Many US government sites now have a clear banner at the top with a US flag and statement declaring "An official website of the United States Government." Some go further and include a link to expose an explanation for "here's how you know" that includes the statement "Official websites use .gov"
None of this appears on www.usps.com. www.usps.gov redirects to www.usps.com. Bare usps.gov does not (goes nowhere)
I wonder how much the phishing would decrease if the USPS website was served on usps.gov with the "an official website" and "how you know" seen on other official US gov't sites.
I dunno, I think the phishing scammers could just copy the banner and change the "how you know" part to include a big green check mark that says "this site was verified to be the real USPS". I don't think most people who are falling for these phishing scams wouldn't also fall for a fake banner.
I just think the inconsistency is glaring. Would love to be a fly on the wall of what I expect/hope was a heated debate over why USPS, one of if not the top US government websites used by people in the US, should opt-out of the anti-phishing tactics used by most other US gov't sites.
And for that matter, why does www.usps.gov redirect to the .com rather than vice-versa, and why does the bare usps.gov domain resolve to nothing? Who makes these decisions and how do they result in the opposite of what I (perhaps naively) would expect rational decision-makers to do?
A better solution would be for the government to seize the domains and arrest the scammers impersonating the post office or the IRS or any other governmental entity.
Comments
Many US government sites now have a clear banner at the top with a US flag and statement declaring "An official website of the United States Government." Some go further and include a link to expose an explanation for "here's how you know" that includes the statement "Official websites use .gov"
None of this appears on www.usps.com. www.usps.gov redirects to www.usps.com. Bare usps.gov does not (goes nowhere)
I wonder how much the phishing would decrease if the USPS website was served on usps.gov with the "an official website" and "how you know" seen on other official US gov't sites.
I dunno, I think the phishing scammers could just copy the banner and change the "how you know" part to include a big green check mark that says "this site was verified to be the real USPS". I don't think most people who are falling for these phishing scams wouldn't also fall for a fake banner.
I just think the inconsistency is glaring. Would love to be a fly on the wall of what I expect/hope was a heated debate over why USPS, one of if not the top US government websites used by people in the US, should opt-out of the anti-phishing tactics used by most other US gov't sites.
And for that matter, why does www.usps.gov redirect to the .com rather than vice-versa, and why does the bare usps.gov domain resolve to nothing? Who makes these decisions and how do they result in the opposite of what I (perhaps naively) would expect rational decision-makers to do?
A better solution would be for the government to seize the domains and arrest the scammers impersonating the post office or the IRS or any other governmental entity.
Seize the domains is doable but there's no guarantee the US has jurisdiction where the scammers are.
Literally true. OTOH, there's quite a bit that the US could do, in most cases. But that would require that the US actually care about the problem.
Don't hold your breath.