6 ms·
Google Is Battling a Russian Spammer Over the Use of the Letter 'G'
- hlandau 10y agoI can't believe it took this long for someone to register that name.
- krona 10y agoI would've thought Google themselves would have bought it many years ago, to protect their users (and their brand.)
- amptorn 10y agoThere's a lot of Unicode variations on "google". Potentially too many to make that practical...
- dogma1138 10y agonot that many to make it even remotely unfeasible.
- scrollaway 10y agoUh, no, more than enough to make it remotely unfeasible. There are tons of variations of the letters in "google" and with all its permutations + all the TLDs, I wouldn't be surprised if there's at least a few million domains. With all the new TLDs as well which are extremely pricey, the costs for this aren't a joke. And don't forget that there's an endless amount of misspellings and word variations (googleapps.com, ...).
- dogma1138 10y agogoogleapps.com is registerd to google ;) Google isn't just anyone, they aren't going to pay 40$ per year per domain.
- scrollaway 10y agoExactly, it's a google domain. And yet, "googleapps.website" is up for grabs right now. They have thousands of these domain variations. googleusercontent.com? picasa? googleplus? gmail? googlemail? ...
- qntty 10y agoHow many could there possible be? 1000? 5000? If google had to spend $50,000/year to never have to worry about this, it would easily be worth it.
- dogma1138 10y agoProbably considerably more, basically depending on how many unicode variations that would render into graphically similar latin font characters of G,g,O,L,l,E,e and then you have all the permutations. So that's probably a few 10,000's overall and then you need to register them for every top level domain that Google operates in so, com., de., co.uk. etc... Overall there are probably a like 100,000's domains that can be registered, under Google.tld_x alone, more if you count in all the other services they have. It will cost a small fortune for an individual even in bulk registration prices but still it's more than affordable for a company the size of Google. That said using cyrillic is even better http://www.miсrosoft.com http://www.miсrosoft.com doesn't looks any different than http://www.microsoft.com http://www.microsoft.com but it translates to http://www.xn--mirosoft-gch.com/ http://www.xn--mirosoft-gch.com/
- shawnz 10y agoIf there are just 5 alternate ways to represent each letter, that's already over 15000 domains.
- planteen 10y agoIf bidi control characters are allowed (not sure if they are), it's even worse. Then you could have something like *elgoog display as google
- NKCSS 10y agounicode in domains is tricky; on the one hand; it's good that we can allow people whom have non-ascii characters in their language to create domains using them, but it introduces the problems pointed out here. It would be sane to say that, when you abuse the system to trick people (as is clear with the google and lifehacker examples), that the registration is voided (and barred from future use). Maybe it should be restricted to certain TLD's though; e.g. only allow the unicode characters in TLD's that have a good reason for using them. That way, it won't be an issue for .com/.net/etc.
- garblegarble 10y agoI always thought that enforcing domain names use characters in the same glyph subset would solve a lot of problems - either all Latin or all Cyrillic, etc. (although I don't have any experience of what people put in their internationalised domain names so maybe that would conflict with a key use case somehow?)
- 3pt14159 10y agoOr you could also enforce that all characters that look similar become unavailable. For example, thèta.com might be a French fighter jet company, while théta.com could be very easily confused as the same thing, especially to non-French speakers. So I think registering that weird version of google.com should never have been possible, since the Gs could obviously be confused by a layman. Also, in general I think web browsers need to be more machine learning backed. The browser should warn you when you're about to do something dumb or when you're reading lie-based propaganda. We're trying to teach laymen to be intelligent enough to check for HTTPS and to be discerning enough to figure out what news is false, but I don't think a majority of our population is able to do so.
- syberspace 10y agowhy yes, let's cram machine learning into everything so people don't have to learn anymore. Learning is boring and takes so much time. /s I don't understand the love for voluntary infantilism. Why is it such an impossibility to have to learn a system before using it? I don't think anybody here would argue that using a keyboard is too difficult. But couldn't we just back it with machine learning and let that algorithm figure out what we want to type when we just hit random keys?
- petetnt 10y agoPopovs argument seems to contradict his statement as seen in this other Motherboard article: https://motherboard.vice.com/read/this-pro-trump-russian-is-spamming-google-analytics https://motherboard.vice.com/read/this-pro-trump-russian-is-... Before: > “I was fully prepared from April, but I wait. I could begin in a month before the elections and on a wave of the anti-Russian hysteria to receive a lot of traffic,” he said. Later: > “Lie! Not my domain!” Popov writes in bright red text regarding the site with dodgy pop-ups. > “Lie! I'm not a spammer!” he continues. Either someone is running an extensive anti-Popov campaign or Popov is realising that the campaign has been a huge mistake.
- raverbashing 10y agoNah, it's typical Russian shift blaming
- foepys 10y agoThis shows the problems with unicode in domain names. Some Cyrillic characters look exactly like Latin characters but have different codepoints, e.g. a (0x61) and а (0xB0D0). This is pretty important for businesses whose domain include an a, like banks. Google is now noticing that those malicious domains don't even have to be an exact visual match but a similar looking one is sufficient to trick users.
- usernam 10y agoIronically this is made worse by some fontsets such as Noto, that unify the look over a variety of scripts (which is something you normally _want_). This is going to be fun to watch. Unicode domain names are a can of worms.
