{"id":39417,"date":"2023-05-17T15:47:16","date_gmt":"2023-05-17T19:47:16","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=39417"},"modified":"2024-10-21T14:14:19","modified_gmt":"2024-10-21T18:14:19","slug":"zip-tld","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2023\/05\/17\/zip-tld\/","title":{"rendered":".zip TLD"},"content":{"rendered":"<p><a href=\"https:\/\/www.blog.google\/products\/registry\/8-new-top-level-domains-for-dads-grads-tech\/\">Christina Yeh<\/a> (<a href=\"https:\/\/twitter.com\/Google\/status\/1653866291692728320\">tweet<\/a>, via <a href=\"https:\/\/news.ycombinator.com\/item?id=35917362\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.blog.google\/products\/registry\/8-new-top-level-domains-for-dads-grads-tech\/\">\n<p>Google Registry has launched some of the most popular (and secure) top-level domains, such as .app and .dev. Today, we&rsquo;re adding eight new extensions to the internet: .dad, .phd, .prof, .esq, .foo, .zip, .mov and .nexus.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/shkspr.mobi\/blog\/2023\/05\/the-new-zip-tld-is-going-to-cause-some-problems\/\">Terence Eden<\/a> (via <a href=\"https:\/\/news.ycombinator.com\/item?id=35927509\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/shkspr.mobi\/blog\/2023\/05\/the-new-zip-tld-is-going-to-cause-some-problems\/\"><p>Many years ago, Google applied for the <tt>.zip<\/tt> Top Level Domain. ICANN, in its infinite wisdom, granted it. And now, I think, bad things are going to happen.<\/p><p>[&#8230;]<\/p><p>So what happens when things which are <em>not<\/em> domain names look like they are domain names? I&rsquo;ve been worrying about this for a few years[&#8230;] Anyway, have fun determining if the link you see was ever intended to link to a website!<\/p><\/blockquote>\n<p>He&rsquo;s referring to confusion over the <tt>.zip<\/tt> filename extension for compressed archives. Amazingly, the <a href=\"https:\/\/icannwiki.org\/index.php?title=.zip\">original idea<\/a> for the TLD was in reference to the Iomega Zip drive.<\/p>\n\n<p><a href=\"https:\/\/financialstatement.zip\/\">Karen West<\/a> (via <a href=\"https:\/\/news.ycombinator.com\/item?id=35920336\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/financialstatement.zip\/\"><p>You can now purchase .zip and .mov domain names, like the one this page resides on! Isn&rsquo;t that just fun for the entire family?<\/p><p>[&#8230;]<\/p><p>For decades engineers have been working hard to try and make the internet less susceptible to phishing attacks, look-alike domains, etc., and now money men have decided to unravel that work so somebody can purchase anyword.zip as a domain name.<\/p><\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2015\/02\/01\/who-else-kinda-misses-their-zip-disks\/\">Who Else Kinda Misses Their Zip Disks?<\/a><\/li>\n<\/ul>\n\n<p id=\"zip-tld-update-2023-05-18\">Update (2023-05-18): <a href=\"https:\/\/hachyderm.io\/@ezekiel\/110385859390714142\">Ezekiel Elin<\/a>:<\/p>\n<blockquote cite=\"https:\/\/hachyderm.io\/@ezekiel\/110385859390714142\">\n<p>I&rsquo;ve seen points claiming that apps will auto link something like <code>document.zip<\/code> and then a scammer could pre-emptively have created a scam website - but I feel like most systems don&rsquo;t auto link without <code>http(s):\/\/<\/code> and when they do it&rsquo;s usually just <code>.com\/.org<\/code><\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.ghacks.net\/2023\/05\/15\/googles-zip-top-level-domain-is-already-used-in-phishing-attacks\/\">Martin Brinkmann<\/a> (via <a href=\"https:\/\/norden.social\/@chucker\/110386443377042816\">S&ouml;ren<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.ghacks.net\/2023\/05\/15\/googles-zip-top-level-domain-is-already-used-in-phishing-attacks\/\">\n<p>The .zip extension allows cyber criminals to run phishing campaigns that abuse the fact that .zip is a popular file extension and also a top level domain.<\/p>\n<p>Domains such as officeupdate.zip or microsoft-office.zip have already been used in phishing campaigns. The latter is still online but safe browsing should warn users prior to accessing the site in question. Several of the registered domains could be used in phishing campaigns, while others may be used for legitimate purposes.<\/p>\n<p>[&#8230;]<\/p>\n<p>Some applications may attach hyperlinks to ZIP file names now, which may lead to the firing of DNS queries and the leaking of information to the .zip domain.<\/p>\n<p>The ICSS recommends to disable access to .zip domains entirely until the dust settles and risks can be accessed.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/medium.com\/@bobbyrsec\/the-dangers-of-googles-zip-tld-5e1e675e59a5\">Bobbyr<\/a> (via <a href=\"https:\/\/norden.social\/@chucker\/110388080666314958\">S&ouml;ren<\/a>):<\/p>\n<blockquote cite=\"https:\/\/medium.com\/@bobbyrsec\/the-dangers-of-googles-zip-tld-5e1e675e59a5\"><p>Can you quickly tell which of the URLs below is legitimate and which one is a malicious phish that drops evil.exe?<\/p><p>[&#8230;]<\/p><p>As you can see in the breakdown of a URL below, everything between the scheme <code>https:\/\/<\/code> and the <code>@<\/code> operator is treated as user info, and everything after the <code>@<\/code> operator is immediately treated as a hostname. However modern browsers such as Chrome, Safari, and Edge don&rsquo;t want users authenticating to websites accidentally with a single click, so they will ignore all the data in the user info section, and simply direct the user to the hostname portion of the URL.<\/p><\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Christina Yeh (tweet, via Hacker News): Google Registry has launched some of the most popular (and secure) top-level domains, such as .app and .dev. Today, we&rsquo;re adding eight new extensions to the internet: .dad, .phd, .prof, .esq, .foo, .zip, .mov and .nexus. Terence Eden (via Hacker News): Many years ago, Google applied for the .zip [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2023-05-17T19:47:18Z","apple_news_api_id":"dff7cd6a-28c3-413d-8a67-c56e5f9158e4","apple_news_api_modified_at":"2024-10-21T18:14:22Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAg==","apple_news_api_share_url":"https:\/\/apple.news\/A3_fNaijDQT2KZ8VuX5FY5A","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[357,728,51,1129,1200,489,96,2673],"class_list":["post-39417","post","type-post","status-publish","format-standard","hentry","category-technology","tag-compression","tag-domain-name-system-dns","tag-google","tag-iomega","tag-phishing","tag-url","tag-web","tag-zip-archive"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/39417","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=39417"}],"version-history":[{"count":2,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/39417\/revisions"}],"predecessor-version":[{"id":39423,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/39417\/revisions\/39423"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=39417"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=39417"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=39417"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}