4 ms·
Web browsers already implement a ‘near miss that’s probably intentionally confusing” check on domains, and the code is readily extracted and shared (I know abou
by c256 8y ago
Web browsers already implement a ‘near miss that’s probably intentionally confusing” check on domains, and the code is readily extracted and shared (I know about it because someone extracted it and added it to Emacs a couple years ago).
This seems like one of those cases where more large infrastructure people need to say “don’t let the perfect be the enemy of the good”.
- joombaga 8y ago> Web browsers already implement a ‘near miss that’s probably intentionally confusing” check on domains, What do they do with the information?
- c256 8y agoFor Emacs (and its web browsers, email clients, etc) this comes up in a concept of “confusables” strings that could easily be mistaken for other strings, usually as a result of Unicode tricks (multiple similar code points from different scripts, or composed versus combined characters, or sometimes ugly tricks with LtR/RtL markers. The code added to emacs was. A library that could be used to detect these probably-misleading tricks, but they didn’t implement a policy for them. The uses I saw of the library fell into the sort of “Danger, Will Robinson! This looks like it might be malicious” type warnings that can be found in most browsers these days.