Live data from Hacker News

Humans Are Bad at URLs and Fonts Don’t Matter

troyhunt.com

51–60 of 109 posts

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#51
post #11

Earlier quoted context omitted.

Just like in real life, I think the answer is not prevention but accountability. The only thing stopping a random person from bashing in my head on the sidewalk (besides moral decency) is their understanding of the consequences. They can do it, but they'll go to jail for a long, long time. Similarly, the answer on the net is not to stop bad actors from being bad. It's to punish and hold accountable those that do bad…

Hopefully the consequences are not the only thing.

Besides moral decency, I said. What else do you think there is?

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#52

Earlier quoted context omitted.

Just like in real life, I think the answer is not prevention but accountability. The only thing stopping a random person from bashing in my head on the sidewalk (besides moral decency) is their understanding of the consequences. They can do it, but they'll go to jail for a long, long time. Similarly, the answer on the net is not to stop bad actors from being bad. It's to punish and hold accountable those that do bad…

> The only thing we have to lose is privacy for domain owners. This is a huge downside. Anonymous publishing is a very important right.

Must speech be anonymous to be free?

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#54

Earlier quoted context omitted.

> Well, your browser also has a history of all the sites you've been to in the past, and people tend not to go to a lot of random sites. It would be pretty simple to display something when you go to a site you've never been to before. Just an unobtrusive, but not too unobtrusive, "this is your first visit to this site.". Whoa, that seems like a shockingly good idea! It could look similar to what happens when you ente…

Several people are suggesting this on this post, but it won't work for input. The phishers will just stop using password forms. And if you make it for all forms, well that can probably be faked trivially with javascript. It _would_ work for first time visits, but I propose that it will be too common that people will ignore it or brainlessly click through it, providing little to no security benefit. Phishing is an art…

You could trigger on any keypress on a first-time site.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#55

While this is a legitimate problem, the article seems to be a disguised advertisement for NordVPN and 1Password, who Troy Hunt is partnered with [1] [2]. There is a clear bias towards suggesting that the solution to the problem is that everyone signs up and pays for these services. [1] https://www.troyhunt.com/im-partnering-with-nord-as-a-strate... [2] https://www.troyhunt.com/have-i-been-pwned-is-now-partnering...

Also take note of the latest post on author's blog, "I've Joined the 1Password Board of Advisers"

https://www.troyhunt.com/ive-joined-the-1password-board-of-a...

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#56
post #47
post #45

Earlier quoted context omitted.

> Please don't use HN primarily for promotion. It's ok to post your own stuff occasionally, but the primary use of the site should be for curiosity. — https://news.ycombinator.com/newsguidelines.html I wish I could downvote this submission. I wonder whether I should flag it.

Neither the parent link nor the post I linked are from accounts with an inordinate number of posts for Troy Hunt's blog (I count 1 each). I don't think he's breaking HN rules, I just think he's being deceptive and unethical.

Right, I don’t want to take the accounts’ karma (certainly not more than they’ve gained from the submissions), I just want to lower the prominence of the links funneling traffic to the unethical and deceptive post.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#57
post #54

Earlier quoted context omitted.

Several people are suggesting this on this post, but it won't work for input. The phishers will just stop using password forms. And if you make it for all forms, well that can probably be faked trivially with javascript. It _would_ work for first time visits, but I propose that it will be too common that people will ignore it or brainlessly click through it, providing little to no security benefit. Phishing is an art…

You could trigger on any keypress on a first-time site.

Hopefully being careful with TAB or anything else somebody might be using for navigation. God help you if you use vimium in that world.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#58

Earlier quoted context omitted.

> The only thing we have to lose is privacy for domain owners. This is a huge downside. Anonymous publishing is a very important right.

Must speech be anonymous to be free?

Yes. That’s why voter anonymity is so important, for example.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#60

Earlier quoted context omitted.

Just like in real life, I think the answer is not prevention but accountability. The only thing stopping a random person from bashing in my head on the sidewalk (besides moral decency) is their understanding of the consequences. They can do it, but they'll go to jail for a long, long time. Similarly, the answer on the net is not to stop bad actors from being bad. It's to punish and hold accountable those that do bad…

> The only thing we have to lose is privacy for domain owners. This is a huge downside. Anonymous publishing is a very important right.

> > The only thing we have to lose is privacy for domain owners.

> This is a huge downside. Anonymous publishing is a very important right.

It also wouldn't work. Or rather, at best it would only work as well as political campaign message attribution does (and that's with considerable enforcement muscle aimed at it).

Somehow "dark money" often manages to evade these efforts, and evade the consequences of violations, and I wouldn't expect transnational phishing and scams to be any different.

Which isn't to say that we should stop trying, but sacrificing the capability of the general public for anonymous speech in return for dubious-at-best attribution by well-heeled actors seems like a poor tradeoff.

Post reply on HN