3 ms·
I think the hard part is how to tell if some site is "similar" to a sensitive site. Do you check just the owner ? (like in the example, but that would prevent
by cdancette 9y ago
I think the hard part is how to tell if some site is "similar" to a sensitive site. Do you check just the owner ? (like in the example, but that would prevent any other company named stripe to own an EV certificate)
Or do you check if the domain is similar to another one?
This is a very hard problem. Maybe the similar name approach could work if it displayed just a warning to the user when he visited a site owned by someone with a similar name to a sensitive site.
- paultopia 9y agoThat's what I was thinking of. A simple "hey, just so you know, this website has a pretty small edit distance from "paypal.com" (or ditto with certificate owner names). If you're trying to go to the big important financial institution that ain't it, but otherwise click here to carry on." Not perfect, obvs, but would that be an improvement?
- cdancette 9y agoAnd even sometimes, you can have totally unrelated domains, but the site that looked exactly like PayPal, and people don't look at the domain (sometimes the site doesn't even have a certificate).. Hard to find a solution to this scam problem
- yorwba 9y agoIf you want to throw machine learning at it, the browser could try to predict what site the user thinks they are on, and highlight any discrepancies. The data collection necessary to get an accurate model would however be quite invasive, so I'm not quite sure whether I'd use a browser with that ability. Maybe just having visual fingerprints of the most visited sites and serving them as a static model would be enough.
- cdancette 9y agoYeah, I guess this could work, like the spam filter in your mailbox.