• @[email protected]
    link
    fedilink
    English
    192 years ago

    Another reason to stick to your distro repositories. This should totally be disabled by default for modern browsers.

  • ares35
    link
    fedilink
    472 years ago

    disable unicode representation of these types of domains in firefox by flipping this setting (in about:config) from the default ‘false’ to TRUE:

    network.IDN_show_punycode

    so you see аррӏе.com instead of аррӏе.com

    compare to (the real deal): apple.com

    • @[email protected]
      link
      fedilink
      English
      52 years ago

      Does anyone using Mullvad Browser know why this setting is not enabled by default? I just checked. If it is important for security it should be.

    • @[email protected]
      link
      fedilink
      English
      29
      edit-2
      2 years ago

      Looks like it’s already flipped to true in Librewolf, glad they seem to have some common sense compared to mozilla.

      Is there any good reason for a browser to mask the real URLs like that? There seems to be a trend of hiding parts of the URL people see lately.

        • @[email protected]
          link
          fedilink
          English
          13
          edit-2
          2 years ago

          This is the big thing that should be happening, even just a little icon in the bar when it’s happening to switch between the two representations.

      • Turun
        link
        fedilink
        English
        302 years ago

        Yes, because the internet is not restricted to English letters.

        Just imagine you had to visit アップル instead of apple.com! And most importantly, would you trust yourself to see the difference that and say プッアル consistently without seeing the real reference?

        Just to be clear, I hate it when the browsers hides part of the url too. Show me the https god damn! But internationalization is a good thing, as it makes the internet accessible to more people.

        • @[email protected]
          link
          fedilink
          English
          152 years ago

          Stop it! The only words that matter are those that can be written in ASCII! The rest of the world just wants to scare you with gibberish letters!

  • AutoTL;DRB
    link
    fedilink
    English
    82 years ago

    This is the best summary I could come up with:


    Google has been caught hosting a malicious ad so convincing that there’s a decent chance it has managed to trick some of the more security-savvy users who encountered it.

    Combining the ad on Google with a website with an almost identical URL creates a near perfect storm of deception.

    “Users are first deceived via the Google ad that looks entirely legitimate and then again via a lookalike domain,” Jérôme Segura, head of threat intelligence at security provider Malwarebytes, wrote in a post Wednesday that revealed the scam.

    The ads were paid for by an outfit called Digital Eagle, which the transparency page says is an advertiser whose identity has been verified by Google.

    When in doubt, people can open a new browser tab and manually type the URL, but that’s not always feasible when they’re long.

    Another option is to inspect the TLS certificate to make sure it belongs to the site displayed in the address bar.


    The original article contains 422 words, the summary contains 157 words. Saved 63%. I’m a bot and I’m open source!

  • Wistful
    link
    fedilink
    English
    22 years ago

    That’s kinda crazy, as it would look like a speck on the screen. I wish I could see the actual site, and see if there is something else sus about it. When I download important things like password managers, I usually try to be extra careful, double check the URL and do the hash check.

    • Izzy
      link
      fedilink
      English
      72 years ago

      Ads are cancer. Google by being a company that makes most of its money from ads is cancer by extension.

    • bluGill
      link
      fedilink
      112 years ago

      They have failed one of their code jobs: validating advertisements are legitimate. I don’t know why any legitimate company would advertise with google as you get associated with the scams they allow on their ad platform.