HACKER Q&A
📣 elashri

Registering common .zip domains to help prevent phishing attacks?


Hi HN,

I recently registered the domain bank-statement.zip (and some mistyped variations), not because I plan to use it, but to prevent it from falling into the wrong hands. As some of you may know, .zip is a potentially dangerous TLD, as many chat and email clients will convert it to a clickable link, making it easy for attackers to trick unsuspecting users into downloading malicious files.

That got me thinking: what if we could collectively register common domain names that correspond to common .zip names that ordinary users or parents might get confused about? For example, we could register tax-return.zip, invoice.zip, or receipt.zip, among others. By doing so, we could prevent these domains from being misused for phishing attacks.

Of course, this initiative would require some coordination and funding, but I believe it's a worthwhile effort to protect users from falling victim to phishing scams. What do you think? Would you be interested in participating or supporting this initiative? It would be easy to register many domains as they are about $12. But some famous names will be more expensive beyond what a PhD student on stipend like me can afford.


  👤 xvello Accepted Answer ✓
Nope, let's not reward them with money. Lobby to get this idiotic TLD shut down. Otherwise someone will grab .pdf and .png soon.

👤 frantathefranta
On the day the .zip/.mov domains started trending, I looked at hunterbidenlaptop.zip but didn't want to shell out $17 just to sit on a domain. I see that it has now been taken.

👤 sen
There’s unlimited ways to create malicious domains with .zip, so unless you plan on buying tens of thousands of domains then you’re just throwing money away (and supporting the domain by giving them sales)

- windows-setup.zip

- macos-setup.zip

- -setup.zip

Same again for -installer.zip, -package.zip, -archive.zip, -update.zip, etc.

Then the generics..

- firmware-update.zip

- update-firmware.zip

- software-update.zip

- software-package.zip

- family-photos.zip

- blackmail-package.zip

- nude-pics.zip

- update-v13.zip (replace numbers as needed)

- firmware-v33.zip (and so on)

- installer-v70.zip (… you get the point, this is kinda fun)

I could go on forever.


👤 el_hacker
I think the better solution is if they just stop registering new .zip domains.