email, I can already link text to an
           | arbitrary link. This whole thing doesn't seem that important
           | to me.
        
         | [deleted]
        
       | kzrdude wrote:
       | Aren't we going to fully replace .zip with something that uses
       | zstd soon anyway?
        
       | gweinberg wrote:
       | Dibs on the .exe domain!
        
       | jchw wrote:
       | Honestly I think while confusing, this will ultimately not wind
       | up being a big deal. As it is, I have spotted literally hundreds
       | of accidental links across the internet, caused by ccTLDs and
       | gTLDs. Any time someone ends a sentence with a period and doesn't
       | put a space after it it's extremely easy for it to become an
       | accidental link.it isn't that hard to imagine :)
       | 
       | Doesn't necessarily mean it's great for ICANN to be granting all
       | of these dumb top-level domain names, but it is a stronger
       | argument against aggressive autolinking. It's always been crappy
       | behavior anyways.
        
         | emodendroket wrote:
         | I think the problem is that people can squat on "obvious"
         | domains like "financial-report.zip" and put malicious stuff
         | there.
        
       | tbyehl wrote:
       | Weird how everyone wants to blame the TLD and not the systems
       | that naively convert text into hyperlinks.
        
         | pornel wrote:
         | Because these systems and conventions were first. ICANN should
         | have considered the status quo instead of passing the buck to
         | thousands of other preexisting implementations.
        
           | tbyehl wrote:
           | The first TLD / file extension collision is older than that.
        
         | galleywest200 wrote:
         | This is also a very pertinent point.
         | 
         | Side note: Outlook automatically converting addresses into Bing
         | Maps links is quite frustrating when you copy+paste dozens of
         | addresses a day for work.
        
           | Akronymus wrote:
           | Also, copy pasting links using the title of the page as the
           | label and putting the actual link behind a "security scan"
           | thingie so that it is incredibly annoying to just get a blank
           | link.
        
       ___________________________________________________________________
       (page generated 2023-05-13 23:02 UTC)