Google Is Battling a Russian Spammer Over the Use of the Letter 'G'
motherboard.vice.com
motherboard.vice.com
Google is now noticing that those malicious domains don't even have to be an exact visual match but a similar looking one is sufficient to trick users.
This is going to be fun to watch. Unicode domain names are a can of worms.
"Unicode is too complex to ever be secure" - Bruce Schneier
So instead of @realdonaldtrump you could create @reaIdonaIdtrump and to the untrained eye, you'd think it was the same thing.
http://money.get.away.get.a.good.job.with.more.pay.and.you.are.okay.money.it.is.a.gas.grab.that.cash.with.both.hands.and.make.a.stash.new.car.caviar.four.star.daydream.think.i.ll.buy.me.a.football.team.money.get.back.i.am.alright.jack.ilovevitaly.com/The buttons on the background are particularly strange.
> No any corporation is not associated with this project. All product names and brands are property of their respective owners. All service names used in this website are for identification of services to open only. Why the richest and the most technologically advanced multinational corporation in the world shows 'Secret.ɢoogle.com You are invited! Enter only with this ticket URL. Copy it. Vote for Trump!' in tens of millions accounts since 5 November ask not me. I don't working in their support so it's not a my problem. This site domain is ilovevitaly.com. Despite the huge number of lies without any proofs in the media, this search shell is absolutely safe and very useful. Just one very rich and influential hidden evil corporation doesn't like competitors very much.
"Ask not me", sure...
Ah, it's the guy that keeps spamming Google Analytics. I'm glad Google is finally doing something about this, although they be working on a technical solution alongside a legal one.
Before:
> “I was fully prepared from April, but I wait. I could begin in a month before the elections and on a wave of the anti-Russian hysteria to receive a lot of traffic,” he said.
Later:
> “Lie! Not my domain!” Popov writes in bright red text regarding the site with dodgy pop-ups.
> “Lie! I'm not a spammer!” he continues.
Either someone is running an extensive anti-Popov campaign or Popov is realising that the campaign has been a huge mistake.
http://webcache.googleusercontent.com/search?q=cache:KZq3KBV...
And don't forget that there's an endless amount of misspellings and word variations (googleapps.com, ...).
They have thousands of these domain variations. googleusercontent.com? picasa? googleplus? gmail? googlemail? ...
So that's probably a few 10,000's overall and then you need to register them for every top level domain that Google operates in so, com., de., co.uk. etc...
Overall there are probably a like 100,000's domains that can be registered, under Google.tld_x alone, more if you count in all the other services they have.
It will cost a small fortune for an individual even in bulk registration prices but still it's more than affordable for a company the size of Google.
That said using cyrillic is even better http://www.miсrosoft.com doesn't looks any different than http://www.microsoft.com but it translates to http://www.xn--mirosoft-gch.com/
Then you could have something like *elgoog display as google
Maybe it should be restricted to certain TLD's though; e.g. only allow the unicode characters in TLD's that have a good reason for using them. That way, it won't be an issue for .com/.net/etc.
For example, thèta.com might be a French fighter jet company, while théta.com could be very easily confused as the same thing, especially to non-French speakers. So I think registering that weird version of google.com should never have been possible, since the Gs could obviously be confused by a layman.
Also, in general I think web browsers need to be more machine learning backed. The browser should warn you when you're about to do something dumb or when you're reading lie-based propaganda. We're trying to teach laymen to be intelligent enough to check for HTTPS and to be discerning enough to figure out what news is false, but I don't think a majority of our population is able to do so.
I don't understand the love for voluntary infantilism. Why is it such an impossibility to have to learn a system before using it? I don't think anybody here would argue that using a keyboard is too difficult. But couldn't we just back it with machine learning and let that algorithm figure out what we want to type when we just hit random keys?
At some point informed people just throw up their hands and start making it harder for people to hurt themselves or others.
Because people seek leisure and ease and going against that means the competitor who recognizes this is going to beat you. Also on a more pedantic front, did you write your own operating system or create your own cpu? What does "learning the system" mean here? Its arbitrary. Even a hard code dev today would seem like a child to the guys in the 60s who had to do literally everything by hand.
>I don't think anybody here would argue that using a keyboard is too difficult.
Ever watch someone learn a keyboard for the first time? Its painful. The common layouts are questionable and lots of keys are extraneous. I dont need a sysrq or break key, thanks. Look at mobile. When I use a mobile device I either use voice or a swipe keyboard. When I'm at home I use my Google Home and Amazon Fire via voice instead of a hunt and peck virtual keyboard. Keyboards are actually fairly terrible, but right now for a lot of tasks are the least of the worst.
Enforcing all of one subset makes more sense to me, though even that's not foolproof because the above example uses both B and ß in the same language. But at least it'll reduce the attack surface, I guess.
A Domain Name Name Service - DNNS!
I don't think I've ever accessed one, and if I ever do it will probably be accidental - something illegitimate like this.
If I regularly used a site that legitimately used such a character, I imagine I'd be more in tune to it and less likely to fool for it.
* ɢᴏᴏɢʟᴇ uses all Latin Small Caps
* ᏀᎤᎤᏀᏞᎬ uses the Cherokee block
* ԌООԌӏЕ uses Cyrillic block
Not perfect, but would you notice them in the small type of your typical address bar?
Requiring that all characters come from the same block certainly doesn't solve the problem but it would help make it a little more obvious - your examples above are much easier for me to spot as suspicious vs the ɢoogle.com in the article.
I hadn't thought about latin small caps before, that's an interesting one - although perhaps that block could be blacklisted entirely.
Overall it's a bit of a mess, isn't it!
https://bugzilla.mozilla.org/show_bug.cgi?id=279099
-- EDIT:
It doesn't 'disable' as such, but renders the 'punycode' in full, so a fake 'http://www.miсrоsоft.com' is rendered as instead 'http://www.xn--mirsft-yqfbx.com'.
For comparison, here's fake on top of real (not in monospace since it destroys the illusion):
[0] http://kb.mozillazine.org/Network.standard-url.encode-utf8
EDIT: doesn't work either. And the same for network.standard-url.escape-utf8. :(