I would revise your request. Youâre the one sending the link(s) to the end user and you should tell them you are sending it. You donât show how or why any custom name is safer. These two links go to the same place but one is masked to look âfriendlyâ.
Regular non technical employees would balk too at least the ones who have security training. It may be fine but it doesnt appear that way. Take it as a UI/UX concern for adoption.
You still havenât explained why you believe a âFriendly name / Custom domainâ would even do for security nor what that is even considered. How are you sharing pictures with âAuntieâ and what is the domain? What are you considering trusted?
That makes it even worse, as it obscures the true destination of the link.
OK, is the concern for âAuntie,â or for âregular non technical employeesâ?
And in either case, the standard security advice would be to not click on links you donât expectâbut in the example you gave, Auntie would presumably be expecting that link. And if youâre digging a bit further, youâd see that the link is to a truenas.com domain, which youâd presumably recognize as legitimate. But thatâs only if you have the sense to look at the URL in the first place, which I wouldnât expect either Auntie or âregular non technical employeesâ to do.
But I suspect there are a couple of reasons it is the way it is, and is unlikely to change:
The link must go to a domain iX controls, so they can get certificates for it.
It uses a long, apparently-random subdomain to avoid leaking any information about the account-holder.
ANYTHING obscures the true destination. If heâs asking to make his urls more friendly to Auntie then thatâs the way without a real domain. But of course no one should link on links they havenât any trust it, thatâs basic security.
Really depends on what he wants to do, in the basics if its a real Auntie go and edit her host file to direct all his links from her PC http://mynethew.com/\*
Non-technical employees who have had training is taught to not click anything unless absolutely sure and they have a good incentive to do so, at least in my company. Anyone who fails a company phishing email test (they send out these phishing emails at random once in a while) will be forced to retake their training.
So they also should be able to identify a phishing link vs legitimate link because this is one of the top focuses of the phishing training.