38
Weaponised Fonts (gardinerbryant.com)
submitted 2 months ago by cm0002@infosec.pub to c/privacy@programming.dev

Arguably more security than privacy, but this made me think. I havent considered the use of ambiguous fonts in phishing before. Worth reading.

top 4 comments
sorted by: hot top new old
[-] AllNewTypeFace@leminal.space 8 points 2 months ago

They could add a lowercase to FE-Schrift (i.e. the German licence plate typeface, which was designed to make it very difficult to make any glyph look like anything but itself) and use that for the URL field.

[-] AnAmericanPotato@programming.dev 4 points 2 months ago

Atkinson Hyperlegible would be a good starting point but I don't know how you could extend it to all of Unicode.

[-] IanTwenty@piefed.social 4 points 2 months ago

In addition, if you attempt to visit a site that is a homograph of one already in your browser history the browser should show a warning, highlight the similarity and force you to confirm you want to proceed.

[-] LodeMike@lemmy.today 2 points 2 months ago

Makes sense that they can't figure out how to instruct people to change their browser's DNS settings

this post was submitted on 30 Jun 2026
38 points (97.5% liked)

Privacy

5082 readers
188 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS