18 ms·
I don't think you do anything tbh. It's not really like those other situations where there's a straightforward, static answer. The problem is honestly just tha
by staticassertion 5y ago
I don't think you do anything tbh. It's not really like those other situations where there's a straightforward, static answer.
The problem is honestly just that unicode is used to convey things like "this is a PDF" or "this is going to execute code" and it's attacker controlled. It's a terrible UX that's been abused for as long as paths have existed.
So I guess hope that operating systems will find a better UX for "this executes" and that they'll stop "a process executed" from being a game over situation for users.
- klabb3 5y agoI think you're right about paths but aside from that we have website urls, usernames or similar identifiers.. People look at those and assume that they can compare them. If I see `google.com` I assume it consists of certain characters that represent a specific institution. Are we doomed to live with ascii for the forseeable future or is there some form of reduced set of unicode that we can use without these types of impersonation attacks?
- BoorishBears 5y agoyou shouldn't get away with an IDN Homograph attack in any modern browser They just turn your url into punycode, and more recently display that instead of the raw url: https://en.m.wikipedia.org/wiki/Punycode https://en.m.wikipedia.org/wiki/Punycode
- account42 5y ago> and more recently display that instead of the raw url Technically, punicode is the raw URL and old enough browsers will display all non-ASCII domains as punycode. It was only for a short while that browsers naively decoded punicode without restrictions.
- staticassertion 5y agoThat's basically why Google wants to get rid of urls. They're terrible at conveying trust.
- toomanydoubts 5y ago>That's basically why Google wants to get rid of urls. Wink-wink ;)
- rightbyte 5y agoGoogle want you to search on Google to see ads and be spied upon, not use a direct url.
- cryptonector 5y agoThere are certainly things that can be done. UTR #36 covers some of the things that can be done. Besides refusing to render U+202E when it is between characters of scripts that aren't bi-directional and flow in the same direction, the UI could display the string in ways that make it clear (e.g., different color, maybe add a warning tooltip, maybe add a dialog around an operation that could be dangerous, or maybe refuse to perform dangerous operations).
- account42 5y agoAnother option for filenames would be to recognize that the basename and extensions are distinct parts and the extension should always be displayed after the basename no matter what is in the basename. Of course, this adds lots of complexity so ¯\_(ツ)_/¯
- cryptonector 5y agoProblem is that there's cases like foo.tar.gz. What's the extension there?
- deleted 5y ago[deleted]