Skip to main content

Gmail acts to sort out new scam using non-Latin characters

gmail acts to sort out new scam using non latin characters
Image used with permission by copyright holder
Google said Tuesday it’s sorted out an issue that arose after it rolled out a change last week which enabled Gmail to recognize email addresses that contain accented or non-Latin characters.

Soon after the feature was introduced, it became apparent that nefarious types had cottoned on to the fact that it was possible to dupe users into thinking they were receiving mail from a genuine company or user when actually it was coming from a scammer or spammer.

How did it work? Mark Risher of Google’s spam and abuse team explained in a post on the Web firm’s security blog:

“Scammers can exploit the fact that ဝ, ૦, and ο look nearly identical to the letter o, and by mixing and matching them, they can hoodwink unsuspecting victims. Can you imagine the risk of clicking ‘ShppingSite’ vs. ‘ShoppingSite’ or ‘MyBank’ vs. ‘MyBɑnk’?”

homoglyphs
Image used with permission by copyright holder

Risher said the Unicode community has worked to identify dodgy-looking combinations of letters that could be misleading, enabling Gmail to now reject email deemed suspicious via its spam filters.

“We’re rolling out the changes today, and hope that others across the industry will follow suit,” Risher wrote in the post. “Together, we can help ensure that international domains continue to flourish, allowing both users and businesses to have a tête-à-tête in the language of their choosing.”

Topics
Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
How to create a Subreddit on desktop and mobile
Laptop Working from Home

Few social media sites are as popular as Reddit. Regardless of what you're interested in, there's probably a thriving community for you to interact with on the platform. Known as subreddits, these communities are home to topics like gaming, world news, science, movies, and more. If you can't find a subreddit with your particular interest, Reddit makes it easy to create your own Reddit community.

Running a successful Reddit community isn't easy – but the process of starting one only takes a few minutes. Keep in mind that you'll want to keep a close eye on your subreddit to prevent it from being shut down or turning into a wasteland with no users, but running a subreddit can be a lot of fun when done properly. If you prefer, you can also create a private community that only your friends can join, giving you a place to hang out beyond Twitter and TikTok.

Read more
How to download music from YouTube on desktop and mobile
A woman sitting on a couch, wearing airpods and holding and looking at a smartphone.

Downloading music from YouTube is a fairly common practice, and the demand for making the process easier has inspired the creation of countless websites and software.

But not every service can be considered safe. In fact, some of these services may infect your computer with malware or produce poor-quality audio files. When downloading music from YouTube, you’ll need to first make sure that the websites or apps you use for doing so won’t hurt your device. For this guide our team has found two methods to make the process safer and easier.

Read more
How to clear your browser cache in Chrome, Edge, or Firefox
The Firefox iPhone app.

A stocked computer cache may be convenient for logging into and out of go-to sites in seconds flat, but a major buildup of these tracking codes could significantly impact your PC’s performance. If you’ve noticed that your PC has been running rather slow of late, or you’re using a new browser and don’t know how to clear its cache, we’ve got you covered with the following guide.

Read more