.ZIP Domains Are a Disaster (Hackers Love them)

แชร์
ฝัง
  • เผยแพร่เมื่อ 30 ก.ค. 2024
  • $5 Free Credit 👉 PCBWay pcbway.com/g/gS3qI9
    Timestamps:
    0:00 Intro
    0:28 A very. Bad. Idea
    1:56 Sophisticated Phishing Links
    4:43 In Defence of .Zip
    5:57 PCBWay
    6:36 Outro
    Sources:
    / the-dangers-of-googles...
    www.bleepingcomputer.com/news...
    www.ghacks.net/2023/05/15/goo...
    www.blog.google/products/regi...
    isc.sans.edu/diary/The+zip+gT...
    isc.sans.edu/diaryimages/zipd...
    www.theregister.com/2023/05/1...
    github.com/trickest/zip/blob/...
    ===============================================
    My Website: www.seytonic.com/
    Follow me on TWTR: / seytonic
    Follow me on INSTA: / jhonti
    ===============================================
  • บันเทิง

ความคิดเห็น • 757

  • @NicholasArmstrong-rn1zn
    @NicholasArmstrong-rn1zn ปีที่แล้ว +2013

    You know it's bad when you're relatively tech savvy but can confidently say you would fall for something...

    • @Daveeeeeeyhowyoudoing
      @Daveeeeeeyhowyoudoing ปีที่แล้ว

      Relative to what, your 80 year old grandmother? A rock?
      If you were tech savvy, you would have an extension that does Grammer checks for you.... You would realize you are relatively stupid

    • @Splarkszter
      @Splarkszter ปีที่แล้ว +74

      yup. now gotta be scared of every markdown.

    • @Izzythemaker127
      @Izzythemaker127 ปีที่แล้ว +55

      Agreed, I would most likely fall for this if I hadn't known, and might still. Idk who's idea it was to store PLAIN TEXT LOG IN CREDENTIALS IN THE URL WITH A COMMONLY USED SYMBOL in the first place

    • @yeetyeet7070
      @yeetyeet7070 ปีที่แล้ว +17

      @@Izzythemaker127 nah thats fine. the .zip TLD is the problem

    • @its_herocast276
      @its_herocast276 ปีที่แล้ว +7

      @@yeetyeet7070 Putting plain text login credentials in the url is "fine" according to you?? Seriously?

  • @Fasguy
    @Fasguy ปีที่แล้ว +1248

    The zip TLD is genuinely one of the dumbest decisions Google has ever made.
    Hey, let's add exe as a TLD as well, while we're at it.

    • @UriahStuff
      @UriahStuff ปีที่แล้ว +158

      Let's add PNG, JPG, MP4, and MP3.

    • @ocsanik502
      @ocsanik502 ปีที่แล้ว +90

      @@UriahStuff and .elf, .bin, .so, and .dll aswell

    • @bitten2up
      @bitten2up ปีที่แล้ว +56

      ​​@@ocsanik502 oh and dont foget about .c, .c++ and .cpp, .c# .. and finally .a

    • @homework8969
      @homework8969 ปีที่แล้ว +44

      wait dont give them ideas (and .o, .dir, .tga)

    • @ocsanik502
      @ocsanik502 ปีที่แล้ว

      @@bitten2up and .h, .asm, .py, and .sh

  • @mfaizsyahmi
    @mfaizsyahmi ปีที่แล้ว +917

    My biggest question is: Who the heck let Google be a TLD registrar???

    • @plasticstuff69
      @plasticstuff69 ปีที่แล้ว +73

      Anyone can be a domain registrar lol?

    • @himabimdimwim
      @himabimdimwim ปีที่แล้ว +171

      ICANN.

    • @Tim_van_de_Leur
      @Tim_van_de_Leur ปีที่แล้ว +191

      @@himabimdimwim its called ICANN, not ICANNOT :P

    • @adispenser
      @adispenser ปีที่แล้ว +44

      @@plasticstuff69 anyone can register a domain but google can create them

    • @wiger_
      @wiger_ ปีที่แล้ว +90

      they let you do anything if you donate millions per year

  • @sherlockmaverick
    @sherlockmaverick ปีที่แล้ว +303

    You and I, maybe we can be on the lookout for this. How on earth am I going to explain this to the infinitely large swathes of non-tech-savvy people I know?!
    Bad move, Google. Very bad.

