3 ms·
> For comparing the symbols visually, you don't even need to know their names. Well, no, this was the main issue with homograph attacks in domain names [1] tha
by riquito 3y ago
> For comparing the symbols visually, you don't even need to know their names.
Well, no, this was the main issue with homograph attacks in domain names [1] that brought us to the use of punycode in browsers [2]
In particular for a cryptographic library, I wouldn't want to constantly have to watch out for sneaky malicious variables put in the right place (e.g. try to compare visually the Cyrillic а, с, е, о, р, х, у with the ascii a, c, e, o, p, x, y (no, they're not the same characters).
EDIT: I realize that many programming languages today allow the use of unicode variables and I like that it's a possibility, it's just not the best when you need to be paranoid about the code
- [1] https://en.wikipedia.org/wiki/IDN_homograph_attack https://en.wikipedia.org/wiki/IDN_homograph_attack
- [2] https://en.wikipedia.org/wiki/Punycode https://en.wikipedia.org/wiki/Punycode
- Retr0id 3y agoPreventing/detecting homoglyph attacks is a feature of competent text editors, and not a feature of the source code itself. If the source spelt out the variable names using latin characters, it would be no more or less susceptible to being backdoored in this way.
- GolDDranks 3y agoAlso, for example, rustc does a homoglyph detection pass and emits warnings.