frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Chinese chemical supplier causes global baby formula recall

https://www.reuters.com/business/healthcare-pharmaceuticals/nestle-widens-french-infant-formula-r...
1•fkdk•1m ago•0 comments

I've used AI to write 100% of my code for a year as an engineer

https://old.reddit.com/r/ClaudeCode/comments/1qxvobt/ive_used_ai_to_write_100_of_my_code_for_1_ye...
1•ukuina•3m ago•1 comments

Looking for 4 Autistic Co-Founders for AI Startup (Equity-Based)

1•au-ai-aisl•14m ago•1 comments

AI-native capabilities, a new API Catalog, and updated plans and pricing

https://blog.postman.com/new-capabilities-march-2026/
1•thunderbong•14m ago•0 comments

What changed in tech from 2010 to 2020?

https://www.tedsanders.com/what-changed-in-tech-from-2010-to-2020/
2•endorphine•19m ago•0 comments

From Human Ergonomics to Agent Ergonomics

https://wesmckinney.com/blog/agent-ergonomics/
1•Anon84•23m ago•0 comments

Advanced Inertial Reference Sphere

https://en.wikipedia.org/wiki/Advanced_Inertial_Reference_Sphere
1•cyanf•24m ago•0 comments

Toyota Developing a Console-Grade, Open-Source Game Engine with Flutter and Dart

https://www.phoronix.com/news/Fluorite-Toyota-Game-Engine
1•computer23•26m ago•0 comments

Typing for Love or Money: The Hidden Labor Behind Modern Literary Masterpieces

https://publicdomainreview.org/essay/typing-for-love-or-money/
1•prismatic•27m ago•0 comments

Show HN: A longitudinal health record built from fragmented medical data

https://myaether.live
1•takmak007•30m ago•0 comments

CoreWeave's $30B Bet on GPU Market Infrastructure

https://davefriedman.substack.com/p/coreweaves-30-billion-bet-on-gpu
1•gmays•41m ago•0 comments

Creating and Hosting a Static Website on Cloudflare for Free

https://benjaminsmallwood.com/blog/creating-and-hosting-a-static-website-on-cloudflare-for-free/
1•bensmallwood•47m ago•1 comments

"The Stanford scam proves America is becoming a nation of grifters"

https://www.thetimes.com/us/news-today/article/students-stanford-grifters-ivy-league-w2g5z768z
2•cwwc•51m ago•0 comments

Elon Musk on Space GPUs, AI, Optimus, and His Manufacturing Method

https://cheekypint.substack.com/p/elon-musk-on-space-gpus-ai-optimus
2•simonebrunozzi•1h ago•0 comments

X (Twitter) is back with a new X API Pay-Per-Use model

https://developer.x.com/
3•eeko_systems•1h ago•0 comments

Zlob.h 100% POSIX and glibc compatible globbing lib that is faste and better

https://github.com/dmtrKovalenko/zlob
3•neogoose•1h ago•1 comments

Show HN: Deterministic signal triangulation using a fixed .72% variance constant

https://github.com/mabrucker85-prog/Project_Lance_Core
2•mav5431•1h ago•1 comments

Scientists Discover Levitating Time Crystals You Can Hold, Defy Newton’s 3rd Law

https://phys.org/news/2026-02-scientists-levitating-crystals.html
3•sizzle•1h ago•0 comments

When Michelangelo Met Titian

https://www.wsj.com/arts-culture/books/michelangelo-titian-review-the-renaissances-odd-couple-e34...
1•keiferski•1h ago•0 comments

Solving NYT Pips with DLX

https://github.com/DonoG/NYTPips4Processing
1•impossiblecode•1h ago•1 comments

Baldur's Gate to be turned into TV series – without the game's developers

https://www.bbc.com/news/articles/c24g457y534o
3•vunderba•1h ago•0 comments

Interview with 'Just use a VPS' bro (OpenClaw version) [video]

https://www.youtube.com/watch?v=40SnEd1RWUU
2•dangtony98•1h ago•0 comments

EchoJEPA: Latent Predictive Foundation Model for Echocardiography

https://github.com/bowang-lab/EchoJEPA
1•euvin•1h ago•0 comments

Disablling Go Telemetry

https://go.dev/doc/telemetry
1•1vuio0pswjnm7•1h ago•0 comments

Effective Nihilism

https://www.effectivenihilism.org/
1•abetusk•1h ago•1 comments

The UK government didn't want you to see this report on ecosystem collapse

https://www.theguardian.com/commentisfree/2026/jan/27/uk-government-report-ecosystem-collapse-foi...
5•pabs3•1h ago•0 comments

