In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears to be fully valid. However all the links use a domain c.gle and whois c.gle errors with "getaddrinfo(whois.nic.gle): Name or service not known". whois gle however does work. I was not sure of the validity of c.gle myself, my step-mother would have no idea.
not that it really helps to know now, but .gle is a TLD operated by Google. the only domains on a .gle domain will be Google (in theory). Plus, a single letter domain (on any TLD), like c.gle would be expensive to burn on a phishing scam.
But no one should need to know this. I don't know what's so wrong about just using google.com, or even .google for anything user facing...
I understand the idea that they want an official TLD that doesn't necessarily have their trademark in it, so you know it's a link to a Google service but potentially user content, but why have c.gle links to official/urgent messaging??
(at least they don't use 1drv.com in emails like Microsoft.. seriously...)
You know what? If someone shows me a shortcode on my feature phone, or on someone else's device, or it's printed on a leaf of paper, or if I'm in a library using library computers, a shortened URL like that is way easier to type in, or write it down by hand.
However you slice it, even after we conquer character limits and font rendering and storage space for every electronic device, human beings will still be using "the analog hole" to copy code like that.
It's interesting to imagine how different the entire security landscape would be, if every human was natively capable of easily transcribing many more bytes of data and noticing when two sequences don't match.
I agree, but I'd also challenge you to find a cellphone that a normal person carries that doesn't just concatonate multiple messages and turn them into MMS. My Pinephone and Librem 5 did that, but that reinforces my point: this is not something a normal person will see
Wait, multiple messages get concatenated to MMS? In early 2010s I remember in my country it's still concatenated as regular text (so if one part is somehow missing or comes in very late, some phones will only show the surviving parts as one, others dump each parts separately), I guess they remove that functionality? Back then each part cost roughly one cent and plenty of phones in use still don't support MMS, then people just jump into WhatsApp entirely when Nokia support it in their feature phone.
Even if you retrieve registration information about a domain, that will not necessarily help a consumer figure out if it is legitimate, or who owns it. There will be a lot of redactions and shell companies and generic information.
The target market for WHOIS and RDAP has always been administrators and registrants and others on their level. Obviously--RDAP is a JSON format, not plain text anymore!
As a consumer, if you're trying OSINT, try not to spread that around, because it is another opportunity for deception, confusion, and cargo culting. What you want is good malware protection, according to your actual risk profile. If your browser protection is worthwhile then it will stop attacks from domains like that.
If you are particularly worried about strange domains, many 3rd-party DNS services can block those. NextDNS had a checkbox for "block newly-registered domains" as well as filtering any sus gTLD or ccTLD type ones.
ICANN: “All gTLD registries and registrars are required to provide RDAP services.” They are listed at lookup.icann.org and the one in question is https://pubapi.registry.google/rdap/domain/c.gle
Even if they did (and I dont see any evidence either way), lobsters is an entirely different site (that also requires invites, excluding the majority of users from commenting).
Since the other person decided to not post it on HN I dont see the harm in someone else reposting it here. Likewise if someone discovers something neat via HN they might repost it on, say, reddit (or vice versa).
We can do Reddit on HN if we want -- hell I'm jonesing for it, I bristle at restrictions on my literary tone... but obsessing over who "stole" a link seems juvenile.
Just to clarify, do you "indeed" that links can't be stolen, or do you "indeed" the idea that we should all just adopt the ironic detached tone of the dirtbag left to discuss Current Events?
I favor a technique I was taught by a nursing student almost 30 years ago. You basically use the usual technique but each time the lace crosses another do it one extra time.
So first you wrap one lace around the other and pull it tight, well before you pull it tight wrap it around one more time. This helps hold the laces tight for the next step where you fold the laces and wrap them around each other. Do that a second time as well before you pull it fully tight.
Without video or illustration I suspect this is not easy to follow. Oh well.
Yes, I still use it and can confirm that I have had no concerns or problems with it. On the other hand, if I had to reinstall, without research, I'm not sure how I would reinstall it. Having alternatives is a good thing.
Don't make statements like this without more explanation. In what way is this happening to you specifically? What distribution and platform are you using? Did you explicitly install something to warn you about 'side-loading' executables?
My understanding is that there is a lot of very fine lunar dust and in the lower gravity even a small amount of static electricity on you means that you are quickly covered in the dust.
Right, and the dust is from shattered meteorites rather than erosion. So it has very sharp edges instead of being smoothed out by tumbling in water like terrestrial rock dust. Really not very good for them to breathe in.