Hacker News new | past | comments | ask | show | jobs | submit login

Is it actually Google or is there some unicode trickery going on?



From what I can tell, it's actually Google, but then they redirect you to a malicious URL after auth/approval


Seems like it's allowed in the oauth form: https://pbs.twimg.com/media/C-7NlIzXUAErblp.jpg:large


Doesn't look like a unicode trick on the app-strings I'm getting


Is there a database of homoglyphs for common fonts that one could use to write a visual string matching algorithm?





Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: