3 ms·
The attacker doesn’t need to spoof anything, this is known as a homograph attack: https://en.m.wikipedia.org/wiki/IDN_homograph_attack https://en.m.wikipedia.o
by arx_ 1y ago
The attacker doesn’t need to spoof anything, this is known as a homograph attack:
https://en.m.wikipedia.org/wiki/IDN_homograph_attack https://en.m.wikipedia.org/wiki/IDN_homograph_attack
https://www.xudongz.com/blog/2017/idn-phishing/ https://www.xudongz.com/blog/2017/idn-phishing/
- eviks 1y agoIf it's a known attack, Google has a known defence in its apps?
- arx_ 1y agoSomething being known doesn’t mean a solution exist. Computing the the set of Unicode characters that would result in a homograph of a latin alphabet word is non trivial. Now do this for relevant/trusted domains, now put in place a mechanism to mark a domain as trustworthy that also minimises your liability.
- eviks 1y ago> Something being known doesn’t mean a solution exist. But we aren't talking theory. In this case solutions exist, just not in this app? Also, the triviality point is puzzling, are we only allowed to criticize professionals for trivial fails? (though using a different font is one of the trivial mitigations) > that also minimises your liability. How is that a factor, what is their liability now without any mechanism and will it increase if they add some?
- palmfacehn 1y agoSeems like a good use for the .google tld
- otterley 1y agoWe don’t know yet that that’s what actually happened in this case.
- arx_ 1y agoIt seems likelier than a @google.com spoof landing in the person’s inbox. Without them providing the headers this is just idle guessing, but I’d argue my guess is likelier to be the truth.