    •  ปีที่แล้ว +1

      I guess we have to save this video to explain to those non technical people. 😅

    • @Vysair
      @Vysair ปีที่แล้ว +6

      @Dave Dörenberg-Veltman It needs to be shorter because of the garbage attention span

    • @DJ_POOP_IT_OUT_FEAT_LIL_WiiWii
      @DJ_POOP_IT_OUT_FEAT_LIL_WiiWii ปีที่แล้ว

      put mouse over link, look in status bar...

    • @Stroopwafe1
      @Stroopwafe1 ปีที่แล้ว

      ​​@@DJ_POOP_IT_OUT_FEAT_LIL_WiiWii *user proceeds to put their physical mouse over the monitor where the URL is, asking "where is the status bar?"*

    • @friendsfrenz1944
      @friendsfrenz1944 ปีที่แล้ว

      ​@@Vysair honestly non tech savvy users will just read the title and believe it... as long as they relatively trust you
      They will care about this stuff

  • @Tarodenaro
    @Tarodenaro ปีที่แล้ว +192

    Sweet, please make a video once a google employee gets pwnd by this domain lol

    • @Seytonic
      @Seytonic  ปีที่แล้ว +65

      I'll be on the lookout 👀

    • @GameMaker3_5
      @GameMaker3_5 ปีที่แล้ว +1

      ​@@Seytonic It'll be ebic ;)

  • @metcaelfe
    @metcaelfe ปีที่แล้ว +620

    It was irresponsible to allow the TLD in the first place

    • @i_am_a_real_cat1443
      @i_am_a_real_cat1443 ปีที่แล้ว +1

      what is a tld?

    • @ahsokaincognito
      @ahsokaincognito ปีที่แล้ว +40

      Absolutely. I cant think of one legitimate business which would use this tld

    • @ahsokaincognito
      @ahsokaincognito ปีที่แล้ว +27

      ​@@i_am_a_real_cat1443 top level domain, the part behind the last dot in a domain. Like net, de, fr

    • @troughy3288
      @troughy3288 ปีที่แล้ว +2

      @@i_am_a_real_cat1443 top level domain

    • @fiverZ
      @fiverZ ปีที่แล้ว +3

      How can Google even issue their own TLD's?

  • @muizzsiddique
    @muizzsiddique ปีที่แล้ว +405

    When .rar and .7z TLDs exist, we will know that this act was malicious the whole time.

    • @danieljaouen9384
      @danieljaouen9384 ปีที่แล้ว +34

      Google wouldn’t do this because they need plausible deniability.

    • @scottc5181
      @scottc5181 ปีที่แล้ว +45

      Along with .tar and all will be covered.

    • @chromefinch
      @chromefinch ปีที่แล้ว +27

      .exe tld
      I quit

    • @madman4043
      @madman4043 ปีที่แล้ว

      That's not how this works. At all. One bad decision followed by more bad decisions doesn't prove it was malicious, just that they make a lot of bad decisions.

    • @bitten2up
      @bitten2up ปีที่แล้ว +8

      @@scottc5181 .gz and .tar.gz tld

  • @evaneevee8398
    @evaneevee8398 ปีที่แล้ว +202

    The fact that the people at the head of this thought it's a good idea to create a .zip domain possibly scares me. It's like they don't even care what happens to their loyal customers. Even as someone who doesn't interact with much outside of a couple friends, I'm worried about falling for one of these now. This opens up so many more attack opportunities that it's quickly becoming dangerous to even download anything that normally sends you to a blank page that auto downloads the file.

    • @Daveeeeeeyhowyoudoing
      @Daveeeeeeyhowyoudoing ปีที่แล้ว +2

      Cry about it 😂😂😂

    • @bubba99009
      @bubba99009 ปีที่แล้ว +25

      They don't care what happens to their customers. It's all about that $15/year.

    • @MischieviousJirachi
      @MischieviousJirachi ปีที่แล้ว +25

      ​@@Daveeeeeeyhowyoudoing no one reply to this guy, they're not serious and jus wanna make u mad

    • @dabster291
      @dabster291 ปีที่แล้ว

      @@MischieviousJirachi report them for harassment instead

    • @vvert1506
      @vvert1506 ปีที่แล้ว

      @@MischieviousJirachi but what if i like their attitude?

  • @GatlingNG
    @GatlingNG ปีที่แล้ว +247

    Who could have seen this coming! That anyone thought that having a gtld be an archive file extension was a good idea is beyond me.