No 10 blocks report on impact of rainforest collapse on food prices

https://www.thetimes.com/uk/environment/article/no-10-blocks-report-on-impact-of-rainforest-colla...
3•pabs3•1h ago•0 comments

Seedance 2.0 Is Coming

https://seedance-2.app/
1•Jenny249•1h ago•0 comments

Show HN: Fitspire – a simple 5-minute workout app for busy people (iOS)

https://apps.apple.com/us/app/fitspire-5-minute-workout/id6758784938
2•devavinoth12•1h ago•0 comments

Dexterous robotic hands: 2009 – 2014 – 2025

https://old.reddit.com/r/robotics/comments/1qp7z15/dexterous_robotic_hands_2009_2014_2025/
1•gmays•1h ago•0 comments
Open in hackernews

Most parked domains now serving malicious content

https://krebsonsecurity.com/2025/12/most-parked-domains-now-serving-malicious-content/
146•bookofjoe•1mo ago

Comments

excalibur•1mo ago
The bit about the gmai.com mailserver is disturbing. One would imagine there are many other typo squatters with a similar setup.
imglorp•1mo ago
I just checked. At least it's not answering on 25 to receive all that free typo mail. Same for gmali.com. But they could spoof the gmail login page. Not finding out.

    PORT     STATE SERVICE
    80/tcp   open  http
    443/tcp  open  https
    8080/tcp open  http-proxy
MrDOS•1mo ago
You're looking in the wrong place. They don't need to be listening for mail on the machine behind the A/AAAA records for the domain, because they have an MX record indicating that mail should be delivered elsewhere:

    $ dig MX gmai.com +short
    1 mail.h-email.net.
Port 25 is very rare these days, as it implies the possibility of unencrypted traffic; legitimate SMTP traffic uses port 587. That said, I checked a couple of the hosts that that name resolves to, and they all listen for both SMTP and secure SMTP traffic:

    $ nmap -p 25,587 mail.h-email.net
    Starting Nmap 7.95 ( https://nmap.org ) at 2025-12-18 16:31 UTC
    Nmap scan report for mail.h-email.net (165.227.159.144)
    Host is up (0.093s latency).
    Other addresses for mail.h-email.net (not scanned): 91.107.214.206 165.227.156.49 167.235.143.33 5.75.171.74 5.161.194.135 178.62.199.248 5.161.98.212 162.55.164.116 49.13.4.90
    rDNS record for 165.227.159.144: mail2.h-email.net

    PORT    STATE SERVICE
    25/tcp  open  smtp
    587/tcp open  submission
johndoeee•1mo ago
mail.h-email.net is a Spamhaus spamtrap.

As far as I've been able to research, these typesquatting domain traps started at the same time as Spamhaus CSS blacklist which was actually a company called Deteque.

If the MX has a large number of Hetzner IPs as mailservers, then it's probably Spamhaus.

MrDOS•1mo ago
Ah, neat – that certainly makes me feel a bit better, then.
phsau•1mo ago
Port 25 is only uncommon for client submission, but prevalent for MTA>MTA traffic.
Bender•1mo ago
I park mine by having no IP address, MX record is "0 ." meaning it does not receive email, the SPF record is "v=spf1 -all" and DMARC is a strict reject, CAA is 0 issue ";", BIMI is "v=BIMI1; l=; a=;". I do the same for wildcard DNS. There's probably more I should add.
ericpauley•1mo ago
Indeed, this is a common practice in the broader data. It seems the linked article is filtering to resolvable+hosted domains, a subset of overall domain parking.
Bender•1mo ago
Yup. That's why I am suggesting to stop that practice and just remove the IP rather than trusting the landing page someone else maintains. Or if one would like to give bots something to do point it to a multicast address or perhaps MoD/US Military address.
bks•1mo ago
The m3aawg has a parked domain guide - https://www.m3aawg.org/sites/default/files/m3aawg_parked_dom...
Bender•1mo ago
I appreciate that but I will always follow the Bender Domain Parking Standard [1].

