I didn’t know my city was cool enough to put signal flyers.

  • hash@lemmy.world
    link
    fedilink
    arrow-up
    34
    arrow-down
    4
    ·
    1 month ago

    Respectfully I think this is a minimal attack vector in this case due to the limited character set of urls. But thanks for the callout, I didn’t know there was a name for this sort of attack.

    • Lichtblitz@discuss.tchncs.de
      link
      fedilink
      arrow-up
      22
      ·
      edit-2
      1 month ago

      Modern browsers happily show you the actual characters, while sending their encoded entities to the server. So, from a user perspective there is no ASCII limitation. Case in point: söhne.at (just some random website, I have no idea what they are or if they are legitimate)

      • gila@lemm.ee
        link
        fedilink
        English
        arrow-up
        6
        ·
        1 month ago

        They’d still resolve via DNS to an address in ASCII though, right? Wouldn’t that only be an issue if ICANN didn’t have a monopoly on DNS registration? i.e what we already depend on for a semblance of convenience without totally compromising opsec