    • @Appoxo
      @Appoxo ปีที่แล้ว +15

      Next one will be .rar and .7z/7zip?

    • @martenkahr3365
      @martenkahr3365 ปีที่แล้ว +17

      The core problem is that Google has paid enough money to ICANN to become a TLD registrar. They didn't need to get any outside opinion or permission to create that tld. I imagine the most that happened was more technical people downstream explaining why this was a bad idea and the business sociopath who only sees the potential revenue of selling those domains to criminals making responding with "Okay, your concerns are noted. Now do it anyway or I'm replacing you with someone who will."

    • @LePedant
      @LePedant ปีที่แล้ว +1

      That's called the Dunning-Kruger effect. It occurs when a person's lack of knowledge and skills in a certain area cause them to overestimate their own competence.

    • @deality
      @deality ปีที่แล้ว

      ​@@Appoxo lol

  • @YEdwardP
    @YEdwardP ปีที่แล้ว +140

    I'm a reasonably tech-savvy, non-expert user and having heard your arguments, I am now convinced that this was a bad idea and should be undone.

    • @LePedant
      @LePedant ปีที่แล้ว +4

      That's called the Dunning-Kruger effect. It occurs when a person's lack of knowledge and skills in a certain area cause them to overestimate their own competence.

    • @turolretar
      @turolretar ปีที่แล้ว +2

      @@LePedant pretty sure it’s called the “Dumb-n-cruder effect”, but I’m not an expert.

    • @LePedant
      @LePedant ปีที่แล้ว

      @@turolretar Lol, sounds like something Michael Scott from The Office would say.

    • @kumi6797
      @kumi6797 11 หลายเดือนก่อน

      @@LePedant can't go wrong, right?

  • @xaza8uhitra4
    @xaza8uhitra4 ปีที่แล้ว +63

    don’t know about you guys but i can’t wait to click on all the .zips i see

  • @FAB1150
    @FAB1150 ปีที่แล้ว +93

    It's a thing I would fall for if I didn't follow all the drama... How the hell will I explain this to my parents?

    • @Tim_van_de_Leur
      @Tim_van_de_Leur ปีที่แล้ว +3

      Just unplug them :P

    • @truerandomchannel
      @truerandomchannel ปีที่แล้ว +4

      don't let them click ANY links

    • @freedustin
      @freedustin ปีที่แล้ว +20

      "Stop using the internet, its by criminals for criminals now."

    • @FAB1150
      @FAB1150 ปีที่แล้ว +5

      @@truerandomchannel the whole thing is that these links don't look like links

    • @joelpww
      @joelpww ปีที่แล้ว +1

      ​@@FAB1150 exactly. The challenge of explaining to most people would be extremely hard

  • @AdamS-nd5hi
    @AdamS-nd5hi ปีที่แล้ว +66

    Google been comfortable collecting checks from black hats for years. Wouldnt suprise me if they put these features out specifically for thwm to drum up new rev streams. Orgs should block zip and mov sites in their dns internally

    • @suncat530
      @suncat530 ปีที่แล้ว +3

      i want to learn more, do you have links to some sort of articles talking about that?

    • @apIthletIcc
      @apIthletIcc ปีที่แล้ว

      And carriers should do the same, somehow though it still isn't happening. Gotta wonder why.

    • @khorps4756
      @khorps4756 ปีที่แล้ว

      I agree. Google is a known cyber fraud company already, so it's no surprise.

    • @AdamS-nd5hi
      @AdamS-nd5hi ปีที่แล้ว

      @@suncat530 there are tons of vids showing google accepting add rev from hackers running scam/pjishing sites and advertising ad the real thing. And they do nothing to stop them

    • @garbagetrash2938
      @garbagetrash2938 ปีที่แล้ว

      I understand why carriers don't want to do it, but I'm already writing custom ElasticSearch rules to alert to any .zip TLDs navigated to.

  • @eddiewramos
    @eddiewramos ปีที่แล้ว +21

    My grandmother’s computer stands no chance now

  • @barjo_
    @barjo_ ปีที่แล้ว +38

    Can't wait to be hyper paranoid when downloading any zip file from now on

    • @garbagetrash2938
      @garbagetrash2938 ปีที่แล้ว

      Virus total is gonna be everyone's best friend.

  • @hubeldubel9730
    @hubeldubel9730 ปีที่แล้ว +22

    Thanks for pointing that out.
    I've added the .zip TLD to my pi hole's regex blacklist, such as many other suspicious TLDs too.

