No video

.ZIP Domains Are a Disaster (Hackers Love them)

  Рет қаралды 194,820

Seytonic

Seytonic

Күн бұрын

$5 Free Credit 👉 PCBWay pcbway.com/g/g...
Timestamps:
0:00 Intro
0:28 A very. Bad. Idea
1:56 Sophisticated Phishing Links
4:43 In Defence of .Zip
5:57 PCBWay
6:36 Outro
Sources:
/ the-dangers-of-googles...
www.bleepingco...
www.ghacks.net...
www.blog.googl...
isc.sans.edu/d...
isc.sans.edu/d...
www.theregiste...
github.com/tri...
===============================================
My Website: www.seytonic.com/
Follow me on TWTR: / seytonic
Follow me on INSTA: / jhonti
===============================================

Пікірлер: 756
@celebrityaudiobooks
@celebrityaudiobooks Жыл бұрын
You know it's bad when you're relatively tech savvy but can confidently say you would fall for something...
@Daveeeeeeyhowyoudoing
@Daveeeeeeyhowyoudoing Жыл бұрын
Relative to what, your 80 year old grandmother? A rock? If you were tech savvy, you would have an extension that does Grammer checks for you.... You would realize you are relatively stupid
@Splarkszter
@Splarkszter Жыл бұрын
yup. now gotta be scared of every markdown.
@Izzythemaker127
@Izzythemaker127 Жыл бұрын
Agreed, I would most likely fall for this if I hadn't known, and might still. Idk who's idea it was to store PLAIN TEXT LOG IN CREDENTIALS IN THE URL WITH A COMMONLY USED SYMBOL in the first place
@yeetyeet7070
@yeetyeet7070 Жыл бұрын
@@Izzythemaker127 nah thats fine. the .zip TLD is the problem
@its_herocast276
@its_herocast276 Жыл бұрын
@@yeetyeet7070 Putting plain text login credentials in the url is "fine" according to you?? Seriously?
@Fasguy
@Fasguy Жыл бұрын
The zip TLD is genuinely one of the dumbest decisions Google has ever made. Hey, let's add exe as a TLD as well, while we're at it.
@UriahStuff
@UriahStuff Жыл бұрын
Let's add PNG, JPG, MP4, and MP3.
@ocsanik502
@ocsanik502 Жыл бұрын
@@UriahStuff and .elf, .bin, .so, and .dll aswell
@bitten2up
@bitten2up Жыл бұрын
​​@@ocsanik502 oh and dont foget about .c, .c++ and .cpp, .c# .. and finally .a
@homework8969
@homework8969 Жыл бұрын
wait dont give them ideas (and .o, .dir, .tga)
@ocsanik502
@ocsanik502 Жыл бұрын
@@bitten2up and .h, .asm, .py, and .sh
@mfaizsyahmi
@mfaizsyahmi Жыл бұрын
My biggest question is: Who the heck let Google be a TLD registrar???
@plasticstuff69
@plasticstuff69 Жыл бұрын
Anyone can be a domain registrar lol?
@himabimdimwim
@himabimdimwim Жыл бұрын
ICANN.
@Tim_van_de_Leur
@Tim_van_de_Leur Жыл бұрын
@@himabimdimwim its called ICANN, not ICANNOT :P
@adispenser
@adispenser Жыл бұрын
@@plasticstuff69 anyone can register a domain but google can create them
@wiger_
@wiger_ Жыл бұрын
they let you do anything if you donate millions per year
@sherlockmaverick
@sherlockmaverick Жыл бұрын
You and I, maybe we can be on the lookout for this. How on earth am I going to explain this to the infinitely large swathes of non-tech-savvy people I know?! Bad move, Google. Very bad.
Жыл бұрын
I guess we have to save this video to explain to those non technical people. 😅
@Vysair
@Vysair Жыл бұрын
@Dave Dörenberg-Veltman It needs to be shorter because of the garbage attention span
@DJ_POOP_IT_OUT_FEAT_LIL_WiiWii
@DJ_POOP_IT_OUT_FEAT_LIL_WiiWii Жыл бұрын
put mouse over link, look in status bar...
