Live data from Hacker News

Phishing with Unicode Domains

xn--80ak6aa92e.com

21–30 of 39 posts

Re: Phishing with Unicode Domains

#21

Do unicode URLs actually provide any real value? Every web user must be already used to typing Latin characters because so many major websites use them. So nobody would be excluded by that. Whereas, any non-Latin character is going to be nearly impossible for most of the world to enter. A particularly terrible language is Chinese where most old people can't type the characters even though they can type Latin letters.…

> A particularly terrible language is Chinese where most old people can't type the characters even though they can type Latin letters. That's because you have to deliberately invest time to sit down and learn an input method which is a non-trivial endeavor that takes weeks of effort and old people just aren't going to go back to school for that.

Is that your personal experience? Most input methods I know work by 1. knowing the Pinyin romanization of the word you want to type 2. typing it in 3. selecting the appropriate characters from a long list of candidates.

If they know the characters and Latin letters, then the only roadblock I can think of would be not knowing Pinyin. That shouldn't take weeks to learn if you already know Chinese, it's more like learning a very simple alphabet.

Re: Phishing with Unicode Domains

#22
post #5

Gosh that’s old. The original paper was from 2001, the Shmoo group wrote about it in 2005 - https://blogs.oracle.com/yakshaving/entry/so_not_funny_shmoo... - and Joi Ito and I were able to register Veriѕign.com then, to highlight how their greedy mismanagement of .com made this possible. Three possible solutions, not mutually incompatible: * Make the browsers catch it - Chrome just shows characters that look like app…

I'm not quite sure if I understand your second suggestion. Isn't that what the article claims to circumvent? I read that as 'Firefox/Chrome already do not render these characters, unless they're all from the same subset' - and the 'apple.com' is presented as completely cyrillic (I don't know/understand that alphabet and might've missed either your point or misread the article).

Re: Phishing with Unicode Domains

#23
post #2

Ouch. This is a good one. Whilst it's easy to say "Just enable punicode always" People that use the web in different languages lose a lot of functionality because of it. I could imagine a solution would be to collect a list of homogliphs then when the browser suspects an overlap it does a search for similarly​ spelt sites then warns the user of the possibility of the site being an imitation. Of course then also conve…

How about an icon next to the URL bar that displays and allows a user to select their preferred Unicode block(s)? If a character in the URL falls outside that block then the URL is highlighted in red or some warning is displayed.

Re: Phishing with Unicode Domains

#24
post #13

Earlier quoted context omitted.

> Do unicode URLs actually provide any real value? yes. Not everybody speaks english. >Every web user must be already used to typing Latin characters because so many major websites use them. s/web user/existing web user/ Unicode domains are one more piece required for the net to be as inclusive as possible.

On the other hand, unicode domains may lead to balkanization of the net. How would you even type in something like борщ.рф (and before you ask, you can easily translate its contents using Google Translate after entering the URL)? And everyone, just everyone in Russia is already capable of typing in stuff in ASCII. So the upside is small and diminishing (more people learn English over time and that's a beautiful thing…

> How would you even type in something like борщ.рф

by clicking on the link on my search engine. Though of course, either that page is in a language I can easily type (so why then use that URL?), or otherwise, I would not have searched for that term to begin with, whether I typed it in the URL bar or in the search field.

If I'm clicking a link on a page in a script I can read, then the point is moot too.

>(more people learn English over time and that's a beautiful thing

I don't know. Giving access to people who don't (yet) speak english to me is a nobler goal than forcing people to learn english and the latin script.

If they want to learn english, that's fine. But forcing them to is being exclusive.

Yes. There's a lot more content available in english and in the end, that's what made me learn it (honestly - the sole reason I started to learn english was to be able to play the talkie version of "Indiana Jones and the Fate of Atlantis"), but this was my decision. I wasn't forced to.

Re: Phishing with Unicode Domains

#27
post #5

Gosh that’s old. The original paper was from 2001, the Shmoo group wrote about it in 2005 - https://blogs.oracle.com/yakshaving/entry/so_not_funny_shmoo... - and Joi Ito and I were able to register Veriѕign.com then, to highlight how their greedy mismanagement of .com made this possible. Three possible solutions, not mutually incompatible: * Make the browsers catch it - Chrome just shows characters that look like app…

Update your Chrome

Re: Phishing with Unicode Domains

#28
post #5

Gosh that’s old. The original paper was from 2001, the Shmoo group wrote about it in 2005 - https://blogs.oracle.com/yakshaving/entry/so_not_funny_shmoo... - and Joi Ito and I were able to register Veriѕign.com then, to highlight how their greedy mismanagement of .com made this possible. Three possible solutions, not mutually incompatible: * Make the browsers catch it - Chrome just shows characters that look like app…

As far as I understand it the actual solution is that registries aren't supposed to let you buy a domain that looks like an existing domain. But that's broken?

And this domain isn't made of mixed characters.

Re: Phishing with Unicode Domains

#29

Do unicode URLs actually provide any real value? Every web user must be already used to typing Latin characters because so many major websites use them. So nobody would be excluded by that. Whereas, any non-Latin character is going to be nearly impossible for most of the world to enter. A particularly terrible language is Chinese where most old people can't type the characters even though they can type Latin letters.…

I see it as a very basic token of respect for other cultures, the actual costs of which in technical effort and a scammer here and there don't even register in absolute terms.

Re: Phishing with Unicode Domains

#30

Safari just displays it as " https://www.xn--80ak6aa92e.com" whereas Chrome (Version 57.0.2987.133 (64-bit)) displays it as the author intended.

Same with pale moon just displays it with the puny code instead of the unicode characters.

Firefox 52.0.2 here displays it as apple.com So updated Firefox (which failed until I reran it) and then.. Still displays it as apple.com (Firefox 53.0)

Post reply on HN