  • @sion-music
    @sion-music ปีที่แล้ว +58

    It sounds to me like the Markettng department at Google managed to override all the sensible teams (Security, IT, Dev, and practically any other technical team). There is a reason that Marketing departments are often referred to as "the colouring-in team".

    • @vvert1506
      @vvert1506 ปีที่แล้ว

      i hate sales i hate marketing i hate the antichrist i hate car culture i hate pussy

  • @SaburoOkita
    @SaburoOkita ปีที่แล้ว +148

    Google is gonna paddle back and introduce a .rar domain instead!

    • @Seytonic
      @Seytonic  ปีที่แล้ว +81

      Maybe we'll get an .exe one day..... Introducing the .exe TLD, where hackers can now confuse you with websites that look like harmless files, making every click a thrilling game of chance. Stay on your toes and pray you don't accidentally download a virus!

    • @seailz
      @seailz ปีที่แล้ว +12

      @@Seytonic Sounds like something they'd do 💀

    • @cfryantofficial
      @cfryantofficial ปีที่แล้ว +13

      @@Seytonic Yep. Gotta get that domain for all your executives. 😂

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked ปีที่แล้ว +1

      ​@@Seytonic true, though I don't do redundant , begging, and debunked prayer. Hehe

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked ปีที่แล้ว

      I think it's cool. :3

  • @Amy_A.
    @Amy_A. ปีที่แล้ว +18

    Why am I not surprised that Google continues to make literally everything they touch just a little bit worse?

  • @dimitribarronmore
    @dimitribarronmore ปีที่แล้ว +72

    In my opinion, browsers should just refuse to resolve TLDs like this. I don't particularly care that it would be walling off anyone who purchases a .zip or similar domain, the only way to shut something like this down is to simply refuse to comply. Make the .zip TLD completely useless and the problem will solve itself.
    Unfortunately we all know that's never happening, seeing as the people who issued the TLD also make the most popular browser, but a clear "potentially malicious link" warning would at least be nice.

    • @BrainPermaDeD
      @BrainPermaDeD ปีที่แล้ว +4

      The main problem is people hate to coordinate. So Shrome is staying.

    • @Mernom
      @Mernom ปีที่แล้ว +1

      You can set up your group policy, or setup your DNS to reject them.

    • @Heknon
      @Heknon ปีที่แล้ว

      You can add a firewall rule to reject this

    • @Voorhees-Jason
      @Voorhees-Jason ปีที่แล้ว

      problem is chrome is one of those browsers lol and a lot and i mean a lot of people uses chrome. Good luck with that one.

    • @donit.
      @donit. ปีที่แล้ว

      you realize that basically every browser except firefox is based on chrome?

  • @username65585
    @username65585 ปีที่แล้ว +86

    Who thought zip was a good idea for a TLD?

  • @notpumkin
    @notpumkin ปีที่แล้ว +34

    Honestly, it's still insane that chrome automatically downloads files by default.

    • @user-xz1ur8us5p
      @user-xz1ur8us5p ปีที่แล้ว +6

      You could configure it to ask where to download each file before actually downloading. But that needs to be set up after the fact when it should be the default setting imo.

    • @gavinthecrafter
      @gavinthecrafter ปีที่แล้ว +3

      Downloading files by themselves is not much of a security threat, right? The program still needs to be executed for it to be malicious

    • @mahdi9064
      @mahdi9064 ปีที่แล้ว +4

      ​@@gavinthecrafter until your windows security decide that it wants to extract a zip file to check for cp or illegal content, and poof you are hacked.

    • @L2002
      @L2002 ปีที่แล้ว +5

      @@mahdi9064 Clearly you don't know how antivirus work.

    • @garbagetrash2938
      @garbagetrash2938 ปีที่แล้ว +2

      ​@@gavinthecrafter this type of attack is called a drive-by download and no it is not particularly dangerous.
      Most organizations will have some type of EDR like carbon black or crowdstrike, that will stop execution anyway.
      It's just stupid to introduce an unnecessary, confusing way for threat actors to make phishing, the most common type of initial access, even easier.