@Stroopwafe1
@Stroopwafe1 Жыл бұрын
​​@@DJ_POOP_IT_OUT_FEAT_LIL_WiiWii *user proceeds to put their physical mouse over the monitor where the URL is, asking "where is the status bar?"*
@friendsfrenz1944
@friendsfrenz1944 Жыл бұрын
​@@Vysair honestly non tech savvy users will just read the title and believe it... as long as they relatively trust you They will care about this stuff
@Tarodenaro
@Tarodenaro Жыл бұрын
Sweet, please make a video once a google employee gets pwnd by this domain lol
@Seytonic
@Seytonic Жыл бұрын
I'll be on the lookout 👀
@GameMaker3_5
@GameMaker3_5 Жыл бұрын
​@@Seytonic It'll be ebic ;)
@evaneevee8398
@evaneevee8398 Жыл бұрын
The fact that the people at the head of this thought it's a good idea to create a .zip domain possibly scares me. It's like they don't even care what happens to their loyal customers. Even as someone who doesn't interact with much outside of a couple friends, I'm worried about falling for one of these now. This opens up so many more attack opportunities that it's quickly becoming dangerous to even download anything that normally sends you to a blank page that auto downloads the file.
@Daveeeeeeyhowyoudoing
@Daveeeeeeyhowyoudoing Жыл бұрын
Cry about it 😂😂😂
@bubba99009
@bubba99009 Жыл бұрын
They don't care what happens to their customers. It's all about that $15/year.
@MischieviousJirachi
@MischieviousJirachi Жыл бұрын
​@@Daveeeeeeyhowyoudoing no one reply to this guy, they're not serious and jus wanna make u mad
@dabster291
@dabster291 Жыл бұрын
@@MischieviousJirachi report them for harassment instead
@vvert1506
@vvert1506 Жыл бұрын
@@MischieviousJirachi but what if i like their attitude?
@muizzsiddique
@muizzsiddique Жыл бұрын
When .rar and .7z TLDs exist, we will know that this act was malicious the whole time.
@danieljaouen9384
@danieljaouen9384 Жыл бұрын
Google wouldn’t do this because they need plausible deniability.
@scottc5181
@scottc5181 Жыл бұрын
Along with .tar and all will be covered.
@chromefinch
@chromefinch Жыл бұрын
.exe tld I quit
@madman4043
@madman4043 Жыл бұрын
That's not how this works. At all. One bad decision followed by more bad decisions doesn't prove it was malicious, just that they make a lot of bad decisions.
@bitten2up
@bitten2up Жыл бұрын
@@scottc5181 .gz and .tar.gz tld
@GatlingNG
@GatlingNG Жыл бұрын
Who could have seen this coming! That anyone thought that having a gtld be an archive file extension was a good idea is beyond me.
@Appoxo
@Appoxo Жыл бұрын
Next one will be .rar and .7z/7zip?
@martenkahr3365
@martenkahr3365 Жыл бұрын
The core problem is that Google has paid enough money to ICANN to become a TLD registrar. They didn't need to get any outside opinion or permission to create that tld. I imagine the most that happened was more technical people downstream explaining why this was a bad idea and the business sociopath who only sees the potential revenue of selling those domains to criminals making responding with "Okay, your concerns are noted. Now do it anyway or I'm replacing you with someone who will."
@LePedant
@LePedant Жыл бұрын
That's called the Dunning-Kruger effect. It occurs when a person's lack of knowledge and skills in a certain area cause them to overestimate their own competence.
@deality
@deality Жыл бұрын
​@@Appoxo lol
@metcaelfe
@metcaelfe Жыл бұрын
It was irresponsible to allow the TLD in the first place
@i_am_a_real_cat1443
@i_am_a_real_cat1443 Жыл бұрын
what is a tld?
@ahsokaincognito
@ahsokaincognito Жыл бұрын
Absolutely. I cant think of one legitimate business which would use this tld
@ahsokaincognito
@ahsokaincognito Жыл бұрын
​@@i_am_a_real_cat1443 top level domain, the part behind the last dot in a domain. Like net, de, fr
@troughy3288
@troughy3288 Жыл бұрын
@@i_am_a_real_cat1443 top level domain
@fiverZ
@fiverZ Жыл бұрын
How can Google even issue their own TLD's?
@YEdwardP
@YEdwardP Жыл бұрын
I'm a reasonably tech-savvy, non-expert user and having heard your arguments, I am now convinced that this was a bad idea and should be undone.
