zlacker

[return to "The FBI now recommends using an ad blocker when searching the web"]
1. Tactic+ra[view] [source] 2023-02-23 21:39:25
>>taubek+(OP)
Here are a few things I do to combat nasty websites:

- blacklists entire domains using wildcards (using an "unbound" DNS resolver and forcing all traffic to my DNS resolver, preventing my browser to use DoH -- I can still then use DoH if I want, from unbound)

- reject or drop a huge number of known bad actors, regularly updated: they go into gigantic "ip sets" firewall rules

- (I came up with this one): use a little firewall rule that prevents any IDN from resolving. That's a one line UDP rule and it stops cold dead any IDN homograph attack. Basically searching any UDP packet for the "xn--" string.

I do not care about what this breaks. The Web still works totally fine for me, including Google's G Suite (yeah, I know).

EDIT: just to be clear seen the comments for I realize I wasn't very precise... I'm not saying all IDN domains are bad! What I'm saying is that in my day to day Web surfing, 99.99% of the websites I'm using do not use IDN and so, in my case, blocking IDN, up until today, is totally fine as it not only doesn't prevent me from surfing the Web (I haven't seen a single site I need breaking) but it also protects me from IDN homograph attacks. Your mileage may vary and you live in a country where it's normal to go on website with internationalized domain names, then obviously you cannot simply drop all UDP packets attempting to resolve IDNs.

◧◩
2. cgb223+wj[view] [source] 2023-02-23 22:21:12
>>Tactic+ra
What’s an IDN and what does blocking them help with?
◧◩◪
3. NetOpW+0m[view] [source] 2023-02-23 22:31:23
>>cgb223+wj
Mainly homoglyphs. Characters that LOOK like Latin characters but aren't. Scammers register domains to make it look like at a glance you're visiting a reputable site.

It's why many browsers started defaulting to showing "xn--<whatever>" (punycode representation of IDN characters).

It sucks for domains that are emoji but whatevs. Scammers ruining things for everyone, as usual.

◧◩◪◨
4. quickt+OR1[view] [source] 2023-02-24 11:28:17
>>NetOpW+0m
Blocking domains with mixed character sets? Might be hard to come up with the rules. But legit sites should stick to one language mostly.
[go to top]