- marcosdumay 10y ago
- ungzd 10y agoSeems that they sued vice.com too, now displays 404.
- rnhmjoj 10y agoI get a "404 horse".
- aptwebapps 10y agoPossibly to mitigate this? https://motherboard.vice.com/en_us/article/spammer-now-spamming-google-analytics-with-motherboard-article-on-spam https://motherboard.vice.com/en_us/article/spammer-now-spamm...
- morsch 10y agoAccessing the domain in question (ɢoogle.com) redirects to this fairly bizarre chain of subdomains http://money.get.away.get.a.good.job.with.more.pay.and.you.are.okay.money.it.is.a.gas.grab.that.cash.with.both.hands.and.make.a.stash.new.car.caviar.four.star.daydream.think.i.ll.buy.me.a.football.team.money.get.back.i.am.alright.jack.ilovevitaly.com/
- lucideer 10y agoWith an even more bizarre website http://webcache.googleusercontent.com/search?q=cache:RWLWj2knleEJ:money.get.away.get.a.good.job.with.more.pay.and.you.are.okay.money.it.is.a.gas.grab.that.cash.with.both.hands.and.make.a.stash.new.car.caviar.four.star.daydream.think.i.ll.buy.me.a.football.team.money.get.back.i.am.alright.jack.ilovevitaly.com/+&cd=1&hl=en&ct=clnk&gl=us http://webcache.googleusercontent.com/search?q=cache:RWLWj2k... The buttons on the background are particularly strange.
- comex 10y agoWow, that site is... interesting. > No any corporation is not associated with this project. All product names and brands are property of their respective owners. All service names used in this website are for identification of services to open only. Why the richest and the most technologically advanced multinational corporation in the world shows 'Secret.ɢoogle.com You are invited! Enter only with this ticket URL. Copy it. Vote for Trump!' in tens of millions accounts since 5 November ask not me. I don't working in their support so it's not a my problem. This site domain is ilovevitaly.com. Despite the huge number of lies without any proofs in the media, this search shell is absolutely safe and very useful. Just one very rich and influential hidden evil corporation doesn't like competitors very much. "Ask not me", sure...
- kombucha2 10y agoThat's Pink Floyd.
- soneca 10y agoGood catch! https://genius.com/Pink-floyd-money-lyrics https://genius.com/Pink-floyd-money-lyrics
- deleted 10y ago[deleted]
- annnnd 10y agoIs it possible to disable Unicode chars for domains in FF?
- OJFord 10y ago`network.enableIDN` apparently. Interesting reading (2005) here: https://bugzilla.mozilla.org/show_bug.cgi?id=279099 https://bugzilla.mozilla.org/show_bug.cgi?id=279099 -- EDIT: It doesn't 'disable' as such, but renders the 'punycode' in full, so a fake 'http://www.miсrоsоft.com' http://www.miсrоsоft.com' is rendered as instead 'http://www.xn--mirsft-yqfbx.com' http://www.xn--mirsft-yqfbx.com'. For comparison, here's fake on top of real (not in monospace since it destroys the illusion): http://www.miсrоsоft.com http://www.miсrоsоft.com http://www.microsoft.com http://www.microsoft.com
- annnnd 10y agoThanks! Setting "network.enableIDN" seems not to work, but this setting works: network.standard-url.encode-utf8 [0] [0] http://kb.mozillazine.org/Network.standard-url.encode-utf8 http://kb.mozillazine.org/Network.standard-url.encode-utf8 EDIT: doesn't work either. And the same for network.standard-url.escape-utf8. :(
- deleted 10y ago[deleted]
- r1ch 10y agoI think an issue here is Google is showing "ɢoogle" as "ɢoogle.com" and not "xn--oogle-wmc.com". The .com TLD has no support for IDNA2008 so they allow registration of these similar-looking unicode TLDs. This is why if you paste ɢoogle.com in your browser it will show the punycode instead. Basically it looks like Google is decoding punycode for all TLDs, not just those that support IDNA2008.
- merricksb 10y agoCached version (as original URL is returning 404): http://webcache.googleusercontent.com/search?q=cache:KZq3KBVYLhYJ:motherboard.vice.com/read/google-is-battling-a-russian-spammer-over-the-use-of-the-letter-g+&cd=1&hl=en&ct=clnk&gl=au http://webcache.googleusercontent.com/search?q=cache:KZq3KBV...
- homero 10y agoVice is under ddos now
- runnr_az 10y agoMy coworker built a little tool to identify potential domain spam problems: http://upsidedown.domains/alternate.html?google http://upsidedown.domains/alternate.html?google
- krumplifej 10y agoI stumbled upon this vulnerability during a white hat phishing test. The success rate was very high when I used the alternate G domains even among hard core IT folks. People have a tendency to overlook the difference. At that point I faced an ethical dilemma: should I just forget about this or maybe publish something? Neither options seemed right. Finally decided to get all the unreserved domain names for the fortune 500. Had to set a limit somewhere... To my surprise 102 of the vulnerable 103 fortune 500 was still available. Now I own these domains... If these companies want them, I am happy to transfer them over. If they do not care, I just let them expire. For my company - we set the spam filters according, changed our web proxies, and also own the alternate domains. I also submitted a bug report with a major software vendor, because their solution further amplified the problem. They are working on a fix...