[1] - https://mirror.newsdump.org/domain_parking_standard.txt

ericpauley•1mo ago
We did a large-scale study of this phenomenon recently: https://www.cs.bu.edu/faculty/crovella/paper-archive/wung-if...

Across a broad sample of typo domains of major sites, most registered domains aren’t actually reachable, implying they are registered for defensive, legitimate, or unrelated purposes. Interestingly, the typo space on major sites is actually very sparsely registered (2% at edit distance 1), meaning that typosquatting may actually be underexploited.

belorn•1mo ago
A possible explanation why typos for major sites are sparsely registered could be that the domain industry has put a lot of focus the last decade on addressing malicious registrations, and many registrars that focus on the market segment of large companies sell products that monitor for malicious registrations with legal response in case one pops up. It is also seems that bulk registrars has gotten better filters to reduce malicious registrations, which is a service some security companies offer to registrars. In theory it should be quite more difficult today for a malicious actor to go to a major registrar and buy an obvious trademark infringing domain for a major site.

Domain/trademark monitoring also directly compete with defensive registrations. Often it is a question if you want to pay the lawyers/monitoring service, a large number of registration/renewal fees, or both.

AStrangeMorrow•1mo ago
My guess is also that not all typos are equal. Should have a stricter edit version for 1-keystroke-away filtered edits (that is delete, swap or add 1 key away / replace one key away) instead of pure Levenshtein. Like Fqcebook is a more likely typo than Fjcebook but they are both edit-1
teddyh•1mo ago
Someone should make a qwertyshtein() function.
zahlman•1mo ago
> Interestingly, the typo space on major sites is actually very sparsely registered (2% at edit distance 1)

It seems to me that "edit distance 1" still describes some very implausible typos.

NewJazz•1mo ago
Yeah corner and comer is an edit distance of 2 but perhaps more lucrative than corner and corker, as a bad example.
Wistar•1mo ago
I saw rnicrosoft in use the other day, somewhere.
AStrangeMorrow•1mo ago
Yes, Levenshtein in that case give too big an exploration space. A keyboard edit distance would probably work better. Delete and swap are still 1 but replace and add should be within say 1-key at most
ricardo81•1mo ago
>Interestingly, the typo space on major sites is actually very sparsely registered (2% at edit distance 1), meaning that typosquatting may actually be underexploited.

Anecdotally, the autosuggestions and improved browsing history recommendations may mean this is way less lucrative than it used to be.

Also, anyone doing search like behaviour in their address bar is far more likely to see a knowledge panel style reply for prominent websites vs the 10 blue link format of historical search engine results, which may have included the nefarious domains.

I'd leap to say that because of this, users find their intended domain by using natural language far more than they used to.

Loughla•1mo ago
I would argue that it is 100% searching in the address bar. Mobile has trained people to do that, and search results are usually solid enough to take you to the right place.
ricardo81•1mo ago
Yeah, I'd lean towards a high % also- it would take some time to prove it.

Also, homograph attacks are likely much less of a thing for the above reasons.

xp84•1mo ago
Mobile? Haven’t all desktop browsers switched to having the address bar do search unless you type a fully qualified domain, since Chrome came out c. 2009? Before that there were 2 fields at the top of browser windows, but Firefox and Safari ditched those pretty quickly after Chrome.
AStrangeMorrow•1mo ago
If I understand correctly from the paper what qualifies as an edit distance of 1 is pure Levenshtein distance-1 right?

Just curious because while the edit-1 space can be fairly big, I’d assume all edits have very different probabilities. So the squatted domains probably skew to a higher probability edit. By that I mean mostly keyboard edit typos, eg on a phone: the “cwt” typo is more likely than “cpt” for “cat” because of an and w keyboard proximity. Wonder what the squatting rate is when you filter for edit within one key stroke for example (only really change the add and replace types of edits, not delete or swap)

1vuio0pswjnm7•1mo ago
"... meaning that typosquatting may actually be underexploited."

Missing from the paper is an examination of web user behaviour

Over time, so-called "direct navigation" where the domain name, e.g., example.com, was typed into the browser address bar, has declined. By the time Google terminated "Adsense for domains" in 2012 IMO it had managed to systematically subsume most of the traffic and associated revenue from the typosquatting/domain parking racket

https://web.archive.org/web/20250320184725if_/https://domain...