  • @-morrow
    @-morrow ปีที่แล้ว +6

    2:50 userinfo in url's isn't a legacy feature. it is very often used as username@host for other protocols like e.g. ssh

  • @tayyabnaveed2266
    @tayyabnaveed2266 ปีที่แล้ว +12

    there should be a committee that looks at more things than just the transaction number.
    Like the potential ramifications of allowing the TLD to exist

  • @starchy_
    @starchy_ ปีที่แล้ว +14

    there is a workaround to make sure you dont fall for this, add the following to your adblocker of choice (which should be ublock origin)
    ||zip^$document
    ||mov^$document
    this will block visiting sites with .zip and .mov tlds, while still allowing recources to be fetched from them (like if google decides no use a .mov domain to serve yt videos) and allowing "zip" and "mov" everywhere else in the url.
    this should give you a nice warning to let you know youre making a mistake, but its not a fix for the underlying problem, and will only really help for already tech savvy users.

    • @arcticcircle9178
      @arcticcircle9178 ปีที่แล้ว

      What do you mean by "allowing resources to be fetched from them"? Would you still be able to accidentally download malicious zip files?

  • @BWAC
    @BWAC ปีที่แล้ว +8

    Well there goes my Monday, Blocking all TLDs that resemble file names >.< - I await to see a .rar, .7z, .zip or god forbid tax_invoice.xlsx

    • @jer1776
      @jer1776 ปีที่แล้ว

      Good idea, hopefully someone makes a DNS server that does just that

  • @uwuifyingransomware
    @uwuifyingransomware ปีที่แล้ว +15

    I understand what you’re saying about web developers implementing safety features like not auto linking, but I see a bigger issue in that random web developers should not have to pick up the pieces after a terrible decision by google. Firstly because it’s not their responsibility (it is google’s, for making a decision that will so obviously go wrong), but also because the average web developer can’t reasonably be expected to know this is happening. That’s not even mentioning the amount of programs that are actively used but don’t receive updates.

  • @alethephobe7586
    @alethephobe7586 ปีที่แล้ว +35

    Your videos are the best. Seriously there's no better channel for cybernews. Thank you sincerely.

    • @Seytonic
      @Seytonic  ปีที่แล้ว +9

      Thanks my dude, I appreciate it :)

  • @christopherg2347
    @christopherg2347 ปีที่แล้ว +5

    When programmers have to add a _exclusion_ for .zip domains, you already fucked up.
    That is a SQL-Injection sized issue - because now programmers have to be aware and invest extra effort just to not cause a issue.

  • @ChefGoreb
    @ChefGoreb ปีที่แล้ว +59

    The shitstorm once it'll be made public that the first google employee fell for this is gonna be gold.
    Worst idea ever Google. Also, I'm still mad u cancelled Wave.

    • @Amy_A.
      @Amy_A. ปีที่แล้ว +4

      I sincerely hope they do, and I hope it finally spooks the public into realizing how little value they actually provide nowadays.

    • @tehjamerz
      @tehjamerz ปีที่แล้ว

      I'm still mad about Google video

  • @bubbleteaichooseyou
    @bubbleteaichooseyou ปีที่แล้ว +8

    I'm not gonna try to defend myself. I work in IT and I think I would fall for it as well

  • @blinking_dodo
    @blinking_dodo ปีที่แล้ว +6

    The @ before domain is still widely used in ssh.
    It is used to specify which username you want to use on the ssh server.

  • @DragoNate
    @DragoNate ปีที่แล้ว +4

    So to remind everyone about links:
    *_DO NOT CLICK RANDOM LINKS_* Even if it comes from a "credible" source.
    check, double check, recheck and check again for good measure.

  • @mordor_3
    @mordor_3 ปีที่แล้ว +12

    Google really going for the big brain manouvers. 🤔

  • @Christopher_S
    @Christopher_S ปีที่แล้ว +9

    Wow. I never saw this coming....
    Google with their ever increasing stupidity, but as long as they can make some money out of it eh?

  • @reegyreegz
    @reegyreegz ปีที่แล้ว +6

    Lol, time to super-harden my home network due to my elderly parents being on it. This will be a nightmare

  • @edgars9581
    @edgars9581 ปีที่แล้ว +4

    Firefox actually asks to confirm when navigating userinfo URLs, so it is less likely to work on it as on Chrome

  • @lucidattf
    @lucidattf ปีที่แล้ว +30

    just because an issue was marked wontfix years ago doesn't mean they can't change their mind if the user credentials in URL trick ever becomes a common attack. auto-hyperlinking domains is the only real concern here, and it can be fixed easily by web developers

    • @stage6fan475
      @stage6fan475 ปีที่แล้ว +15

      Ah, but in the modern internet, just because an issue can be easily fixed by web developers doesn't mean it ever will except for a small minority of cases.

