Showing posts with label typosquatting. Show all posts
Showing posts with label typosquatting. Show all posts

2024-11-01

No style

 

Image from Pixabay

If you put a sticker that says SECURE on something, does that make it secure? It depends. If that sticker is stuck on after the security has been checked, and if it’s clear that the sticker is only granted after the check, then you can indeed assume that the stickered thing is secure - at least, if the sticker shows that it is authentic. In all other cases, that sticker makes no sense at all, of course. In fact, it promotes a false sense of security.

Recently I spoke to a colleague who manages a great web application. When creating that program, they forgot one thing: the house style or, if you wish, the corporate identity. And the people who watch over the house style didn't think that was a good idea. Because, they argued, users would think that it was a fake website, where scary things could happen. Put our corporate logo on it, they said, that will prove that the site is secure.

Nonsense. If cybercriminals have become good at anything in recent years, it is the faithful reconstruction of websites. They look at what the real website looks like and copy the entire house style: logos, photos, font, writing style, and yes, even the beware-of-cybercriminals notice, which is on many sites these days. So you can't tell security from the appearance.

But, the administrator said, users of my application can see in the browser’s URL bar that the displayed web page is in our domain. But that doesn't work either. Because for the average user that is simply a bridge too far. Or have you never seen someone type 'wikipedia.org' in the search bar of Google and then go to that website via the search results? Instead of typing 'wikipedia.org' (the URL) immediately in the URL bar (at the very top of the browser), so that you immediately end up in the right place? Many users have a blind spot for the URL (or address) bar, let alone that they go and see what is there and that they could also determine whether they have ended up on a bona fide site.

Aside: the method outlined here introduces an additional problem. Cybercriminals are very successful in having their fake sites appear high in the search results. This means that you may end up on a fake site via your search engine. Tip: if you know the URL, type it into the URL bar, not into Google (or another search engine). If you visit a site often, bookmark it so that you don't have to type. Bookmarks also prevent you from ending up on a fake site due to a typo ('wikipidia.org'). Criminals like to build websites with URLs that are very similar to those of the real websites. And then they hope that you make a typo and end up on their site. This is called typosquatting.

Despite all this, I have pleaded with the administrator to apply the house style. Am I then in favor of a false sense of security? Not at all. But I want to prevent a flood of unjustified reports from users who think they are on a fake site – the colleagues at the IT service desk are busy enough as it is, so if I can spare them a number of false positives , I am happy to do so. In addition, we train users to recognize dangers. I call them red flags. The more red flags, the more likely that something is wrong. For example, for phishing, I can easily list a number of red flags: an impersonal salutation ("Dear customer"), a different sender address (amazon.ru instead of amazon.com) or a link to a different domain (amazon.com.customer.com). Tip: you should read URLs from right to left; so only if amazon.com is on the far right, you are visiting the domain of that webshop. By the way, something may be added behind that, starting with a '/': amazon.com/customerservice takes you to a page in the domain amazon.com. But amazon.com.customer.com is not an amazon.com page.

Of course I went to look at the page of that internal web application. And what do I see? In a corner, our corporate identity logo is displayed! They have made concessions, hoping that everyone is happy now. And they are going one step further: the application will be connected to single sign-on, so visitors no longer have to log in manually. A smart move, because if you think that you might be on a fake site and it asks for your credentials, it increases the feeling of insecurity.

 

And in the big bad world…

 

2023-06-23

Alphabets

Image from Unsplash

It is a somewhat strange sensation when suddenly everyone is talking about something and you have no idea where it came from. My teammates came to the rescue: it was on Facebook, which is just a corner of the internet I never visit. You may have seen it, though: that message that warns about links that are not what they seem because they contain letters from a different alphabet. It was adopted by the popular newspaper USA Today and then things went fast.

Homoglyphs is the term for characters that look like letters. The best-known examples of homoglyphs in our own world are the 0 and the O: the first is a number, the second a letter. Always hard to tell the difference. And what about the l and the I? The first is the lowercase L, the second the uppercase i. Since we usually use sans-serifs in modern texts, you won't see the difference. If you choose a font with serifs, you will see this: “And what about the l and the I?” ( Courier New font).

The Cyrillic alphabet, used in Russia and its surroundings, also contains homoglyphs. In the example shown on Facebook, our a and its Cyrillic counterpart are mentioned. Incidentally, the letter, which is called the Cyrillic a in that message, is the Greek letter alpha (ɑ). Because the Cyrillic a looks like this: а.

All letters, numbers and other characters that you can type on your keyboard are defined in tables. The best-known table is ASCII, IBM mainframes speak EBCDIC and the most extensive is Unicode, because it defines the letters of all alphabets – not just the Latin alphabet we are familiar with. The Cyrillic letter at the end of the previous paragraph was created by typing the Unicode for that letter (0430) and then pressing Alt and X. With the help of the Unicode tables you can therefore make all characters, even if they do not appear on your keyboard. Like for example Њ and ß.

In the address bar of your browser you will not see the difference between amazon.nl and аmаzon.nI (the latter contains the Cyrillic a and a capital i). While you might think that this URL will take you to the Dutch website (.NL) of that company, it will take you to a website hosted in Nicaragua, as the top level domain (TLD) .ni belongs to that country. You see how easily criminals can lure you to their fake website, where they then steal your data or install malicious software on your device. Dutch domains, which fall under the TLD .NL, are relatively safe because no domains can be registered with characters from other than our own alphabet. But beware: the trick with the i and the L does work here.

Your browser can protect you from a homoglyph attack simply by not supporting them or by rejecting a mix of different alphabets. In addition, many domain registrars also ensure that no domains are registered that are no good. So you could say that all the attention to homoglyphs is a bit exaggerated – after all, effective measures have been taken.

In this context, I would also like to mention another form of trickery and deceit called typosquatting . In this trick, someone registers a domain name that looks like a real one, and then hopes people will make typos or get the name wrong and end up on their site. Think for example of googel.com, amazone.com or microsof.com. The holders of the official websites of these organizations can protect themselves against this by registering all domains that are similar to their own. If a smart guy manages to score a similar domain, the holder of the real domain can demand that the fake domain be cancelled.

My guess is that homoglyphs won't get you in trouble anytime soon. The chance that you type in a wrong web address that happened to be thought of by a typosquatter is somewhat higher. But I think the most remarkable thing about these techniques is that they exist at all. This shows once again that criminals can be particularly inventive and possess a great deal of knowledge.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

Passport Leak

Image: Unsplash The data behind every passport and ID card has been leaked. No one accepts them as valid ID anymore without question. “You...