Hacker News new | ask | show | jobs
by yourusername 37 days ago
Why do you use a TLD that is commonly blocked?
2 comments

Kind of crazy to me that anyone would block an entire TLD. This timeline is bizarre. How often and with what services do you find zip blocked? Genuinely curious
My employer blocks it on our work computers. Looking around it seems like this is commonly done because one of the main uses of the .zip tld is to spread malware by faking links to zip files using "/" look alike characters and other URLs that look like download links to zip files.
Well by that token we should probably also block the .com TLD since that is actually an executable file suffix.
Modern 64-bit Windows doesn't execute .com files, unless the user installs an emulator or something.
It does execute PE files with .com extension.
https://luke.zip/posts/zip-defense/

I get asked this a lot, so here's my defense!

I had little opinion on .zip but this convinced me to go figure out how to block .zip tld. Why would someone risk all those attack vectors when there is so much available on the many other tlds. I could see myself getting caught by many of them.
this timeline is bizarre because someone allowed TLD with common filetype name be created

ideally it should've been killed the moment it was created to become a lesson for everyone else

so I guess you would also support killing another TLD with a common filetype:

https://ohmyz.sh

That ship sailed when ".com" was created.
We run https://aero.zip, works fine, not once anyone complained about it being blocked. There was a study somewhere that .zip TLD actually gets less malicious registrations compared to other TLDs.
The whole TLD is blocked by my work firewall. I imagine you don't get complaints because the few people who are blocked just don't know what you do. How would they even complain if they can't access your website?
Sssshhhh, don't disturb their science, it's sleeping.