Google-hosted malvertising leads to fake Keepass site that looks genuine

sylverstream@lemmy.nz to Technology@beehaw.org – 220 points –
Google-hosted malvertising leads to fake Keepass site that looks genuine
arstechnica.com
26

You are viewing a single comment

This should be ON by default, in my opinion. Also, I believe Mozilla has a massive opportunity here to demarcate themselves as the more security-conscious browser vendor. "This phishing trick works on all major browsers except Firefox" would be great publicity material.

Turning it on by default would be a massive disservice to the work that domain registries and registrars have been doing to allow Unicode to be used in domain names. In Spanish speaking countries the ñ character is pretty ubiquitous for example, and the workaround of replacing it with an n creates many problems like misdirected web traffic and typos in email addresses. Unicode in URLs and domain names is a feature, abuse should be attacked by means other than disabling it.

Seems to be on by default in Librewolf(I just checked mine from the AUR on Arch), maybe consider that one!

3 more...