@LePedant
@LePedant Жыл бұрын
That's called the Dunning-Kruger effect. It occurs when a person's lack of knowledge and skills in a certain area cause them to overestimate their own competence.
@turolretar
@turolretar Жыл бұрын
@@LePedant pretty sure it’s called the “Dumb-n-cruder effect”, but I’m not an expert.
@LePedant
@LePedant Жыл бұрын
@@turolretar Lol, sounds like something Michael Scott from The Office would say.
@kumi6797
@kumi6797 Жыл бұрын
@@LePedant can't go wrong, right?
@xaza8uhitra4
@xaza8uhitra4 Жыл бұрын
don’t know about you guys but i can’t wait to click on all the .zips i see
@FAB1150
@FAB1150 Жыл бұрын
It's a thing I would fall for if I didn't follow all the drama... How the hell will I explain this to my parents?
@Tim_van_de_Leur
@Tim_van_de_Leur Жыл бұрын
Just unplug them :P
@truerandomchannel
@truerandomchannel Жыл бұрын
don't let them click ANY links
@freedustin
@freedustin Жыл бұрын
"Stop using the internet, its by criminals for criminals now."
@FAB1150
@FAB1150 Жыл бұрын
@@truerandomchannel the whole thing is that these links don't look like links
@joelpww
@joelpww Жыл бұрын
​@@FAB1150 exactly. The challenge of explaining to most people would be extremely hard
@hubeldubel9730
@hubeldubel9730 Жыл бұрын
Thanks for pointing that out. I've added the .zip TLD to my pi hole's regex blacklist, such as many other suspicious TLDs too.
@AdamS-nd5hi
@AdamS-nd5hi Жыл бұрын
Google been comfortable collecting checks from black hats for years. Wouldnt suprise me if they put these features out specifically for thwm to drum up new rev streams. Orgs should block zip and mov sites in their dns internally
@suncat530
@suncat530 Жыл бұрын
i want to learn more, do you have links to some sort of articles talking about that?
@apIthletIcc
@apIthletIcc Жыл бұрын
And carriers should do the same, somehow though it still isn't happening. Gotta wonder why.
@khorps4756
@khorps4756 Жыл бұрын
I agree. Google is a known cyber fraud company already, so it's no surprise.
@AdamS-nd5hi
@AdamS-nd5hi Жыл бұрын
@@suncat530 there are tons of vids showing google accepting add rev from hackers running scam/pjishing sites and advertising ad the real thing. And they do nothing to stop them
@garbagetrash2938
@garbagetrash2938 Жыл бұрын
I understand why carriers don't want to do it, but I'm already writing custom ElasticSearch rules to alert to any .zip TLDs navigated to.
@barjo_
@barjo_ Жыл бұрын
Can't wait to be hyper paranoid when downloading any zip file from now on
@garbagetrash2938
@garbagetrash2938 Жыл бұрын
Virus total is gonna be everyone's best friend.
@eddiewramos
@eddiewramos Жыл бұрын
My grandmother’s computer stands no chance now
@SaburoOkita
@SaburoOkita Жыл бұрын
Google is gonna paddle back and introduce a .rar domain instead!
@Seytonic
@Seytonic Жыл бұрын
Maybe we'll get an .exe one day..... Introducing the .exe TLD, where hackers can now confuse you with websites that look like harmless files, making every click a thrilling game of chance. Stay on your toes and pray you don't accidentally download a virus!
@seailz
@seailz Жыл бұрын
@@Seytonic Sounds like something they'd do 💀
@cfryantofficial
@cfryantofficial Жыл бұрын
@@Seytonic Yep. Gotta get that domain for all your executives. 😂
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked Жыл бұрын
​@@Seytonic true, though I don't do redundant , begging, and debunked prayer. Hehe
@ReligionAndMaterialismDebunked
@ReligionAndMaterialismDebunked Жыл бұрын
I think it's cool. :3
@sion-music
@sion-music Жыл бұрын
It sounds to me like the Markettng department at Google managed to override all the sensible teams (Security, IT, Dev, and practically any other technical team). There is a reason that Marketing departments are often referred to as "the colouring-in team".
