Live data from Hacker News

Humans Are Bad at URLs and Fonts Don’t Matter

troyhunt.com

41–50 of 109 posts

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#41

This is one of the reasons why I think it was a mistake for the web browsers to de-emphasize EV certificates. Precisely because they are expensive and difficult to get automatically, they can be a an extra protection against phishing. I fear that because of these kind of URL issues, and with the deemphasis of EV certificates which would have provided a somewhat decentralized solution, we will end up in a world where…

An EV cert basically screams you have no idea what you are doing in the security realm. "We can't make our site secure, but we can make it look secure.". Like when people put those little "security seal" gifs all over the place.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#42
While this is a legitimate problem, the article seems to be a disguised advertisement for NordVPN and 1Password, who Troy Hunt is partnered with [1] [2]. There is a clear bias towards suggesting that the solution to the problem is that everyone signs up and pays for these services.

[1] https://www.troyhunt.com/im-partnering-with-nord-as-a-strate...

[2] https://www.troyhunt.com/have-i-been-pwned-is-now-partnering...

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#43

While this is a legitimate problem, the article seems to be a disguised advertisement for NordVPN and 1Password, who Troy Hunt is partnered with [1] [2]. There is a clear bias towards suggesting that the solution to the problem is that everyone signs up and pays for these services. [1] https://www.troyhunt.com/im-partnering-with-nord-as-a-strate... [2] https://www.troyhunt.com/have-i-been-pwned-is-now-partnering...

And this is not the first time [1], either. I feel it's unethical to not disclose in the article that he's affiliated with the services he's advertising.

[1] https://news.ycombinator.com/item?id=24544195

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#44

A password manager helps simply because it "remembers" exactly what sites you've been to in the past and if you go to a different site with a same looking url it won't auto-fill. Well, your browser also has a history of all the sites you've been to in the past, and people tend not to go to a lot of random sites. It would be pretty simple to display something when you go to a site you've never been to before. Just an…

> Well, your browser also has a history of all the sites you've been to in the past, and people tend not to go to a lot of random sites. It would be pretty simple to display something when you go to a site you've never been to before. Just an unobtrusive, but not too unobtrusive, "this is your first visit to this site.". Whoa, that seems like a shockingly good idea! It could look similar to what happens when you ente…

Several people are suggesting this on this post, but it won't work for input. The phishers will just stop using password forms. And if you make it for all forms, well that can probably be faked trivially with javascript.

It _would_ work for first time visits, but I propose that it will be too common that people will ignore it or brainlessly click through it, providing little to no security benefit.

Phishing is an artifact of the bad design of the system of remembering a password, and will likely continue until we design and widely deploy a better alternative.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#45
post #43

While this is a legitimate problem, the article seems to be a disguised advertisement for NordVPN and 1Password, who Troy Hunt is partnered with [1] [2]. There is a clear bias towards suggesting that the solution to the problem is that everyone signs up and pays for these services. [1] https://www.troyhunt.com/im-partnering-with-nord-as-a-strate... [2] https://www.troyhunt.com/have-i-been-pwned-is-now-partnering...

And this is not the first time [1], either. I feel it's unethical to not disclose in the article that he's affiliated with the services he's advertising. [1] https://news.ycombinator.com/item?id=24544195

> Please don't use HN primarily for promotion. It's ok to post your own stuff occasionally, but the primary use of the site should be for curiosity. — https://news.ycombinator.com/newsguidelines.html

I wish I could downvote this submission. I wonder whether I should flag it.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#46
> I mean what if the world was completely different to what it actually is and people understood visual security indicators?

The article is full of tweets by people, including Hunt himself, that use visual security indicators

Note: biased. Worked on a web verification startup for 4 years. Including campaigning for better indicators.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#47
post #45
post #43

Earlier quoted context omitted.

And this is not the first time [1], either. I feel it's unethical to not disclose in the article that he's affiliated with the services he's advertising. [1] https://news.ycombinator.com/item?id=24544195

> Please don't use HN primarily for promotion. It's ok to post your own stuff occasionally, but the primary use of the site should be for curiosity. — https://news.ycombinator.com/newsguidelines.html I wish I could downvote this submission. I wonder whether I should flag it.

Neither the parent link nor the post I linked are from accounts with an inordinate number of posts for Troy Hunt's blog (I count 1 each). I don't think he's breaking HN rules, I just think he's being deceptive and unethical.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#48
post #22

Can anyone tell me why 1Password is specifically suggested over, say, literally any other password manager? Why is 1Password better than your browser’s own, free, preconfigured manager?

Why it's suggested and why it's better are separate questions. It's suggested because the author has a vested interest in 1Password.

As for why it's better than the browser's password manager... for an individual, it probably isn't. For me, I will say that I like that 1Password allows my partner and me to share passwords to joint accounts, which iCloud Keychain can't do without getting out of sync when a password changes. (iCloud Keychain also only works on Apple devices, of course.)

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#49

https://www.schneier.com/blog/archives/2006/02/petnames.html

Great link. In a broader context this is makes me wonder whether the development in-group nomenclature (slang) developed for similar reasons, to defend against collisions in terminology with others where misunderstandings could lead to disagreements and fights. You can still speak the same language, but if someone overhears you (tries to interpret what you type into a url bar) they don't understand unless you have intentionally specified the mapping to the global nomenclature. Of course this would require that browsers stop trying to redirect you to who knows where when you type in a single word in the url bar so that not typing in the local name would lead to a failure.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#50

Earlier quoted context omitted.

Just like in real life, I think the answer is not prevention but accountability. The only thing stopping a random person from bashing in my head on the sidewalk (besides moral decency) is their understanding of the consequences. They can do it, but they'll go to jail for a long, long time. Similarly, the answer on the net is not to stop bad actors from being bad. It's to punish and hold accountable those that do bad…

A lot of phishing, and other online financial crime, is perpetrated by groups operating with the support of their home governments. There's no way to hold North Korean state-backed phishing/criminal hacking groups accountable without disconnecting North Korea from the Internet or going to war with them. Similar issues apply to curtailing online crime committed by Russian mafia entities, as they are well connected to…

Seems like something functioning governments should be able to resolve with extradition treaties, and sanctions for those who do not abide by them.
Post reply on HN