Humans Are Bad at URLs and Fonts Don’t Matter
troyhunt.com
troyhunt.com
[1] https://www.troyhunt.com/im-partnering-with-nord-as-a-strate...
[2] https://www.troyhunt.com/have-i-been-pwned-is-now-partnering...
I wish I could downvote this submission. I wonder whether I should flag it.
https://www.troyhunt.com/ive-joined-the-1password-board-of-a...
If he wants to use his rep to write fluff pieces for his corporate sponsor, so be it. But he discredits himself for doing so.
You're avoiding a service because it sponsors content you enjoy?
Well, your browser also has a history of all the sites you've been to in the past, and people tend not to go to a lot of random sites. It would be pretty simple to display something when you go to a site you've never been to before. Just an unobtrusive, but not too unobtrusive, "this is your first visit to this site.". So when you see that on googie.com you might double check where you are. If the site url is similar to one you've been to in the past it could even say "Did you mean to go to one of these sites with similar looking names?...."
I'm not sure what the deal is with shilling for a vpn, or how that helps. It doesn't.
Whoa, that seems like a shockingly good idea! It could look similar to what happens when you enter data into a password field on a non-https website. The browser can pop up a little box under the input when you start typing, which says something like "this is your first time visiting this website. Only enter passwords on websites you trust."
Are there any major downsides I'm missing? Signing up for accounts on new sites would certainly create false-positives, but if the warning is properly coded that doesn't seem like such a problem.
It _would_ work for first time visits, but I propose that it will be too common that people will ignore it or brainlessly click through it, providing little to no security benefit.
Phishing is an artifact of the bad design of the system of remembering a password, and will likely continue until we design and widely deploy a better alternative.
I might keep your first addition but nix the final paragraph, as good a suggestion as it may be.
Similarly, the answer on the net is not to stop bad actors from being bad. It's to punish and hold accountable those that do bad things. That avoids the "thoughtcrime" problem, and makes space for actual freedom.
The only thing we have to lose is privacy for domain owners. Seems like a trade-off worth considering.
What prevents the violent psychopath from killing the child they see to get their lollipop when they want something sweet? The fact that there are repercussions. What prevents those that have no qualms about stealing from a store from doing so most of the time (even those that steal don't do it every time they enter a store)? The same.
An alternative strategy would be to crack down on the money laundering channels used by criminal entities to get money from their victims, but this would be politically difficult as it would involve shutting down grey-market banks that are well used by the ultra wealthy to evade taxes and pay bribes.
https://www.zdnet.com/article/north-korea-s-apt38-hacking-gr...
https://www.cnn.com/2019/03/01/politics/north-korea-cyberatt...
Connections between specific Russian financial crime organizations and the Russian government are much harder to pin down as people who try to investigate ties between the Russian mob and the Russian government often wind up dead. However, the Russian government is well known to be tightly linked connected to Russian organized crime[0]. Given the sheer scale of Russian financial fraud operations--Carbanak stole upwards of a billion USD[1]--the balance of probabilities suggest these operations exist with the tacit approval of the Russian government.
[0] https://bpr.berkeley.edu/2019/12/16/gangs-and-gulags-how-vla...
[1] https://securityintelligence.com/carbanak-how-would-you-have...
This is a huge downside. Anonymous publishing is a very important right.
If you create a git repo, the first branch’s name is a controversial political issue.
“Everything’s political” ~ What’s-his-face the communist in Fiddler on the Roof after introducing “Will you marry me?” as “a political question.”
> This is a huge downside. Anonymous publishing is a very important right.
It also wouldn't work. Or rather, at best it would only work as well as political campaign message attribution does (and that's with considerable enforcement muscle aimed at it).
Somehow "dark money" often manages to evade these efforts, and evade the consequences of violations, and I wouldn't expect transnational phishing and scams to be any different.
Which isn't to say that we should stop trying, but sacrificing the capability of the general public for anonymous speech in return for dubious-at-best attribution by well-heeled actors seems like a poor tradeoff.
Obviously it's best if there was a simple automated solution that worked in all cases, but there is no such thing. Password managers are great, but they don't counter disinformation from sites you don't have a password with. Preventing access to malicious sites only works if it's known to be malicious; new sites will always slip through (and attackers can keep creating new sites), false positives are a problem, and not everyone can afford them. Reputation systems can be gamed.
In many cases you try to make it so that an attacker has to pass multiple barriers, instead of pinning your hopes on a single perfect solution. Usually there isn't one.
So yes, DO display the URL; use fonts, lowercased domains, colorize each character by Unicode region, or whatever you have to do to help users detect when there could be a problem. Then let users check. Some URLs will slip through, but I'll note that a LOT of people picked up the "googIe.com" in the survey - it wasn't randomly distributed.
DO use a password manager. That will dramatically help if you've previously logged into that site.
I'm less excited about filtering domains, especially because some implementations are privacy disasters. But if done in a privacy-respecting way, I can see some value. But only SOME value - they are NOT a panacea. And many will not use them.
The goal isn't to find the one true answer; the goal is to make it unlikely for an exploit attempt to work. If you CAN come up with a perfect automated defense that's affordable, great, do that. In most circumstances you need multiple defensive mechanisms so that the attacker has to overcome multiple very different barriers.
I still think this could help people realize when they are being phished at least for their most important sites in a privacy-respecting way, even if they don't use a password manager for those sites. I don't use my password manager for my banking account, for instance, since I don't want those credentials to be synced anywhere.
But maybe the identicons don't need to be meaningful or the same for everyone. You could hash the domain with another value, like a computer name or username, then show some interesting pattern. Then it would have a different pattern. Not perfect, but yet another user cue.
user_pref("network.IDN_show_punycode", true);
in your user.js. Then all URLs will appear in their punycode form, eg apple.com with the cyrillic glyphs will show as: https://www.xn--80ak6aa92e.com/
Is this good enough? Probably not in general.- It relies on you to notice the URL bar after you've clicked a link. Worse, it relies on you to notice the URL bar after you've clicked a link and after the website has begun loading long enough so that firefox changes the URL to the target.
- If you're someone who does actually visit websites with punycoded domains regularly, then this conversely makes it harder for you to know you're on the right domain.
- Even if you notice the URL is wrong, you've already started loading the page. Best case your IP is now known to that server. Worst case it had a malicious payload for your browser / OS / hardware and your content blocker wasn't configured / able to block it.
It's good enough for me, at any rate.
We have consolidation and the exclusion of bit players and new entrants in real life already, and I don't like it. Now we're talking about solving these problems on the internet in a way that seems like it will lead to the same place.
I definitely don't want Google to solve this problem for me. Then again, I don't use their search engine nor primarily their browser, so then we end up with "solutions" that are very unevenly distributed.
The root issue is that the internet is a very hostile environment, and trying to make it safe seems like a losing cause, a denial of reality.
Unfortunately this doesn't solve the problem in general, because most people don't use password managers.
Why is 1Password better than your browser’s own, free, preconfigured manager?
As for why it's better than the browser's password manager... for an individual, it probably isn't. For me, I will say that I like that 1Password allows my partner and me to share passwords to joint accounts, which iCloud Keychain can't do without getting out of sync when a password changes. (iCloud Keychain also only works on Apple devices, of course.)
Precisely because they are expensive and difficult to get automatically, they can be a an extra protection against phishing.
I fear that because of these kind of URL issues, and with the deemphasis of EV certificates which would have provided a somewhat decentralized solution, we will end up in a world where the author of the browser becomes the ultimate authority on what is a trustworthy URL. That means for most of the users, Google will be the arbiter of what is and is not a trust worthy URL.
The thing is, just charging extra money would probably work for the most part, even if it isn't all that fair. Also, how do I set myself up as the authority you need to pay $$$$$ to for a certificate? That seems like a pretty sweet market to be in. ;)
And the requirement for an EV certificate is that it has to be registered specifically in the corporate name, which isn't necessarily the well-known trade name. Furthermore, anyone could choose to register their company as, say, "Microsoft" if it's not in the same jurisdiction as the actual Microsoft, and you get this lovely verified checkmark saying that the phishing site is, indeed, Microsoft. (Just not the Microsoft they were expecting).
A system that presented the end user with a business card of relevant information regarding a given website could be very effective if done properly. Presenting a list of industries and trademarks that the site does business under in the user's current jurisdiction would be a good start.
If you 'verifying' without knowing the legal identity, what on earth have you verified? Perhaps we could include trademarks somehow, but at the end of the day having weired names is down to the firm.
The example with google blogs was particularly apt - all URLs are legit, but only one belongs to Google. I want to know which one.
1. Users do not understand the difference between an EV and a DV cert. We spent a decade training users that the padlock is all you need.
2. Company registration norms are not standardised across the world, and you can easily get a certificate for Microsoft Corp, see https://news.ycombinator.com/item?id=15904513 for eg.
When https green shields and locks appeared at first I thought it's something like that, only to be disappointed.
The problem is your browser or DNS cache would basically have to have a copy of the root zones OR contact a special name resolver that would return...what? in the case of a collision.
com.google.accounts/612361/signin/v2/identifier?hl=en&... com.tinyurl.amp.com.google.accounts/612361/signin/v2/identifier?hl=en&...
(And these days, since google have the .google TLD, they don't even need that "com.")
The issue with this is that it requires a crawler that determines this. In a way, the existing safe browsing mechanisms already offer the infrastructure.
These would be all the sites on which you think you need extra amount of trust. Say all sites where you do financial transactions, and ones like gmail which are used for identity verification.
The article is full of tweets by people, including Hunt himself, that use visual security indicators
Note: biased. Worked on a web verification startup for 4 years. Including campaigning for better indicators.
So, he writes an article about a service related to these companies which helps to solve a real issue.
So, why all the hate?
Case sensitive identifiers should have been never allowed.
The only solution to this is to tell users to look at the URL bar and make that work well. If they don’t, you can’t do much.
Something key he alluded to but didn't get into is that browsers should remember (a hash of) your history and warn you when you visit a site (like googleblog.com) that you never visited before and isn't known to be owned by the owner of a site you have visited before.
I think a similar warning could be fine for passwords and auto-fill information: "This is the first time you're sending a password to googie.com, which is registered to the Googie Real Estate Corporation. Is that what you mean to do?"