Live data from Hacker News

Humans Are Bad at URLs and Fonts Don’t Matter

troyhunt.com

71–80 of 109 posts

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#71

For one thing, I blocked that foolish kid who tweeted that browsers should warn about "googie.com" (a term that refers to a style of architecture https://en.wikipedia.org/wiki/Googie_architecture ). Knee jerk response make things worse.

I love this style and didn’t know there was a term for it. Thanks!

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#72
post #58

Earlier quoted context omitted.

Yes. That’s why voter anonymity is so important, for example.

I would posit that for normal run-of-the-mill communications, anonymity is overrated. What is this edge case of politically sensitive communications that you think is at risk?

Most HNers here including yourself are writing comments with the comfort of anonymity. I don't want to worry about anything I have to say being tied to my identity, whether it's even my thoughts that there's nothing wrong with a "master" branch much less my much more unsavory thoughts in the tech space.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#73

It's a hard problem, but I don't think there's any solution that doesn't make the web measurably worse. We have consolidation and the exclusion of bit players and new entrants in real life already, and I don't like it. Now we're talking about solving these problems on the internet in a way that seems like it will lead to the same place. I definitely don't want Google to solve this problem for me. Then again, I don't…

Why not display a warning if the character set is different from users?

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#74
This article, despite being an obvious advertisement, was informative. But I’m a bit confused about why this is considered a tricky problem, and why we need technological solutions. I’m no computer security expert, but I don’t think I will be affected. I don’t click on links in emails or (good lord) in text messages. I don’t download executables. I suppose I could end up on a counterfeit site by following a link, say, from Twitter. But I wouldn’t be following a link from Twitter to my banking site. So where is the vector? Am I being naive?

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#75

A browser-based password manager mostly solves the confusables problem. If your password manager matches by domain name, and someone tries to phish you, it will immediately clue you in that something's not right. Unfortunately this doesn't solve the problem in general, because most people don't use password managers.

What if the attack is targeted at new users. Work on signing people up for Netflix then drain their bank account.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#76

Why must there be exactly one solution that solves everything? We don't expect that anywhere else in life. Obviously it's best if there was a simple automated solution that worked in all cases, but there is no such thing. Password managers are great, but they don't counter disinformation from sites you don't have a password with. Preventing access to malicious sites only works if it's known to be malicious; new sites…

[deleted]

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#78

Earlier quoted context omitted.

> The only thing we have to lose is privacy for domain owners. This is a huge downside. Anonymous publishing is a very important right.

Must speech be anonymous to be free?

Yes. Think of countries with a mandatory "impressum" (Germany and Austria)

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#79

Why must there be exactly one solution that solves everything? We don't expect that anywhere else in life. Obviously it's best if there was a simple automated solution that worked in all cases, but there is no such thing. Password managers are great, but they don't counter disinformation from sites you don't have a password with. Preventing access to malicious sites only works if it's known to be malicious; new sites…

A few years ago, I had this idea of using identicons to visualize the host part of URLs: https://vorba.ch/2018/url-security-identicons.html

I still think this could help people realize when they are being phished at least for their most important sites in a privacy-respecting way, even if they don't use a password manager for those sites. I don't use my password manager for my banking account, for instance, since I don't want those credentials to be synced anywhere.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#80

Earlier quoted context omitted.

> Well, your browser also has a history of all the sites you've been to in the past, and people tend not to go to a lot of random sites. It would be pretty simple to display something when you go to a site you've never been to before. Just an unobtrusive, but not too unobtrusive, "this is your first visit to this site.". Whoa, that seems like a shockingly good idea! It could look similar to what happens when you ente…

Hell, that warning could be helpful even on signups to new sites: “This is your first time visiting this website. Only enter passwords on websites you trust, and don’t reuse passwords from other sites. We recommend you use this securely-generated password:”

Finally a way to know if you should try to reset your password before creating a new account. It sometimes happens that I don't remember I've already signed up for some site and forgot about it entirely.
Post reply on HN