Hacker News new | ask | show | jobs
by pockybum522 36 days ago
Kind of crazy to me that anyone would block an entire TLD. This timeline is bizarre. How often and with what services do you find zip blocked? Genuinely curious
2 comments

My employer blocks it on our work computers. Looking around it seems like this is commonly done because one of the main uses of the .zip tld is to spread malware by faking links to zip files using "/" look alike characters and other URLs that look like download links to zip files.
Well by that token we should probably also block the .com TLD since that is actually an executable file suffix.
Modern 64-bit Windows doesn't execute .com files, unless the user installs an emulator or something.
It does execute PE files with .com extension.
https://luke.zip/posts/zip-defense/

I get asked this a lot, so here's my defense!

I had little opinion on .zip but this convinced me to go figure out how to block .zip tld. Why would someone risk all those attack vectors when there is so much available on the many other tlds. I could see myself getting caught by many of them.
this timeline is bizarre because someone allowed TLD with common filetype name be created

ideally it should've been killed the moment it was created to become a lesson for everyone else

so I guess you would also support killing another TLD with a common filetype:

https://ohmyz.sh

That ship sailed when ".com" was created.