With the introduction of the so-called "omnibar" or "omnibox" in Firefox^1 and Chrome, typographical errors in domain names are submitted as "searches" to a company that sells ad services. For example, Safari, Firefox, Chrome all sending search traffic to Google, LLC. From the DoJ antitrust litigation we know that Google has been paying ridiculously large sums of money to various companies for this traffic

1. Firefox originally called this the "awesome bar"

https://web.archive.org/web/20250927011424if_/https://www.cn...

Not to mention increasingly common user practice of direct navigation to a search engine webpage, e.g., google.com, then searching for the desired website, e.g., example.com

As everyone knows, one company, in some cases through acquisitions and/or anticompetitive conduct, came to control 1. search, 2. "the web browser", 3. online advertising services on the open web, 4. operating systems (mobile, "chromebook"), ...

If parked domains only get traffic from "direct navigation",^2 then it stands to reason that such traffic has declined as it has been increasingly captured by advertising-sponsored "default browsers" and, ultimately, Google. IMO, it makes sense that domain parking as a means of delivering ads and generating revenue would give way to these domains becoming unregistered or registered to malware distributers or the like

What are the registration histories for the unregistered edit distance 1 typosquatting domains. Consider the number that are "currently unregistered" versus "never before registered"

2. Perhaps the registrants are using other ways to send traffic to these domains

moralestapia•1mo ago
This just happened to me a month ago, I was waiting for a unused domain to expire. The domain was hosted on Epik (which I think is a trashy company but w/e).

About a month before expiration it somehow got renewed for 10 years, which is weird because it was not available ... and is now hosting a "get-rich-quick" scam that pretends to be a genuine Petro Canada campaign.

homebrewer•1mo ago
> About a month before expiration it somehow got renewed for 10 years, which is weird because it was not available

I've seen some domain registrars auctioning off domains during the last 2-4 weeks before they expire. If nobody buys it, then it actually expires and is then released.

HWR_14•1mo ago
Which registrars? I would want to avoid those.
reactordev•1mo ago
At the end of the day, no matter your domain, ICANN can just take it for their VC bros. Happened to a friend of mine that owned a pretty novel domain name that a certain social media company wanted. He refused to sell. ICANN and his registrar just transferred it out from under him. Gone. See ya.
Tade0•1mo ago
Wow. In light of this it's amazing that Mr. Nissan (RIP) and later his heirs managed to not only retain control of nissan.com, but regain it after it was stolen years after his passing.
reactordev•1mo ago
Money talks
ctxc•1mo ago
Out of curiosity, what was the domain?
Steve16384•1mo ago
You gotta name the domain!
reactordev•1mo ago
I'd rather not face the ire of ICANN, sorry.

I know better. They read this site. They know that all it takes is some company to issue some trademark litigation and they fold. No basis, no question, just here you go.

ajkjk•1mo ago
what would they do to you...?
reactordev•1mo ago
Oh you sweet summer child, you haven’t met their lawyers…
ajkjk•1mo ago
well, condescension aside, literally what would they do? there's nothing remotely illegal about posting the name of a site in a forum. and here you are trying to get me to be as scared as you are about posting a basic fact in a forum and why would I be?
HWR_14•1mo ago
There's a difference between trademark issues and your registrar auctioning off the name
reactordev•1mo ago
[delayed]
dvh•1mo ago
Yesterday I received spam with link on https://storage.googleapis.com/ that redirected to some parked domain.
rickcarlino•1mo ago
Hopefully “direct navigation” does not become a boogeyman like “side loading” has.
wlesieutre•1mo ago
Especially when the alternative is "type the company name into google" where the top 3 results are ads and they've previously been seen to stick malware distribution sites above the legitimate company pages

This was happening for months with blender in 2022/2023, previously collected links about it here: https://news.ycombinator.com/item?id=34917701

xp84•1mo ago
Top 3 are ads? Usually it’s more like 1. D-tier AI Slop Overview 2. Shopping ads 3. A bunch of AdWords ads 4. A bunch more Google-specific content (maps etc) 5. 1-3 organic results (Or sometimes 0 unless you click a “More results” link)
belorn•1mo ago
Their definition of parked domain is a bit odd, with "expired" domain names and typosquatting” domains. I work at a registrar and the absolutely vast majority of parked domains for us are domains owned by customers that register alternative versions, campaign, products and misspellings of their primary domain. Parked in that sense mean an almost empty zone with occasionally a default landing page, sometimes as a paid DNS service at the registrar, and sometimes as a free service (There are still registration and renewal fees).

