7 ms·
The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity i
by mamborambo 4y ago
The consumer's dependence on "legit-sounding domain name", a green SSL key, and recognizable corporate logos and website layout as the "proof" of authenticity is passe.
In this era of online ubiquity there should be another layer of opt-in validation, ring of trust, p2p feedback and rating, that can all be plugged into the consumer web experience.
- NavinF 4y agoIn practice consumers just go straight to Amazon because they're afraid of the wider internet and depend on the return policy to save them when they get scammed. Doubt any "opt-in validation, ring of trust, p2p feedback and rating" will change that in the next decade.
- leveraction 4y agoThis and the fact that they have your cc and shipping already on file, which makes things a lot easier. More than once I have found a product on some site and then purchased it from Amazon just because it is so much easier.
- Krisjohn 4y agoThat’s kind of what antivirus web plugins do
- jesterson 4y agoAs weird as it sounds, it is still the best. If we have centralised "licensing" solution it is abused by large capital to wash off smaller - there is plenty of examples. If we have decentralised solution (which is basically what review is) - it is immediately abused by "marketers". There is no simple and easy solution to the problem.
- BobbyJo 4y agoIMO, the best solution to the problem is friction. Criminals are criminals because it's easy. If opening a fraudulent store is 90% as difficult as opening a legit one, no one is going to bother.
- Tiereven 4y agoI see what you're saying: if you add more startup cost then it makes it harder for spammers without legitimate business interest to profit. I think I disagree, though. Legitimate "mom and pop" businesses experience all the pain of learning the process of setting up a store, creating real products and pricing, inventory, delivery etc. They don't need more friction. These criminals on the other hand are likely automating everything and have the advantage of lessons learned from dozens of iterations. The article indicated the mimic sites accept credit card numbers but don't actually process them -- to me that is the Achilles heel of the process. If credit card companies started requiring instantaneous verification of the card's actual use (via a card chip reader or an app on user's phone, for example) instead of allowing payment via static information vulnerable to replay at any time, I think that could do a lot more to improve security of online transactions than green check boxes.
- joshspankit 4y agoThere’s danger on the other side of this: Credit card companies are already stifling creators because of the power they have when CCs are the primary payment method. Additional security gives them a tighter grip.
- BizarroLand 4y agoComputers with built in NFC readers could allow you to pay for your purchases with your phone and use fingerprint/passcode/faceID etc. for verification. That would be convenient enough for most people that it's usable.
- sydbarrett74 4y agoOrganised criminal syndicates are behind most of these operations. They have immense resources from which to draw. It's another example of the saying, 'It takes money to make money.' IOW, adding friction wouldn't be a sufficient deterrent. Criminals are resourceful, and enriching themselves further is a strong motivator.
- BizarroLand 4y ago
- FortiDude 4y agoTo me it's very simple: nation states should have their own layer that uses the national registry for companies to verify a domain. When you register a business you also provide your official domains and so the validity of the website is checked against the validity of the business.
- prox 4y agoThat would be a great idea.
- stevewatson301 4y agoThe path to an China-esque ICP recordal system.
- moooo99 4y agoIn Germany we have an approach with a somewhat similar effect. For any site with an commercial intent (which is pretty loosely defined) it is mandatory to have an Imprint with the person representing the company, the address of the HQ as well as the companies registration number and court location. It makes it somewhat more transparent what company is behind the site and gives you information you can lookup in public registries. I hate it from a privacy perspective but it’s okay for for consumer protection.
- CorrectHorseBat 4y agoFraudulent websites could just add fake/copied information, no? A special domain doesn't have that issue.
- Kovah 4y agoOh they do copy this information! I became victim of such a fraud because the whole website looked really legitimate to me, and I am the "tech guy" in our family. Thing is: fraudsters create good looking websites and just copy all the company information from other stores, put in a non-working telephone number and email and they are good to go. There are thousands of small businesses that sell stuff online. One would argue that there is a Handesregistereintrag (record of commerce at the officials) that might help, but it only contain information about the seller including contact details and what the does, and not domains. And the record is not needed for small businesses. TLDR: Germany seems to have hurdles for fraudsters, but they are easily taken by simply copying information from legit stores.
- deleted 4y ago[deleted]