| ▲ | kccqzy 8 hours ago | |||||||
Well then it’s a failure of UI design if you think this can cause confusion. In any UGC design it should be extremely clear which text is generated by another user and which belongs to the site itself. | ||||||||
| ▲ | netsharc 5 hours ago | parent | next [-] | |||||||
What if a user with the name kссqzу (k[Cyrillic c][Cyrillic c]qz[Cyrillic y]) pretends to be you, sends your friend a PM and extracts a secret out of them? | ||||||||
| ||||||||
| ▲ | zahlman 7 hours ago | parent | prev [-] | |||||||
No, no. The problem is, say you operate a forum; a malicious user makes a post that uses a Unicode confusion attack on a URL to direct other forum members to an attack site (e.g. a phishing site). | ||||||||