Hacker News new | ask | show | jobs
by lolsowrong 968 days ago
Explain why it’s a huge mistake, please.
3 comments

I think the idea is ambiguity between a zip file from your coworkers website and an entirely separate phishing website which downloads an entirely different zip file with a malicious payload.

Anything that introduces unnecessary and previously unforseen ambiguity to the olds is just another path to filling the internet with scams

Browser vendors should just splash users with one of those click-through security warnings. Make it bright yellow.

I'd be very entertained by drama from owners of those domains, but in my opinion, such a thing would be completely justified.

Here’s the problem: the biggest browser vendor is the one selling the domains!
Well, we also have .com as a common extension on Windows machines?
Check out familyphotos.zip
A link reading attachment.zip is no longer a 'safe' file but a eg browser window.