@vvert1506
@vvert1506 Жыл бұрын
i hate sales i hate marketing i hate the antichrist i hate car culture i hate pussy
@dimitribarronmore
@dimitribarronmore Жыл бұрын
In my opinion, browsers should just refuse to resolve TLDs like this. I don't particularly care that it would be walling off anyone who purchases a .zip or similar domain, the only way to shut something like this down is to simply refuse to comply. Make the .zip TLD completely useless and the problem will solve itself. Unfortunately we all know that's never happening, seeing as the people who issued the TLD also make the most popular browser, but a clear "potentially malicious link" warning would at least be nice.
@BrainPermaDeD
@BrainPermaDeD Жыл бұрын
The main problem is people hate to coordinate. So Shrome is staying.
@Mernom
@Mernom Жыл бұрын
You can set up your group policy, or setup your DNS to reject them.
@Heknon
@Heknon Жыл бұрын
You can add a firewall rule to reject this
@Voorhees-Jason
@Voorhees-Jason Жыл бұрын
problem is chrome is one of those browsers lol and a lot and i mean a lot of people uses chrome. Good luck with that one.
@donit.
@donit. Жыл бұрын
you realize that basically every browser except firefox is based on chrome?
@Amy_A.
@Amy_A. Жыл бұрын
Why am I not surprised that Google continues to make literally everything they touch just a little bit worse?
@-morrow
@-morrow Жыл бұрын
2:50 userinfo in url's isn't a legacy feature. it is very often used as username@host for other protocols like e.g. ssh
@notpumkin
@notpumkin Жыл бұрын
Honestly, it's still insane that chrome automatically downloads files by default.
@user-xz1ur8us5p
@user-xz1ur8us5p Жыл бұрын
You could configure it to ask where to download each file before actually downloading. But that needs to be set up after the fact when it should be the default setting imo.
@gavinthecrafter
@gavinthecrafter Жыл бұрын
Downloading files by themselves is not much of a security threat, right? The program still needs to be executed for it to be malicious
@mahdi9064
@mahdi9064 Жыл бұрын
​@@gavinthecrafter until your windows security decide that it wants to extract a zip file to check for cp or illegal content, and poof you are hacked.
@L2002
@L2002 Жыл бұрын
@@mahdi9064 Clearly you don't know how antivirus work.
@garbagetrash2938
@garbagetrash2938 Жыл бұрын
​@@gavinthecrafter this type of attack is called a drive-by download and no it is not particularly dangerous. Most organizations will have some type of EDR like carbon black or crowdstrike, that will stop execution anyway. It's just stupid to introduce an unnecessary, confusing way for threat actors to make phishing, the most common type of initial access, even easier.
@username65585
@username65585 Жыл бұрын
Who thought zip was a good idea for a TLD?
@shadamethyst1258
@shadamethyst1258 Жыл бұрын
People in marketing
@suncat530
@suncat530 Жыл бұрын
Alphabet
@starchy_
@starchy_ Жыл бұрын
there is a workaround to make sure you dont fall for this, add the following to your adblocker of choice (which should be ublock origin) ||zip^$document ||mov^$document this will block visiting sites with .zip and .mov tlds, while still allowing recources to be fetched from them (like if google decides no use a .mov domain to serve yt videos) and allowing "zip" and "mov" everywhere else in the url. this should give you a nice warning to let you know youre making a mistake, but its not a fix for the underlying problem, and will only really help for already tech savvy users.
@arcticcircle9178
@arcticcircle9178 Жыл бұрын
What do you mean by "allowing resources to be fetched from them"? Would you still be able to accidentally download malicious zip files?
@alethephobe7586
@alethephobe7586 Жыл бұрын
Your videos are the best. Seriously there's no better channel for cybernews. Thank you sincerely.
@Seytonic
@Seytonic Жыл бұрын
Thanks my dude, I appreciate it :)
@tayyabnaveed2266
@tayyabnaveed2266 Жыл бұрын
there should be a committee that looks at more things than just the transaction number. Like the potential ramifications of allowing the TLD to exist
@uwuifyingransomware
@uwuifyingransomware Жыл бұрын
I understand what you’re saying about web developers implementing safety features like not auto linking, but I see a bigger issue in that random web developers should not have to pick up the pieces after a terrible decision by google. Firstly because it’s not their responsibility (it is google’s, for making a decision that will so obviously go wrong), but also because the average web developer can’t reasonably be expected to know this is happening. That’s not even mentioning the amount of programs that are actively used but don’t receive updates.
