logoalt Hacker News

albert_eyesterday at 1:20 PM1 replyview on HN

> 82 pairs are pixel-identical

> a string like “аpple.com” with Cyrillic а (U+0430) is pixel-identical to “apple.com” in 40+ fonts. The user, the browser’s address bar, and any visual review process all see the same pixels. This is not theoretical. It is a measured property of the font files shipping on every Mac.

Current implementations of "Computer Use" Agentic AI tools mostly use visuals -- screenshotting of a computer screen and interpreting it.

These pixel-dentical character pairs will be a straight failure mode for those automations and could possibly be a threat vector if crafted well.


Replies

pitchedyesterday at 1:22 PM

I don’t think a human could tell the difference either. This will make phishing emails much more effective.