4 ms·
> What is the standard solution to this type of phish? For domain names I use a "corporate" setting in Firefox, disallowing the use of DoH/DoT: to make sure th
by TacticalCoder 2y ago
> What is the standard solution to this type of phish?
For domain names I use a "corporate" setting in Firefox, disallowing the use of DoH/DoT: to make sure that every single domain name resolution goes through my own local DNS resolver.
And my firewall inspects every packet on port 53 and rejects any packet containing "xn--" (the way they encode Unicode chars in ascii URLs).
For text: my editor is configured to display in bold, fluo, on a dark background any character that is no a visible ASCII char (except newlines and spaces) and "zero width" char are forced to have a width.
But it's a losing battle: too many people don't understand the security implication of using Unicode everywhere.
The most enraging in all this is how stupid these homoglyph/homograph attacks are to pull off: any dumbfuck can pull it off. The bar is insanely low.