(no title)
chii | 3 days ago
that is very interesting.
I imagine the browser could take some context clues and switch rendering to puny code if the locale of the user is nowhere near a cyrillic region. But that is only going to patch some edge cases and miss others.
Ideally, the solution is password managers everywhere, which don't have this vulnerability, instead of using human eyes to visually recognize web urls and thus is vulnerable.
bojan|2 days ago
Anyone reading this - please, please, please do not make any assumptions based on the end-user's geography.
Signed, someone who can cross 3 national and 4 language borders within a few hours of driving.
jdranczewski|2 days ago
I think the lack of exploration of the context around the problem and current mitigations is an issue with the article - it spends a lot of time talking about the possible threat, but very little time on whether the attack is actually practical with modern mitigations.
olsondv|2 days ago
alterom|2 days ago
Here you go:
https:// аррlе.соm
(using English "l" and "m" here, Russian м looks differently)
drran|2 days ago
[deleted]