Putting a redirect onto such domain would be a major bad faith act by the registrar and a reason to avoid that registrar at all costs. The customer is the owner of that name, has their name attached as the registrant, and generally hold some legal risk while doing so. It also goes directly against the primary reason why the customers bought the domains in the first place.

The ones that hold advertisement two specific cases. One is "expired" domains which are not actually expired but where the registrar holds on to it in the hope that the old or new customer will buy it for an extra cost. The other is names which a customer or the registrar itself bought as an investment in hope to auction out. That kind of behavior was historically frowned at but is fairly common practice for a smaller number of domains. Usually you don't put redirects on those since you want to expose the fact that the domain is for sale.

So I am very confused where they got their 90% number from, but then I would not call typosquatting as parked domains if its registered by a malicious actor and used for a scam on their own servers (or hacked servers as it may be).

xp84•1mo ago
Yeah, I think there’s just multiple definitions of the word “parked” in play. To a registrar it may just mean idle, but there is an industry out there of what I’d call “monetized parking” where you can point domains to this kind of garbage and collect the ad money.

It’s unclear what the definition used in this study is.

RankingMember•1mo ago
We've unfortunately come a long (bad) way from the innocuous "backpack girl" parking pages.

For a refresher: https://i.kym-cdn.com/entries/icons/original/000/033/037/gir...

zahlman•1mo ago
> For a refresher

I've never seen that image before. :/

RankingMember•1mo ago
More background: https://knowyourmeme.com/memes/people/parked-domain-girl
bookofjoe•1mo ago
I remember her!
armenarmen•1mo ago
I owned facebook.ky, as a goof, for about 2 weeks 10+ years ago before Facebook claimed it from me. Wild to me that huge banks don’t have a team whose responsibility it is to watch for and seize scam domains
thaack•1mo ago
Facebook[1], Google, etc all use (or used to use) MarkMonitor that offers domain squatting monitoring as a service[2] that utilizes the Uniform Domain Name Dispute Resolution Policy to remove offending domains violating their trademark. These services are quite expensive from my understanding.

[1] It appears Facebook now utilizes their own internal registry.

[2] https://www.markmonitor.com/domain-dispute-recovery-solution...

hnburnsy•1mo ago
>“In large scale experiments, we found that over 90% of the time, visitors to a parked domain would be directed to illegal content, scams, scareware and anti-virus software subscriptions, or malware, as the ‘click’ was sold from the parking company to advertisers, who often resold that traffic to yet another party,” Infoblox researchers wrote in a paper published today.

Hey, same thing happens with my Google search results, what a coincidence!

DoctorOW•1mo ago
Yeah maybe it's not over 90% of the time. But I wonder if a study has been done to what the percentage is just for search ads.
dredmorbius•1mo ago
A similar trend I've noticed in the US within recent years has been that misdialing toll-free numbers(or even correctly dialing an apparently expired number), originally "area code" 800, since expanded to include 888, 877, 866, 855, and 844, will lead to a scam or advertising connection.

This is one of numerous trustworthiness attacks on general public-switched telephone network (PSTN) use which I suspect will lead to an increased abandonment of that system. If we can neither trust either incoming or outgoing calls to connect to a trustworthy counterparty, people will tend to prefer systems which do so.

(This is on top of privacy and security issues with PSTN, including data exfiltration by operators, and potential for wiretapping and intercepting voice, texts, and data.)

bradley13•1mo ago
I've seen this on some of the domains speculatively registered by companies hoping to sell them for a fortune. Pick a dictionary word, or just a short (3 or 4 letter) Domain Name. If it's not actually in use, somebody had registered it and would love to sell it for some stupid amount. In the mean time, I guess they pay the fees by renting to scammers...

I really wish the domain registrar's would prohibit speculation, but there's money to be made, so...

teeray•1mo ago
Can we have a land value tax for domains?
thaumasiotes•1mo ago
We have one; that's the registration fee.
xp84•1mo ago
It feels like the price should vary by how many a legal entity has. It would be nice for one to be super cheap, 5 to be perfectly acceptable for a business to afford, and 100 to be unfathomably expensive. And maybe trademarks would get you a big break (on domains that contain your trademark) since you’re not hogging anything anyone else could legally use.

Of course, this is fantasy though because it’s not worth forcing people to tie their identity documents to registrations.