logoalt Hacker News

apothegmlast Wednesday at 1:23 PM3 repliesview on HN

Maybe not at super large font sizes. But even lowercase i and l are easy enough to confuse at a glance mid-word in most sans-serif fonts, not to mention uppercase I and lowercase l. You don’t even need “confusable” glyphs to create a domain name that will stand up to a casual visual confirmation from a busy user in a phishing context.


Replies

hinkleylast Wednesday at 7:22 PM

Every Albert, Alfred, or Alphonso who goes by “Al” getting confused with bots right now…

show 3 replies
LorenPechtelyesterday at 8:25 PM

I recently spent way too much time on a bug that only showed up in a large data set. (Turned out a walker had a problem with certain leaf patterns.) Put a trap on a string that looked unique--even after I had actually found the problem and fixed it it still couldn't find the offending text. Sans serif, l vs I.

dec0dedab0deyesterday at 3:00 PM

we used to mess with our friends by making AIM screen names that looked identical, or super close to then. then messaging other friends in the group. Or going into chat and saying things like "im a big dumb idiot"

This was like 1998-2003, and non technical people were doing it too. I think I am the only one from that friend group who would even consider that as something to watch out for.