Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Great. There's a Dutch bank called ING. I can't wait for all the phish.ing to start. IMHO all those new TLDs are just a huge mistake and a blatant money-grab.


>> IMHO all those new TLDs are just a huge mistake and a blatant money-grab.

Especially with this one. There is no room for competition since each verb can only be used once with the ing suffix. Well, competition for who is willing to pay the most, but from the consumer side there can only be one URL.


i mean, if you can't get fuck.ing/cool, you can go with reallyfuck.ing/cool or getsurf.ing gosurf.ing learnsurf.ing or justhang.ing/out etc

I think I'm at my limit of dumb domain names for no reason though, so I'll pass on this round.


Reallyfuckingcool.net or .org available, same for getsurfing, learnsurfing and justhangingout. With all these domains there’s no real point unless you are getting a dictionary word or a specific name, imho.


Which just outlines how it is a money-grab for existing property owners. Yet another stupid vanity domain you're forced to add to your portfolio!


I wonder if we're at the point that the costs of registering a new TLD are immediately recouped from the set of large businesses that must register their name in every TLD?


I was thinking about this too. Some TLDs look like an obvious obligatory money grab (such as .download), so companies are compelled to buy it.

I have seen some TLDs owned by a company and didn't even bother to set a redirect.

My anecdote is that the ICANN annual fee ($25k) is easily covered by these obligatory registrations and the premium domains. The cost of running nameservers aren't that high. NS1 has an offering, but it's impossible to find their pricing for anything.


reallyfuckingcool.ing


Great for an HVAC company


Ugh, when I saw the HN headline about this TLD I thought it belonged to ING Group, just like .barclays and .chase belong to their corporate owners. Just shows how suited this TLD is for phishing...


If I were the lawyers at ING, I would be sending Google it cease-and-desist with regards to selling any domains with banking related terms. I actually think they would have a reasonably strong claim.


https://bank.ing is ING Bank.


Suuuuure it is!


yeah, right


To be honest both cases are equally strong. Trademark by a bank, and English gerundial suffix. I want to see their lawyers knife fight in a ring while burning piles of cash, it would be an entertaining self resolving problem!


And grammar teachers would sue ING?


On what grounds? ING can sue on grounds of owning a trademark.


Don't they sell .zip TLDs now too?


I hate that mentioning example.zip now turns into a link in modern chat programs. At least link preview can be disabled... Also .py is annoying but that one I can understand more why it reasonably needs to exist.


I don't get it, and I'm sure some people fall for the scams, but .com has been a dangerous file format since before the internet became common and that hasn't been much of a problem either.

My guess is that it'll only be a matter of time before .png and .jpg will be TLDs.


If someone is allowed to make .xlsm a TLD I'm 100% quitting the internet.


Yes, they do, huge mistake

...but a lot of fun!


Explain why it’s a huge mistake, please.


I think the idea is ambiguity between a zip file from your coworkers website and an entirely separate phishing website which downloads an entirely different zip file with a malicious payload.

Anything that introduces unnecessary and previously unforseen ambiguity to the olds is just another path to filling the internet with scams


Browser vendors should just splash users with one of those click-through security warnings. Make it bright yellow.

I'd be very entertained by drama from owners of those domains, but in my opinion, such a thing would be completely justified.


Here’s the problem: the biggest browser vendor is the one selling the domains!


Well, we also have .com as a common extension on Windows machines?


Check out familyphotos.zip


A link reading attachment.zip is no longer a 'safe' file but a eg browser window.


They already got the bank.ing domain name.


With this gem on their side:

> While bank.ing is managed by ING, please be aware that any other domain ending with .ing is not an ING website.


And they use it to remind people that the .ing tld is a bad idea.


but do they have fuckof\f.ing for submitting complaints?

Edit: HN doesn't accept FO as one word, it replaces the last `f` with `i`. Try it yourself.


  hunter2
I don't understand, it seems to work for me.


I am old. I forgot about this hunter2 password filter phish reference.


hunter2 is 20 years old next year, just to make everyone else feel old too


Huh. i actually thought it was older. I can remember a time before *******


Is this just a trick to see how many people you can get to type 'fuckoff'? :-)


Let me test it again...

Edit: No I swear, when I typed fuckingoff.ing and post the comment it shows as fuckingofi.ing to me. I edited the post a dozen of times and it always displayed something else. I tested it even on two browsers!


Seems to work for me: Fuckoff fuckoff.ing


I only see *** ***.ing


You might be mitm-ed. there’s no space in the original.


It must be Anton's son.


Sadly phish.ing is over $1000 / year.


But think of the return


Think of how funny it will be when you send out a social engineering training test email with that URL to your company and see who falls for it.


  https://we.are.totally.not.phish.ing/this-is-legit/link.php?really=just-click-it&fill-in=your-pii&submit=true


Wouldn't it be called fish.ing instead, so you'd trick users.


The real money is in spearfish.ing.


I can't wait for creditcard.ing, pinpas.ing, debitkarte.ing, cartededebit.ing, and all the others to be sent across the world.

Might as well pre-emptively add .ing to every phishing list out there.


Mobile app is already first class citizen at ING in some EU countries. One is unable to make transactions or even is locked out completely from all online channels after losing access to their mobile app, or if their app simply stops responding on tapping the "Confirm" button. Web is merely second class citizen. No idea how they arrived to this retarded architectue. Submitting any kind of architectural feedback to a bank is hopeless and helpless, these fuckers always know better.


> No idea how they arrived to this retarded architecture

2FA is known to increase security drastically. It's easy to understand why it's a good idea.

EU banks in particular do this because 2FA for banks is mandated by a EU level directive.

> Submitting any kind of architectural feedback to a bank is hopeless and helpless, these fuckers always know better.

In this case they clearly do.


There are lots of options for 2FA that don't require me to install a bloated and buggy app that only supports one bank.


You don't have to install it, you can ask them to send you a physical 2FA device instead.


They charge money for physical 2FA device.

https://www.ing.de/hilfe/auftraege-freigeben/phototan/


In at least one EU country the only available free of charge second factor of 2FA at ING is their FULL MOBILE BANKING APP. You're posting a comment at HN explaining that "mobile banking app is 2FA because security because EU", are you working there?


Hm, last time I tried 3 years ago paper mails were their only channel (after opening an account online). They were so past century. If they do anything with this TLD before improving their basic banking platform/UX it will only prove the point of how retarded they have been.


It is, the reasoning along as to buy an .ing domain is laughable at best. it does nothing that a .com isn't already doing


I mean, strictly speaking, this argument could apply to any public suffix. Why not have every site be its own TLD in a single global namespace?


or maybe they'll buy a whole bunch of insult domains imveryunhappywith.ing dontuse.ing, yourmotherhasapreferenceformassagetoolsfrom.ing


that's so insult.ing


exactly my fist thought :)




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: