6 ms·
> you could just replace any of the letters in 'user' with a different, but almost-identical looking unicode symbol and you'd still have an exploit. The post m
by codesections 5y ago
> you could just replace any of the letters in 'user' with a different, but almost-identical looking unicode symbol and you'd still have an exploit.
The post mentions that exploit (and Rust's already existing defense) in the appendix.
Here are the details, as explained in a previous post:
> The compiler will warn about potentially confusing situations involving different scripts. For example, using identifiers that look very similar will result in a warning.
warning: identifier pair considered confusable between `s` and `s`
https://blog.rust-lang.org/2021/06/17/Rust-1.53.0.html https://blog.rust-lang.org/2021/06/17/Rust-1.53.0.html
- joosters 5y agoThe compiler will warn about potentially confusing situations involving different scripts. For example, using identifiers that look very similar will result in a warning. Unfortunately, I've little experience of rust, so I don't have experience of that warning. It would certainly help catch a one-liner exploit, but wouldn't it be excessively noisy for code written in non-english languages?
- wongarsu 5y agoIt only warns if there actually are two identifiers that look similar. Even if it's not malicious it's still confusing and is worth renaming. But if you want to, turning off specific warnings for a file or block of code is really simple in rust, just add "#[allow(confusable_idents)]"
- estebank 5y agoThe Unicode homoglyph lint will only trigger if there are multiple identifiers that can look the same, it's not a blanket warning on anything that isn't ASCII. It's close to what browsers do with domain names. And you can always allow lints.
- lol768 5y agoAm I missing something here? The spacing around these homoglyph is almost always noticeably wider than it should be such that I don't understand how you could ever miss it in any half-decent code review. if access_level != "user" { // Check if admin if access_level != "user" { // Check if admin Come on, that looks obviously off.
- hug 5y agoI thіnk thаt іt іs possіblе thаt you аre missing а fаіrly important point. ... And that point is that none of the vowels in my previous sentence are latin, I guess.
- mkl 5y agoI think you missed some. I can't seem to paste your fake "i"s back in, but here's what I see: $ xxd I thіnk thаt іt іs possіblе thаt you аre missing а fаіrly important point. 00000000: 4920 7468 d196 6e6b 2074 68d0 b074 20d1 I th..nk th..t . 00000010: 9674 20d1 9673 2070 6f73 73d1 9662 6cd0 .t ..s poss..bl. 00000020: b520 7468 d0b0 7420 796f 7520 d0b0 7265 . th..t you ..re 00000030: 206d 6973 7369 6e67 20d0 b020 66d0 b0d1 missing .. f... 00000040: 9672 6c79 2069 6d70 6f72 7461 6e74 2070 .rly important p 00000050: 6f69 6e74 2e0a oint..
- hug 5y agoMade you look. :) I also skipped a bunch of the "I"s.
- mkl 5y agoYes. What browser did you use to make the comment? I can't get all those characters to paste in.
- hug 5y agoFirefox 93.0 on Windows 11. Characters copied & pasted from charmap.exe a: U+0430 "Cyrillic small letter a" e: U+0435 "Cyrillic small letter e" i: U+0456 "Cyrillic small letter Byelorussian-Ukranian i"
- nonameiguess 5y agoIf you were really reviewing that code, Rust has algebraic data types, and access level should be an Enum, not a String. But it's their example. The problem isn't with homoglyphs, though. It's with bidi control characters, which are invisible to a human but not to the compiler, which is how generated code can end up semantically different from source code, which is the actual problem here. What you see in code review would be the first line, even though that isn't actually what is in the source, because an editor that is bidi-aware would show it that way.
- est31 5y ago> warning: identifier pair considered confusable Note that the lint you mention is about identifiers, while "user" is a literal. The lint does not fire for literals. String literals have always supported non ascii characters since 1.0.0, and there has never been a lint for them, until now with the 1.56.1 release.
- estebank 5y agoAlso worth noting that the homoglyph attack isn't linted for in literals or comments, only the bidi codepoints are.