I think the only reasonable and fair solution is building a reputation system on top of DNS. Browsers and message apps would show a warning if the score for a domain is low and completely block those that are rated "known scam" unless you turn on developer settings.
You start out at "suspicious" and gain trust with time. Collisions with well known names or high outgoing traffic give you a penalty but you can defeat it with enough positive votes. Domain owners with a high score would be able to vouch for other domains with an entry in `.well-known` and get them to high status faster, with penalties if they end up being scams to prevent "trust as a service" operations.
I don't know who we can trust to manage it. Mozilla can't really do it alone, Apple and Microsoft are good candidates but Google is actively making money from scams and they would try to push for ID verification if they joined.
First: Registrars could ask for an escrow payment. Pay €9 for the domain name put €900 in escrow
Next: I don't want to live in a world where I have to show my passport and pay thousands of pounds to register a domain
Want or not want?
Plus the 900 in escrow shows a very US centric view. It's only like three Starbucks lattes over there with the current inflation right?
I assume this is supposed to be somewhat tongue-in-cheek, because the argument that SoMeThInG mUsT bE dOnE aBoUt DnS because a whopping 10% of registrations were associated with spam/scams seems silly.
There are lots of large open systems that the average person interacts with daily that would love to see <30% spam/scam volume:
- email - paper mail - telephone numbers - SMS messages - basically any social media platform
> I don't want to live in a world where I have to show my passport and pay thousands of pounds to register a domain which is only available after being vetted by private interests. But I also don't want to live in a world where scammers have effectively no deterrent from abusing millions of people.
One solution would be to have recognised verified TLDs that require some verification on some, whilst allowing others to be more lax an accessibel. The issue is we have these, e.g. .gov.uk.
Another solution would be to dissuade people from using less well known gtlds in favour of ones that have some sort of limits/controls, such as recommending people avoid .mobi domains in favour of ones with more oversight like .com. (I say this as someone with a .fun personal domain!)
I don't know. I'm not saying this isn't a problem, I'm just saying that Terence kicking this nest seems like the start of some monkey paw meme or something.
The (refundable) escrow payment would indeed be a possible solution.
I feel to some degree governments are also responsible for this, by not making consistent use of *.gov domains.
Take for example sunbiz.org, the Florida business register. For 20+ years sunbiz.org was the official domain, until they switched to dos.fl.gov in 2023. The average joe may have heard about "Sunbiz", but was the domain sunbiz.com, sub.biz, sunbiz.net ... who knows?? How would anyone know? All of this could have been avoided by using *.gov everywhere in the first place.
Oh, look, more state sponsored control propaganda disguised as protection.
Scams are run by state sponsored actors and intelligence agencies and their targets are often regular people who have nothing to do with any of this.
You can say whatever you want, DNS is the only thing preventing control by all governments. If that locks down, you find see more people pushing for alt root servers and other ways to get out of there. What might actually help is tracking finances of government agencies and the few people who are often funding all these illicit activities.
Ill-devised Internet control movements will make everything incredibly difficult to reconcile back to. Parts of the world are already creating and using their own systems for this, and further DNS control will lead to even wider adoption of Alternative DNS Roots such as OpenNIC or Handshake even. (See https://en.wikipedia.org/wiki/Alternative_DNS_root )
Eventually, given that and a list of alternative certificate authorities, we will end up with a permanently forked internet where the only saving grace might be the protocols themselves and nothing more. Some companies are already creating a way to send a list of trusted CAs via their DHCP infrastructure already (See https://info.support.huawei.com/info-finder/encyclopedia/en/... ) so I can totally see loss of control happening in the upcoming years.
You heard it here first.