Live data from Hacker News

Humans Are Bad at URLs and Fonts Don’t Matter

troyhunt.com

81–90 of 109 posts

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#81
post #58

Earlier quoted context omitted.

Yes. That’s why voter anonymity is so important, for example.

I would posit that for normal run-of-the-mill communications, anonymity is overrated. What is this edge case of politically sensitive communications that you think is at risk?

What isn’t “politically sensitive”?

If you create a git repo, the first branch’s name is a controversial political issue.

“Everything’s political” ~ What’s-his-face the communist in Fiddler on the Roof after introducing “Will you marry me?” as “a political question.”

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#82

This is one of the reasons why I think it was a mistake for the web browsers to de-emphasize EV certificates. Precisely because they are expensive and difficult to get automatically, they can be a an extra protection against phishing. I fear that because of these kind of URL issues, and with the deemphasis of EV certificates which would have provided a somewhat decentralized solution, we will end up in a world where…

> Precisely because they are expensive and difficult to get automatically, they can be a an extra protection against phishing. And the requirement for an EV certificate is that it has to be registered specifically in the corporate name, which isn't necessarily the well-known trade name. Furthermore, anyone could choose to register their company as, say, "Microsoft" if it's not in the same jurisdiction as the actual M…

The concept of TLS certs validating the identity of a business entity--rather than just ownership of a domain name--has merit even though the implementation of EVs was poorly considered.

A system that presented the end user with a business card of relevant information regarding a given website could be very effective if done properly. Presenting a list of industries and trademarks that the site does business under in the user's current jurisdiction would be a good start.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#83
I always wondered why don't browsers highlight the address bar with the color sourced from the domain hash? If my bank's site is always pink but after clicking a link it's suddenly teal, could it get any easier?

When https green shields and locks appeared at first I thought it's something like that, only to be disappointed.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#84

Earlier quoted context omitted.

Just like in real life, I think the answer is not prevention but accountability. The only thing stopping a random person from bashing in my head on the sidewalk (besides moral decency) is their understanding of the consequences. They can do it, but they'll go to jail for a long, long time. Similarly, the answer on the net is not to stop bad actors from being bad. It's to punish and hold accountable those that do bad…

A lot of phishing, and other online financial crime, is perpetrated by groups operating with the support of their home governments. There's no way to hold North Korean state-backed phishing/criminal hacking groups accountable without disconnecting North Korea from the Internet or going to war with them. Similar issues apply to curtailing online crime committed by Russian mafia entities, as they are well connected to…

Are there any sources for this? I'm not saying what you're saying is true, but I have a hard time believing the majority of scams and spam out there is state-sponsored as opposed to independent bad actors, and if accountability can at least weed those out then that's still a win.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#85
post #22

Can anyone tell me why 1Password is specifically suggested over, say, literally any other password manager? Why is 1Password better than your browser’s own, free, preconfigured manager?

Because the article is an ad for 1password quite literally, hes on board of advisors. Same with nordvpn that he is shilling.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#86

Earlier quoted context omitted.

A lot of phishing, and other online financial crime, is perpetrated by groups operating with the support of their home governments. There's no way to hold North Korean state-backed phishing/criminal hacking groups accountable without disconnecting North Korea from the Internet or going to war with them. Similar issues apply to curtailing online crime committed by Russian mafia entities, as they are well connected to…

Seems like something functioning governments should be able to resolve with extradition treaties, and sanctions for those who do not abide by them.

North Korea is already under severe economic sanctions for its nuclear weapons program and other geopolitical issues[0]. Russia is also under economic sanctions for invading Ukraine. There's very little the rest of the world can do to hold either of them accountable for sanctioning organized fraud groups in their territories.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#87

While this is a legitimate problem, the article seems to be a disguised advertisement for NordVPN and 1Password, who Troy Hunt is partnered with [1] [2]. There is a clear bias towards suggesting that the solution to the problem is that everyone signs up and pays for these services. [1] https://www.troyhunt.com/im-partnering-with-nord-as-a-strate... [2] https://www.troyhunt.com/have-i-been-pwned-is-now-partnering...

He loses my respect with that. NordVPN isn't without its problems and he's also selling a VPN that monitors your browsing to detect this stuff. A VPN that grows by underselling itself all over youtube isn't one I want to be a customer of.

If he wants to use his rep to write fluff pieces for his corporate sponsor, so be it. But he discredits himself for doing so.

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#88
post #87

While this is a legitimate problem, the article seems to be a disguised advertisement for NordVPN and 1Password, who Troy Hunt is partnered with [1] [2]. There is a clear bias towards suggesting that the solution to the problem is that everyone signs up and pays for these services. [1] https://www.troyhunt.com/im-partnering-with-nord-as-a-strate... [2] https://www.troyhunt.com/have-i-been-pwned-is-now-partnering...

He loses my respect with that. NordVPN isn't without its problems and he's also selling a VPN that monitors your browsing to detect this stuff. A VPN that grows by underselling itself all over youtube isn't one I want to be a customer of. If he wants to use his rep to write fluff pieces for his corporate sponsor, so be it. But he discredits himself for doing so.

> A VPN that grows by underselling itself all over youtube

You're avoiding a service because it sponsors content you enjoy?

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#89

This is one of the reasons why I think it was a mistake for the web browsers to de-emphasize EV certificates. Precisely because they are expensive and difficult to get automatically, they can be a an extra protection against phishing. I fear that because of these kind of URL issues, and with the deemphasis of EV certificates which would have provided a somewhat decentralized solution, we will end up in a world where…

Even better: Rather than all the red-tape, you can just use an indicator between `$` and `$$$$$` to indicate how much the subject paid for the certificate. This is better because it establishes more than just two (five!) tiers of credibility. I briefly considered adding a sixth tier, but I think that would be distasteful.

That is essentially what you used to be paying for with certs back in the day. You bought yourself a $500, $1000, or $1500 cert based on the level of liability insurance you needed if someone "broke the encryption". The extra money does help pay for extra betting by the issuing authority, theoretically.

The thing is, just charging extra money would probably work for the most part, even if it isn't all that fair. Also, how do I set myself up as the authority you need to pay $$$$$ to for a certificate? That seems like a pretty sweet market to be in. ;)

Re: Humans Are Bad at URLs and Fonts Don’t Matter

#90
post #6

For firefox, you can disable IDN in the urlbar with: user_pref("network.IDN_show_punycode", true); in your user.js. Then all URLs will appear in their punycode form, eg apple.com with the cyrillic glyphs will show as: https://www.xn--80ak6aa92e.com/ Is this good enough? Probably not in general. - It relies on you to notice the URL bar after you've clicked a link. Worse, it relies on you to notice the URL bar after yo…

I'm honestly surprised at Firefox's behavior here. I thought all of the browsers years ago identified homoglyph attacks and deployed defenses. For example, in Safari, this domain does render as https://www.xn--80ak6aa92e.com because Safari decided this was a homoglyph attack. My impression was all the browsers did this for any domain that used a homoglyph of a latin character, so why is Firefox failing?

Firefox wontfix'd it because it would be racist to not show phishy IDNs.

https://bugzilla.mozilla.org/show_bug.cgi?id=1332714

Post reply on HN