@ChefGoreb
@ChefGoreb Жыл бұрын
The shitstorm once it'll be made public that the first google employee fell for this is gonna be gold. Worst idea ever Google. Also, I'm still mad u cancelled Wave.
@Amy_A.
@Amy_A. Жыл бұрын
I sincerely hope they do, and I hope it finally spooks the public into realizing how little value they actually provide nowadays.
@tehjamerz
@tehjamerz Жыл бұрын
I'm still mad about Google video
@christopherg2347
@christopherg2347 Жыл бұрын
When programmers have to add a _exclusion_ for .zip domains, you already fucked up. That is a SQL-Injection sized issue - because now programmers have to be aware and invest extra effort just to not cause a issue.
@bubbleteaichooseyou
@bubbleteaichooseyou Жыл бұрын
I'm not gonna try to defend myself. I work in IT and I think I would fall for it as well
@BWAC
@BWAC Жыл бұрын
Well there goes my Monday, Blocking all TLDs that resemble file names >.< - I await to see a .rar, .7z, .zip or god forbid tax_invoice.xlsx
@jer1776
@jer1776 Жыл бұрын
Good idea, hopefully someone makes a DNS server that does just that
@DragoNate
@DragoNate Жыл бұрын
So to remind everyone about links: *_DO NOT CLICK RANDOM LINKS_* Even if it comes from a "credible" source. check, double check, recheck and check again for good measure.
@blinking_dodo
@blinking_dodo Жыл бұрын
The @ before domain is still widely used in ssh. It is used to specify which username you want to use on the ssh server.
@BorealBlizzard
@BorealBlizzard Жыл бұрын
Hehehe, I just bought one because they are surprisingly cheap. Using it for a personal landing page and some self hosted services because it's nice and short.
@lucidattf
@lucidattf Жыл бұрын
just because an issue was marked wontfix years ago doesn't mean they can't change their mind if the user credentials in URL trick ever becomes a common attack. auto-hyperlinking domains is the only real concern here, and it can be fixed easily by web developers
@stage6fan475
@stage6fan475 Жыл бұрын
Ah, but in the modern internet, just because an issue can be easily fixed by web developers doesn't mean it ever will except for a small minority of cases.
@mordor_3
@mordor_3 Жыл бұрын
Google really going for the big brain manouvers. 🤔
@_JohnHammond
@_JohnHammond Жыл бұрын
Appreciate the nod @Seytonic! :) Hope to have helped with at least some of the blast radius...
@edgars9581
@edgars9581 Жыл бұрын
Firefox actually asks to confirm when navigating userinfo URLs, so it is less likely to work on it as on Chrome
@wantacupoftea
@wantacupoftea Жыл бұрын
Not often i find something I would actually fall for. Thanks for bringing it to my attention
@___gg421
@___gg421 Жыл бұрын
This was definitely a decision made my a non technical manager type who is refusing to back down now
@reegyreegz
@reegyreegz Жыл бұрын
Lol, time to super-harden my home network due to my elderly parents being on it. This will be a nightmare
@gus473
@gus473 Жыл бұрын
Read about this example last night, and I think your animated version does a great job of making it more understandable! Yeah, potential mess! Thanks! 😎✌️
@CreoSM
@CreoSM Жыл бұрын
This is seriously a bad idea, they could have chosen anything else but this
@Christopher_S
@Christopher_S Жыл бұрын
Wow. I never saw this coming.... Google with their ever increasing stupidity, but as long as they can make some money out of it eh?
@Sound_.-Safari
@Sound_.-Safari Жыл бұрын
Too many projects not maintained to receive updates that would prevent auto highlight of .zip domains. Though maybe they wouldn’t recognize them anyways. Either way I think it’s too confusing for the end users that are unlikely to learn about it. Adds a tool for phishers and seems low value for the TLD domain space
@CongruentYT
@CongruentYT Жыл бұрын
These "new TLDs" have been available to Google since 2014, just now made public.
@RokeJulianLockhart.s13ouq
@RokeJulianLockhart.s13ouq Жыл бұрын
I believe that we should only have TLDs for each internet governance authority, since that's what they're for - to designate where to send domain resolution requests to.
@LabiaLicker
@LabiaLicker Жыл бұрын
This is all going to get worse with Google having complete control over the web now....
