4 ms·
Encryption doesn’t help Unicode homoglyph attacks. I can send you encrypted messages all day long from google.com, even though they’re not coming from who you t
by bayarrhea 7y ago
Encryption doesn’t help Unicode homoglyph attacks. I can send you encrypted messages all day long from google.com, even though they’re not coming from who you think they are.
- DyslexicAtheist 7y agoif you don't care about unicode domains then mitigation can be very simple using dnsmasq, e.g.: in /etc/dnsmasq.conf add something like: # Add domains which you want to force to an IP address here. address=/:xn--*:/0.0.0.0 (in case your dnsmasq doesn't support this then there is a patch here: https://github.com/spacedingo/dnsmasq-regexp_2.76 https://github.com/spacedingo/dnsmasq-regexp_2.76)
- deleted 7y ago[deleted]
- yabadabadoes 7y agoIf you are using web of trust in a gpg style then homoglyph attacks are not particularly effective.. If you are using CAs then homoglyph attacks are the simplest of many attacks based on a system of minimal technical compliance.
- pbhjpbhj 7y agoWhen I use the actual second party's public key, the decryption won't work though, so you'd be found out immediately, surely?
- mirimir 7y agoExactly so.
- zelly 7y agoYou wouldn't be able to sign the fake message with the fake domain unless you compromised the sender's PGP private key, which was not the vector of this attack.
- deleted 7y ago[deleted]