Google's New .zip and .mov Domains Raise Security Concerns
Via BleepingComputer
The Story
Google's release of the new .zip and .mov top level domains sparked a cybersecurity debate because the extensions double as common file formats.
Google made eight new domains generally purchasable in May 2023, and although .zip and .mov were technically created back in 2014, only now could anyone register them.
The core risk comes from automatic linkification, where platforms like Twitter turn any text ending in .zip or .mov into a clickable link, letting attackers register a domain matching a familiar filename such as update.zip and redirect users to malware or phishing.
Researchers at Silent Push Labs found a credential stealing phishing page spoofing a Microsoft Office download, and Bobby Rauch showed how Unicode characters and the URL userinfo delimiter could craft convincing fake links.
Google responded that applications already have mitigations such as Safe Browsing that apply to these domains, while the maintainers of the Public Suffix List declined to remove the extensions.
Security experts remained split, warning that a single employee tricked into installing malware could compromise an entire corporate network.
Google made eight new domains generally purchasable in May 2023, and although .zip and .mov were technically created back in 2014, only now could anyone register them.
The core risk comes from automatic linkification, where platforms like Twitter turn any text ending in .zip or .mov into a clickable link, letting attackers register a domain matching a familiar filename such as update.zip and redirect users to malware or phishing.
Researchers at Silent Push Labs found a credential stealing phishing page spoofing a Microsoft Office download, and Bobby Rauch showed how Unicode characters and the URL userinfo delimiter could craft convincing fake links.
Google responded that applications already have mitigations such as Safe Browsing that apply to these domains, while the maintainers of the Public Suffix List declined to remove the extensions.
Security experts remained split, warning that a single employee tricked into installing malware could compromise an entire corporate network.
Go Deeper
Read the original reporting at BleepingComputer.
Read Full Story at BleepingComputer →