Hacker News new | ask | show | jobs
by gkoberger 1129 days ago
What if someone legitimate writes "download assets.zip", and GMail (aka Google, aka the owner of the .zip tld) starts converting it to a URL like they do with .com?

It's worse than phishing, because it could be a legitimate email from someone you trust.

(Overall, I mostly agree that the issues are ultimately somewhat minimal... but this is a situation where there's absolutely no upside and only downside.)