Why is this on 3d-bbc•co•uk 😭😭😭 yes, a hyphen, not a dot! Not a subdomain like 3d•bbc•co•uk
When scrolling past this, I even read it as 3d•bbc•co•uk, which is why this domain is especially dangerous.
Domains like this make phishing easier for threat actors — they don't have to try as hard when choosing a domains.
People can't read URLs properly already, but we're constantly told to read the URL. How can we do that with this?
I get that this is an experiment, probably the work of an overachieving employee working in their spare time. It could be developed by a third party. But organisations need to run these sorts of things on a unified microsite domain.
Google does this using withgoogle•com: experiments•withgoogle•com, buildyourfuture•withgoogle•com…
Meta does it with atmeta•com: investor•atmeta•com, datacenters•atmeta•com, communityforums•atmeta•com…
This domain pattern clearly demarcates trust boundaries while unifying your domain estate, because you'll probably forget about 3d-bbc•co•uk in a few years and it will be registered by someone else.
But most importantly, since 3d-bbc•co•uk is legitimate, it gives threat actors confidence to effortlessly register domains like this, to phish users of the BBC and other orgs, and consumers won't bat an eyelid. They won't spot the bad domain. They'll use claims to authority in the bad email to gain misguided trust.
It's a slippery slope. Domains like this weaken trust and our collective defence.
We've got this incredible feature on the BBC through the World Cup. For games the BBC cover, you can watch the games live (or back) in this 3D space, freely controlling the camera angle or viewing it in first person from any players' POV. Top for tactical insight. See here:
3d-bbc.co.uk/