Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Spammers Abusing Trust in US .Gov Domains (krebsonsecurity.com)
22 points by Khol on March 18, 2016 | hide | past | favorite | 4 comments


Bit.ly could follow the links, see if they redirect, and if they do then don't flag them as ".gov" if they don't terminate on a ".gov" site.

Ultimately however it would be better to eliminate these insecure redirects because even without bit.ly spammers can use .gov websites to make their link seem more legitimate.


Or a step further: don't use the usa.gov URLs for any link that appears to contain an embedded URL (e.g, contains "http://" or "https://").


It's not hard to not redirect bit.ly but redirect victims that click the link.

Some .gov sites need the redirect for whatever reason, but they could check the referer.


This is clearly a public safety issue. Private industry should set up a licensing board that regulates government use of technology, contingent on some demonstration of competence.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: