26 ms·
What is the standard solution to this type of phish? This problem did not exist in the ASCII world, of course. Unicode is useful, but what is the best way to
by TheDudeMan 2y ago
What is the standard solution to this type of phish? This problem did not exist in the ASCII world, of course. Unicode is useful, but what is the best way to prevent this malicious use of it?
- omneity 2y agoThis problem extends beyond character encoding. The average joe (and not so average alike) seems to have a hard time to distinguish official channels from non-official scammy ones, even more so when the official channel doesn't exist on a given platform ("we don't offer support via Telegram" kind of situations). Cue in some greed as well and you got a perfect recipe for disaster. The root issue is the lack of skepticism and verification. At the same time humans have limited energy and verifying everything causes significant fatigue over time, so the problem might as well be intractable.
- pessimizer 2y agoIt's not about average Joes, it's about large numbers. If the scam works on 1/100 people in the US, that's 4 million people. If you're automating pitching it to 500 people a day, that's 5 wins a day. If your average haul is $500, that's $2500 a day. That's $900K a year.
- raincole 2y agoI do think it's good for certain things to be ASCII-only. People will say it's Americentrism or Anglo-Saxon-centrism. Ok so be it. Make the account handles and email addresses not inclusive and ASCII-only.
- michaelt 2y agoFor web URLs, browsers will sometimes display "punycode" where for example "домен" would be represented as "xn--d1abbgf6aiiy" I believe different browsers have different heuristics about when to switch to that representation - suspicious characters, mixing scripts in the same URL, and so on.
- TacticalCoder 2y ago> What is the standard solution to this type of phish? For domain names I use a "corporate" setting in Firefox, disallowing the use of DoH/DoT: to make sure that every single domain name resolution goes through my own local DNS resolver. And my firewall inspects every packet on port 53 and rejects any packet containing "xn--" (the way they encode Unicode chars in ascii URLs). For text: my editor is configured to display in bold, fluo, on a dark background any character that is no a visible ASCII char (except newlines and spaces) and "zero width" char are forced to have a width. But it's a losing battle: too many people don't understand the security implication of using Unicode everywhere. The most enraging in all this is how stupid these homoglyph/homograph attacks are to pull off: any dumbfuck can pull it off. The bar is insanely low.