MetaMask / eth-phishing-detect

Utility for detecting phishing domains targeting Web3 users
Other
1.09k stars 948 forks source link

Legitimate domain(s) report - curve.sh #88033

Closed signalreturn closed 1 week ago

signalreturn commented 1 week ago

Domain: https://curve.sh/

Details: Personal blog on cryptography and crypto in general. Stopped setting up WordPress when I discovered target audience would be served a bright-red warning for the given audience.

curve.sh serves as a domain hack, with the "h" being a C header file (my cope for .s not being a TLD).

Hoping for a technical explanation as to why this new domain was auto-blocked, if my hamming distance to curve.fi is correct, or it was something else. It got blocked before it had ever been shared on social media, so either it was a friends plugin that auto-reported it, or "curve.ccTLD" is just blocked by default.

image

Best, SIGNAL

EDIT: Additionally, I feel like this blocking might be borderline illegal or anti-competitive in nature, as these lists are sourced from Consensys-sanctioned third parties. The site does not request a web3.js injection/provider at any point, maybe that should be a guiding heuristic to determine if it should end up there in the first place and not just "is it close to another domain"?

**

AlexHerman1 commented 1 week ago

this is very similar to curve.fi which is why it was blocked.

We don't process unblocking requests for generic blog sites that have no content. This type of domain can be used obviously to phish users.

If you have something stood up here please feel free to open a new issue.

signalreturn commented 1 week ago

@AlexHerman1 I'll try to keep my reply civil in tone, but this is the most ridiculous policy I've ever heard and probably illegal. A domain-hack for "curves" has the same root as "curve.fi" so and so, curve.fi effectively owns the "curve" name regardless of TLD, that's absurd.

If that is not a sufficient argument for you personally to revisit your primitive blocking heuristic and immediately unblock curve.sh, and it does require me to have an actual website finished, please provide an e-mail for Consensys legal, and I'll give this to my counsel to liaise with them about this practice.

You can also DM me this information on Twitter/X: @SIGNAL_RETURN

signalreturn commented 1 week ago

I'm going to launch a successful DeFi project called Google.fi — Google is now blocked for all Metamask users. 😏