@Reeces_Pieces
@Reeces_Pieces Жыл бұрын
Blocked the whole TLD after seeing that medium article example. That's just too sneaky.
@bubba99009
@bubba99009 Жыл бұрын
This just seems like a gift to hackers. Not sure what the legitimate use case is. Also it's ridiculous the number of TLDs being created just in general. I guess it's close to 100% profit for the registrars and that's the motivation behind it.
@freedustin
@freedustin Жыл бұрын
Not a gift. A sales pitch.
@1cindy8552
@1cindy8552 Жыл бұрын
there must have been AT LEAST one person in the Google team that knew the repercussions and stayed quiet. no?
@TheUnknownCatWarrior
@TheUnknownCatWarrior Жыл бұрын
Set your browser to ask before downloading and you will save your self from those websites that redirect you to an automatic download.
@asdprogram
@asdprogram Жыл бұрын
Thanks for letting us know! You're the best! 👍
@douro20
@douro20 Жыл бұрын
The "backup" one serves a random backup-related quote.
@bioman2007
@bioman2007 Жыл бұрын
Liked and sub, Amazing video! Pd: Google's motto "Don't be evil" now looks more like just another corporate cliche.
@tursilion
@tursilion Жыл бұрын
They dropped that motto back in 2018 ;)
@KO6BXL1
@KO6BXL1 Жыл бұрын
we won't believe the amount of normal company employees falling for this
@lamjeri
@lamjeri Жыл бұрын
Firefox actually does some work in this regard. As you mentioned, everything before the @ sign is considered a username (and password if there's a : as well), so when you click on such a malicious link, but the landing page doesn't accept logins, Firefox displays a message saying if you're sure you want to proceed because you're about to land on a page that didn't request a login, but the link provided one. Not completely fool proof, but it's a step in the right direction.
@sirshark10
@sirshark10 Жыл бұрын
Noting your browser section, Firefox has had a feature to combat this *sort of* for a little bit at least. When you try to connect to a page with a username that doesn't take a login, it will immediately prompt you before navigating.
@cephy8102
@cephy8102 Жыл бұрын
Welp, now I just have all the more reason to double-check every link I see lol
@chrisoakleyfx
@chrisoakleyfx Жыл бұрын
The scary/infuriating thing about this is that I would 100% fall for this if there were no other obvious red flags of a phishing scam. Those links are very convincing. Sure I wouldn't be dumb enough to open a zip file from a random email (be it an actual .zip or an obfuscated URL), but if it is socially engineered in the right way that gives me little reason to question the authenticity, then sure I could see myself falling for this 👀
@alexanderklee6357
@alexanderklee6357 Жыл бұрын
Googles big brain move here is capitalizing on White hats who will buy up .zip domains xD
@somedude7447
@somedude7447 Жыл бұрын
This is a really bad idea. What legitimate domains would use this? A zipper company or maybe compression software like 7zip? The negatives far outweigh the positives. Waiting on the .exe/.dmg domains next.
@FrancescoRosi27
@FrancescoRosi27 Жыл бұрын
I've always been a little skeptical of .zip ever since Google announced it. Guess my skepticism was well placed!
@AntonioNoack
@AntonioNoack Жыл бұрын
I see the bigger issue in Chromium allowing fake slashes in user credentials / allowing user credentials there at all. I'd like to see them removed, and the issue is done.
@jacobelgan5196
@jacobelgan5196 Жыл бұрын
Google doing such a seemingly dumb action implies to me that there's something going on behind the scenes that extends to beyond network security that had influenced its existance
@bettercalldelta
@bettercalldelta Жыл бұрын
I wouldn't even be surprised if google knew exactly what they were doing. It's all about the $$$
@DragonNuts
@DragonNuts Жыл бұрын
I feel like this on the Google ads thing it seems like Google wants people to get hacked
@charlottenburg
@charlottenburg Жыл бұрын
Buying a .zip asap
@arsen3223
@arsen3223 Жыл бұрын
If you are phishing someone through gmail with the zip tld then wait until you hear about link display texts. You can already do these download urls scams with any domain. Just checked discord and looks like the part before the @ gets removed in your message. Telegram also has link display texts. But sure, if I see it on a website, I'd probably fall for it
@winkcla
@winkcla Жыл бұрын
I was thinking about this as well. If you control the email body, obfuscation in the link display text is meaningless. And people are already much less likely to inspect the actual URL. For all apps that auto-link domains written without a protocol in all user content it's going to be really annoying and possibly dangerous as stated in the video
@SzaboB33
@SzaboB33 Жыл бұрын
I have experience reporting bugs to chromium. They refuse to care if it's not something super critical. :D
@rfkgaming
@rfkgaming Жыл бұрын
this is why I have zip and mov blocked at a domain level in my firewall it will just get sent to a blackhole on my network.
