Daydream: Browsers and email programs are shipped with "Default Allow" lists, which include only the older & higher-quality TLD's. While users can add whatever TLD's they want to the lists, that default behavior destroys 99% of the value of new & crap-infested TLD's.
Per the article 0.2% of .com domains are phishing vs 4.2% of .top. Or put another way, if you have a .top domain it's about 17 times as likely to be phishing than a .com domain.
.com has the most phishing domains by virtue of by far being the biggest, not because they have looser controls or are less reliable.
Only if you select a random domain from a list of all .com or .top domains. No one does that of course. The chance a random .top (or .com) you encounter is a phishing domain isn't so easily calculated, depends on where you see it, etc.
Ate some cheese before dreaming: Google and MSFT (as maintainers of the dominant mail clients) start charging TLDs under the table to go on GMail/Outlook's "Default Allow" list, except, of course, the ones that Google administers
Why does that matter at all? If I go and create a bunch of legitimate .top domains, is it suddenly better somehow? No, it's still the first of the list, and .com is still second.
yes, precisely. if you and a bazillion other people do it so that the percentage goes down. it's the fact that scammers are glomming onto a trendy TLD ruins the reputation of that TLD. If the percentage of scam is higher in one TLD over another, people will consider it a TLD used for scams. Not sure where the logic breaks down here
> No, it's still the first of the list, and .com is still second.
also, what do you mean .com is second? it states that .top was second to .com
Because any action will have a negative impact on the legitimate sites and we want to maximize the effect while minimizing collateral damage.
It seems you’re saying if there’s a terrorist training camp with 10 terrorists and no bystanders in it, it would be unreasonable to drop a bomb on it unless we’re first willing to level the nearby city of a million people with 11 terrorists in it because it has more terrorists.
I already do this with NextDNS, I block all the "new" TLDs except for .io, .tv, and .ai because they're used for tech sites that are legitimate. I know that many organizations do the same, in fact it's mentioned in another comment.