  • @_JohnHammond
    @_JohnHammond ปีที่แล้ว +2

    Appreciate the nod @Seytonic! :) Hope to have helped with at least some of the blast radius...

  • @CreoSM
    @CreoSM ปีที่แล้ว +9

    This is seriously a bad idea, they could have chosen anything else but this

  • @BorealBlizzard
    @BorealBlizzard ปีที่แล้ว +10

    Hehehe, I just bought one because they are surprisingly cheap. Using it for a personal landing page and some self hosted services because it's nice and short.

  • @gus473
    @gus473 ปีที่แล้ว +7

    Read about this example last night, and I think your animated version does a great job of making it more understandable! Yeah, potential mess! Thanks! 😎✌️

  • @___gg421
    @___gg421 ปีที่แล้ว +4

    This was definitely a decision made my a non technical manager type who is refusing to back down now

  • @asdprogram
    @asdprogram ปีที่แล้ว +1

    Thanks for letting us know! You're the best! 👍

  • @wantacupoftea
    @wantacupoftea ปีที่แล้ว +10

    Not often i find something I would actually fall for. Thanks for bringing it to my attention

  • @bubba99009
    @bubba99009 ปีที่แล้ว +8

    This just seems like a gift to hackers. Not sure what the legitimate use case is. Also it's ridiculous the number of TLDs being created just in general. I guess it's close to 100% profit for the registrars and that's the motivation behind it.

    • @freedustin
      @freedustin ปีที่แล้ว +2

      Not a gift. A sales pitch.

  • @LabiaLicker
    @LabiaLicker ปีที่แล้ว +2

    This is all going to get worse with Google having complete control over the web now....

  • @Sound_.-Safari
    @Sound_.-Safari ปีที่แล้ว +2

    Too many projects not maintained to receive updates that would prevent auto highlight of .zip domains. Though maybe they wouldn’t recognize them anyways. Either way I think it’s too confusing for the end users that are unlikely to learn about it. Adds a tool for phishers and seems low value for the TLD domain space

  • @1cindy8552
    @1cindy8552 ปีที่แล้ว +2

    there must have been AT LEAST one person in the Google team that knew the repercussions and stayed quiet. no?

  • @douro20
    @douro20 ปีที่แล้ว +1

    The "backup" one serves a random backup-related quote.

  • @TheUnknownCatWarrior
    @TheUnknownCatWarrior ปีที่แล้ว +2

    Set your browser to ask before downloading and you will save your self from those websites that redirect you to an automatic download.

  • @Reeces_Pieces
    @Reeces_Pieces ปีที่แล้ว +2

    Blocked the whole TLD after seeing that medium article example. That's just too sneaky.

  • @descuddlebat
    @descuddlebat ปีที่แล้ว +5

    I've been using URLs with @ for SSH logins and git clones for some time now, yet I absolutely would've fallen for this one on any font that doesn't give away the slashes... Can we go back to when my online safety wasn't dependent on font choice please

    • @-morrow
      @-morrow ปีที่แล้ว +4

      yeah, userinfo in urls certainly isn't a "legacy feature" as he seytonic said

  • @jacobelgan5196
    @jacobelgan5196 ปีที่แล้ว +1

    Google doing such a seemingly dumb action implies to me that there's something going on behind the scenes that extends to beyond network security that had influenced its existance

  • @cephy8102
    @cephy8102 ปีที่แล้ว +3

    Welp, now I just have all the more reason to double-check every link I see lol

  • @KO6BXL1
    @KO6BXL1 ปีที่แล้ว +3

    we won't believe the amount of normal company employees falling for this

  • @somedude7447
    @somedude7447 ปีที่แล้ว +2

    This is a really bad idea. What legitimate domains would use this? A zipper company or maybe compression software like 7zip? The negatives far outweigh the positives. Waiting on the .exe/.dmg domains next.

  • @sirshark10
    @sirshark10 ปีที่แล้ว +1

    Noting your browser section, Firefox has had a feature to combat this *sort of* for a little bit at least. When you try to connect to a page with a username that doesn't take a login, it will immediately prompt you before navigating.

  • @DragonNuts
    @DragonNuts ปีที่แล้ว +2

    I feel like this on the Google ads thing it seems like Google wants people to get hacked

  • @bettercalldelta
    @bettercalldelta ปีที่แล้ว +2

    I wouldn't even be surprised if google knew exactly what they were doing. It's all about the $$$

  • @RokeJulianLockhart.s13ouq
    @RokeJulianLockhart.s13ouq ปีที่แล้ว +17

    I believe that we should only have TLDs for each internet governance authority, since that's what they're for - to designate where to send domain resolution requests to.

  • @chickenroyalty9233
    @chickenroyalty9233 ปีที่แล้ว

    never knew about this thank you very much for spreading the word

  • @FrancescoRosi27
    @FrancescoRosi27 ปีที่แล้ว +12

    I've always been a little skeptical of .zip ever since Google announced it. Guess my skepticism was well placed!

  • @Jack-vv7zb
    @Jack-vv7zb ปีที่แล้ว

    How's the gmail one any different to just changing the text of a link? Both reveal the true destination on hover.

  • @HandlesSuck
    @HandlesSuck ปีที่แล้ว +21

    Why on earth did they choose .zip? Is there a logical reason?

    • @Amy_A.
      @Amy_A. ปีที่แล้ว +10

      "Because we're richer than a million millionaires, so screw you" -Alphabet

    • @dunk7605
      @dunk7605 ปีที่แล้ว

      money

  • @Brainiac469
    @Brainiac469 ปีที่แล้ว

    What are the fonts that make it look weird . Perhaps if we use those it would be an easy way to spot malicious links.

  • @mirrikybird
    @mirrikybird ปีที่แล้ว +1

    how would you even blacklist these hyperlinks on a company email system without also blacklisting the mention of a .zip file or a normal download link to a web hosted .zip file?

  • @electricalmayhem
    @electricalmayhem ปีที่แล้ว

    Does anyone know of a good Firefox extension that will highlight or block unusual Unicode in URLs?

  • @lamjeri
    @lamjeri ปีที่แล้ว +1

    Firefox actually does some work in this regard. As you mentioned, everything before the @ sign is considered a username (and password if there's a : as well), so when you click on such a malicious link, but the landing page doesn't accept logins, Firefox displays a message saying if you're sure you want to proceed because you're about to land on a page that didn't request a login, but the link provided one. Not completely fool proof, but it's a step in the right direction.

  • @alexanderklee6357
    @alexanderklee6357 ปีที่แล้ว +5

    Googles big brain move here is capitalizing on White hats who will buy up .zip domains xD

  • @TommyvanWanroij
    @TommyvanWanroij ปีที่แล้ว

    Thanks for the amazing tutorial, will be useful.

  • @charlottenburg
    @charlottenburg ปีที่แล้ว +8

    Buying a .zip asap

  • @bioman2007
    @bioman2007 ปีที่แล้ว +3

    Liked and sub, Amazing video!
    Pd: Google's motto "Don't be evil" now looks more like just another corporate cliche.

    • @tursilion
      @tursilion ปีที่แล้ว +8

      They dropped that motto back in 2018 ;)

  • @AntonioNoack
    @AntonioNoack ปีที่แล้ว +1

    I see the bigger issue in Chromium allowing fake slashes in user credentials / allowing user credentials there at all.
    I'd like to see them removed, and the issue is done.

  • @shalwinbabu645
    @shalwinbabu645 ปีที่แล้ว

    Does clicking on a link automatically download executables that also run without us doing anything??

  • @chrisoakleyfx
    @chrisoakleyfx ปีที่แล้ว +1

    The scary/infuriating thing about this is that I would 100% fall for this if there were no other obvious red flags of a phishing scam. Those links are very convincing. Sure I wouldn't be dumb enough to open a zip file from a random email (be it an actual .zip or an obfuscated URL), but if it is socially engineered in the right way that gives me little reason to question the authenticity, then sure I could see myself falling for this 👀

  • @Beffel
    @Beffel ปีที่แล้ว

    My Mail-Provider (it's a quite common one in germany) changes links to some very long url, that gets cut by the browser. They pretend it's a security-check-feature, but for me it looks like an additional landing page to put ads. So even if I try to hover such links, I'm clueless...

  • @TILR
    @TILR ปีที่แล้ว

    Could a browser extension be made that detects the fake slashes and blocks you from going to that site?

  • @SzaboB33
    @SzaboB33 ปีที่แล้ว +2

    I have experience reporting bugs to chromium. They refuse to care if it's not something super critical. :D

  • @its_herocast276
    @its_herocast276 ปีที่แล้ว +2

    Lesson learned, hover your cursor above a zip download link to check the domain.