@descuddlebat
@descuddlebat Жыл бұрын
I've been using URLs with @ for SSH logins and git clones for some time now, yet I absolutely would've fallen for this one on any font that doesn't give away the slashes... Can we go back to when my online safety wasn't dependent on font choice please
@-morrow
@-morrow Жыл бұрын
yeah, userinfo in urls certainly isn't a "legacy feature" as he seytonic said
@sanityd1
@sanityd1 Жыл бұрын
o god another thing I need to try and explain to my parents - also PCBway even got to you lol
@HandlesSuck
@HandlesSuck Жыл бұрын
I share your pain.
@bruh83483
@bruh83483 Жыл бұрын
whar wrong with him being sponsored
@Dudeplay
@Dudeplay Жыл бұрын
Thanks for the video, will block tomorrow every .zip domain for dna resolution in the firm.
@n-i-n-o
@n-i-n-o Жыл бұрын
Im using NextDNS, and I block new registered Domains and the whole .ZIP Domain by default.
@its_herocast276
@its_herocast276 Жыл бұрын
Lesson learned, hover your cursor above a zip download link to check the domain.
@physicsgrad
@physicsgrad Жыл бұрын
I guess blocking out the .zip TLD via some DNS resolver could be a solution, for now.
@HandlesSuck
@HandlesSuck Жыл бұрын
Why on earth did they choose .zip? Is there a logical reason?
@Amy_A.
@Amy_A. Жыл бұрын
"Because we're richer than a million millionaires, so screw you" -Alphabet
@dunk7605
@dunk7605 Жыл бұрын
money
@Yune_Faded
@Yune_Faded Жыл бұрын
Okay i seriously wondering which Engineer or cyber security specialist thought making file name domains was a smart idea. Honestly this just sounds like some marketing people convincing executives that they could earn a lot of money and not listening to engineers
@siouxWaits
@siouxWaits Жыл бұрын
Why big companies love these days to 'unsecure' the masses ? Lately Discord and Ledger and now Google. What they're up to ???
@monkaSisLife
@monkaSisLife Жыл бұрын
How does a multi-billion dollar tech company not see anything wrong with providing a .ZIP-TLD. i think even my dad could tell me why that is a bad idea and he hasn't even used a computer since a few years now
@liquidsnake6879
@liquidsnake6879 Жыл бұрын
I think web browsers should just blacklist such websites and not treat them as hyperlinks, if someone wants to manually type it in their address bar fine, if not then it shouldn't be rendered as a hyperlink, you can probably make a chrome extension that does this for people
@g-program-it
@g-program-it Жыл бұрын
cheers for sharing this. Another potential exploit to look out for.
@chukaml
@chukaml Жыл бұрын
Because Google wants more money. Not a bit more but globally much more money. More types of TLD means a company owner needs to register more domain names to protect against domain name abuse.
@AvenFurness
@AvenFurness Жыл бұрын
Upcoming TLDs include: .exe, .docx, .pdf, .mp3 and .png!
@DavidJCobb
@DavidJCobb Жыл бұрын
word on the grapevine is this is straight-up deliberate. zip and mov files are often used in piracy, and this is a sledgehammer blow to reduce confidence in those formats
@hiiamelecktro4985
@hiiamelecktro4985 Жыл бұрын
I’m honestly wondering if this was made for cybercriminals. Like, this product is targeted towards them or something. Even though this is a stupid thought, I literally cannot fathom for what other reason they did this.
