Hacker News new | ask | show | jobs
by Buge 2362 days ago
Look at these 2:

    https://ee.co.uk.billing-update-jan02.info
    https://ee.co.uk/billing-update-jan02.info
There's just a single character difference. The layperson will think they mean the same thing. Now look at these 2:

    https://info.billing-update-jan02.uk.co.ee
    https://uk.co.ee/billing-update-jan02.info
There's a big difference there. People can easily see something is abnormal.
1 comments

The attacker wouldn't use that one in that case though.

    https://uk.co.ee/billing-update-jan02.info
    https://uk.co.ee-billing-update-jan02/info
Would be more likely.

Perhaps an animation showing both would help.

You're right, the benefit isn't really about character differences. In both cases users need to be taught that '-' isn't a divider and '.' is a divider. The benefit is that it would be easier to teach people to start on the left then search right than it is to teach people to start at the leftmost / (but not the ones in the scheme) then search left.