  • @1cindy8552
    @1cindy8552 ปีที่แล้ว

    easy explanation, good graphics.
    you got a new subscriber ;)

  • @arsen3223
    @arsen3223 ปีที่แล้ว +2

    If you are phishing someone through gmail with the zip tld then wait until you hear about link display texts. You can already do these download urls scams with any domain. Just checked discord and looks like the part before the @ gets removed in your message. Telegram also has link display texts. But sure, if I see it on a website, I'd probably fall for it

    • @winkcla
      @winkcla ปีที่แล้ว

      I was thinking about this as well. If you control the email body, obfuscation in the link display text is meaningless. And people are already much less likely to inspect the actual URL. For all apps that auto-link domains written without a protocol in all user content it's going to be really annoying and possibly dangerous as stated in the video

  • @rfkgaming
    @rfkgaming ปีที่แล้ว +1

    this is why I have zip and mov blocked at a domain level in my firewall it will just get sent to a blackhole on my network.

  • @physicsgrad
    @physicsgrad ปีที่แล้ว +3

    I guess blocking out the .zip TLD via some DNS resolver could be a solution, for now.

  • @n-i-n-o
    @n-i-n-o ปีที่แล้ว +2

    Im using NextDNS, and I block new registered Domains and the whole .ZIP Domain by default.

  • @valcaron
    @valcaron ปีที่แล้ว

    Would one solution be to use a local bind server as a nameserver, and configure it to refuse to resolve any IPs that correlate to anything within a certain blacklist of TLDs? Is that even possible?

    • @momentomori1747
      @momentomori1747 ปีที่แล้ว

      Nextdns does it easily. Just set up your security config on the site and swap out your dns servers

  • @sanityd1
    @sanityd1 ปีที่แล้ว +5

    o god another thing I need to try and explain to my parents - also PCBway even got to you lol

    • @HandlesSuck
      @HandlesSuck ปีที่แล้ว

      I share your pain.

    • @bruh83483
      @bruh83483 ปีที่แล้ว

      whar wrong with him being sponsored

  • @liquidsnake6879
    @liquidsnake6879 ปีที่แล้ว +1

    I think web browsers should just blacklist such websites and not treat them as hyperlinks, if someone wants to manually type it in their address bar fine, if not then it shouldn't be rendered as a hyperlink, you can probably make a chrome extension that does this for people

  • @siouxWaits
    @siouxWaits ปีที่แล้ว +1

    Why big companies love these days to 'unsecure' the masses ? Lately Discord and Ledger and now Google. What they're up to ???

  • @AvenFurness
    @AvenFurness ปีที่แล้ว +2

    Upcoming TLDs include: .exe, .docx, .pdf, .mp3 and .png!

  • @RokeJulianLockhart.s13ouq
    @RokeJulianLockhart.s13ouq ปีที่แล้ว +1

    What's the link to that Chromium bug report?

  • @Dudeplay
    @Dudeplay ปีที่แล้ว

    Thanks for the video, will block tomorrow every .zip domain for dna resolution in the firm.

  • @roulzhq
    @roulzhq ปีที่แล้ว

    The email sender Matt holt being the creator of the caddy server btw. Awesome guy pushing for security in the web space

  • @chukaml
    @chukaml ปีที่แล้ว +1

    Because Google wants more money. Not a bit more but globally much more money. More types of TLD means a company owner needs to register more domain names to protect against domain name abuse.

  • @In_swedish_the_jam_means_sylt
    @In_swedish_the_jam_means_sylt 11 หลายเดือนก่อน

    I want to create your kind of stock photos 😂 they are great

  • @g-program-it
    @g-program-it ปีที่แล้ว +1

    cheers for sharing this.
    Another potential exploit to look out for.

  • @nickname7760
    @nickname7760 ปีที่แล้ว

    I would have been fallin' for this. Thanks

  • @gameboyv1790
    @gameboyv1790 ปีที่แล้ว

    Anyone know how to make a drive by download that automatically starts

  • @Yune_Faded
    @Yune_Faded ปีที่แล้ว +1

    Okay i seriously wondering which Engineer or cyber security specialist thought making file name domains was a smart idea. Honestly this just sounds like some marketing people convincing executives that they could earn a lot of money and not listening to engineers

  • @SioxerNikita
    @SioxerNikita ปีที่แล้ว +1

    Most of this seems more like other security failures that are being exposed now