@svaira
@svaira Жыл бұрын
For some things I am convinced we should have just stuck to ASCII, and URLs are such a thing. The amount of damage done by it is not worth this, having to type a few more characters is obviously better. (Or at least no Unicode symbols, just the letter class... Anything else seems just quite absurd to me)
@DavidJCobb
@DavidJCobb Жыл бұрын
there are large parts of the world that don't use the latin alphabet, and people living there deserve to be able to write the urls of their own countries' websites in their own language this is not to say Unicode should be fully unrestricted of course
@svaira
@svaira Жыл бұрын
@@DavidJCobb yes, I can see the point, but restricting it to the letter class makes sense to me, this includes Arabic, Chinese etc. writing, but no punctuation, math symbols etc. that could be confusing.
@ZizzyDizzyMC
@ZizzyDizzyMC Жыл бұрын
Well at least no one will be falling for Homework. That cost me quite a bit!
@Bmarquismarkail
@Bmarquismarkail Жыл бұрын
While Google mentions that they have mechanisms to suspend or remove malicious domains across all TLDs, including .zip, they do not provide specific details about the countermeasures designed specifically for this TLD. I can't simply allow a company so powerful to hand-wave this without explaining how, in detail, they have control over the situations. This is a lack of transparency of which all consumers of the internet need to be wary of.
@user-qq4wu8sc2k
@user-qq4wu8sc2k Жыл бұрын
It would be nice for DNS service providers other then Google to redirect access for the users which trying to resolve .zip .Mov etc domains with the stab that show user it trying to access something shady.
@SioxerNikita
@SioxerNikita Жыл бұрын
Most of this seems more like other security failures that are being exposed now
@timyg
@timyg Жыл бұрын
Cant wait to fall for this because im tired and need to get one of my million projects finished quick
@uniktbrukernavn
@uniktbrukernavn Жыл бұрын
I would like to know more about the person who designed a unicode character to look almost like a slash. Genius.
@jhgvvetyjj6589
@jhgvvetyjj6589 Жыл бұрын
The division slash and fraction slash characters which are used to fractions
@apolloapostolos5127
@apolloapostolos5127 Жыл бұрын
0:20 that’s not irony, it’s coincidence. Irony would be the URL actually got longer.
@chickenroyalty9233
@chickenroyalty9233 Жыл бұрын
never knew about this thank you very much for spreading the word
@estrawitch
@estrawitch Жыл бұрын
honestly i think the best thing to do is either have browsers no longer support that legacy feature you mentioned or have browsers show a warning edit: firefox already does this lol
@Darkangelike
@Darkangelike Жыл бұрын
I am glad I use firefox and now chrome!!
@ChongMcBong
@ChongMcBong Жыл бұрын
it seems insane, almost like they want to cause trouble with it
@huddunlap3999
@huddunlap3999 Жыл бұрын
I posted this on Facebook to let my friends know. So Google is expecting developers to fix a problem they started
@thenewaeon
@thenewaeon Жыл бұрын
Thanks, Google, for your continuous work to make the web a horrible place to be.
The ChatGPT Scam
9:30
Seytonic
Рет қаралды 295 М.
Weaponized Tor is being Spread on YouTube
10:05
Seytonic
Рет қаралды 856 М.
Comfortable 🤣 #comedy #funny
00:34
Micky Makeover
Рет қаралды 16 МЛН
Kids' Guide to Fire Safety: Essential Lessons #shorts
00:34
Fabiosa Animated
Рет қаралды 11 МЛН
Exploiting Calculator.exe For Hacking
8:33
Seytonic
Рет қаралды 205 М.
The Weirdest Top-Level Domain Extensions
16:52
ThioJoe
Рет қаралды 201 М.
Hacking Windows TrustedInstaller (GOD MODE)
31:07
John Hammond
Рет қаралды 512 М.
Russia's #1 Malware Was Just Sabotaged (Thanks FBI)
6:30
Seytonic
Рет қаралды 132 М.
Hacking a SATA Cable to Transmit Files
10:11
Seytonic
Рет қаралды 92 М.
What Happened To Google Search?
14:05
Enrico Tartarotti
Рет қаралды 3,1 МЛН
Exploiting Github to Mine Crypto
10:46
Seytonic
Рет қаралды 319 М.
How Hackers Bypass Kernel Anti Cheat
19:38
Ryscu
Рет қаралды 649 М.
Pro-Russian 'Hackers' Sabotage Trains With $20 Radio
10:10
Seytonic
Рет қаралды 89 М.
Fake Crypto App Exposed
11:44
Seytonic
Рет қаралды 141 М.