Post
Topic
Board Beginners & Help
Re: [WARNING] PHISHING - Trezor Typosquatting Domain
by
brianddk
on 13/02/2020, 03:51:06 UTC
As the reddit thread suggests, add these sites to a hosts file or ask PiHole to catch them.  You can also do a bit of study of how SSL works.  All these sites have a "Lets Encrypt" SSL cert, whereas the official trezor wallet sites have certs issued by "Amazon".  If you want to offload the work, you can always look the sites up on Alexa.

https://www.alexa.com/siteinfo/trezor.us <== Phishing sites have poor rank

https://www.alexa.com/siteinfo/trezor.io <== Real sites are well ranked

If you want to offload even more you can use the Alexa Traffic Rank plugin, but that will harvest a lot of browsing data unless you tweek the settings.  The plugin is nice since you have a very visual indicator as to whether the site is well ranked (legit) or poorly ranked (phish)