Live data from Hacker News

Attackers Used Look-Alike Domains to Steal $1M from a Chinese VC

darkreading.com

11–20 of 37 posts

Re: Attackers Used Look-Alike Domains to Steal $1M from a Chinese VC

#11
post #3

Earlier quoted context omitted.

Isn’t it time to see more widespread use of encryption in emails? What I’m pertaining to is signing emails to make sure they are coming from correct source.

Encryption doesn’t help Unicode homoglyph attacks. I can send you encrypted messages all day long from google.com, even though they’re not coming from who you think they are.

When I use the actual second party's public key, the decryption won't work though, so you'd be found out immediately, surely?

Re: Attackers Used Look-Alike Domains to Steal $1M from a Chinese VC

#14
Firefox users: be sure to set "network.IDN_show_punycode" to "true" in about:config.

Test with the fake Apple domain https://www.xn--80ak6aa92e.com/ .

See "Phishing with Unicode Domains" for more information: https://www.xudongz.com/blog/2017/idn-phishing/ .

Re: Attackers Used Look-Alike Domains to Steal $1M from a Chinese VC

#15
post #3

Earlier quoted context omitted.

Isn’t it time to see more widespread use of encryption in emails? What I’m pertaining to is signing emails to make sure they are coming from correct source.

Encryption doesn’t help Unicode homoglyph attacks. I can send you encrypted messages all day long from google.com, even though they’re not coming from who you think they are.

You wouldn't be able to sign the fake message with the fake domain unless you compromised the sender's PGP private key, which was not the vector of this attack.

Re: Attackers Used Look-Alike Domains to Steal $1M from a Chinese VC

#17

I'm thinking it might have quite likely been people from inside both the VC firm and the startup to be funded, collaborating to phish the money away from their companies...

Considering that both the countries (Israel, China) are and have been involved in very unsavory stuff, I wouldn’t say that it’s an unreasonable conclusion. Less than 50% likely, probably. But definitely not out of the question.

Re: Attackers Used Look-Alike Domains to Steal $1M from a Chinese VC

#19
post #14

Firefox users: be sure to set "network.IDN_show_punycode" to "true" in about:config. Test with the fake Apple domain https://www.xn--80ak6aa92e.com/ . See "Phishing with Unicode Domains" for more information: https://www.xudongz.com/blog/2017/idn-phishing/ .

For the situation in the article it would not have changed anything. As the fake domains were just adding an 's' to the end of the domain.

Also I'm not sure what effect that will have for Chinese users. It might make many of their URLs look strange to them.

See: https://www.reddit.com/r/firefox/comments/7ul9p3/why_is_netw...

Post reply on HN