That link you clicked on? Yeah, it’s actually Russian

“Click this link (don’t fret, nothing malicious),” Kieren McCarthy reports for The Register. “Chances are your browser displays ‘’ in the address bar. What about this one? Goes to ‘,’ right?”

“Wrong. They are in fact carefully crafted but entirely legitimate domains in non-English languages that are designed to look exactly the same as common English words,” McCarthy reports. “The real domains for the two above links are: and”

“In quick testing by El Reg, Chrome 57 on Windows 10 and macOS 10.12, and Firefox 52 on macOS, display and rather than the actual domains,” McCarthy reports. “We’re told Chrome 57 and Firefox 52 are vulnerable while Safari and Internet Explorer are in the clear. Bleeding-edge Chrome 60 on macOS 10.12 was not vulnerable.”

“This domain disguising, which tricks people into visiting a site they think is legit but really isn’t, is called a ‘homograph attack’ – and we were supposed to have fixed it more than a decade ago when the exact same problem was noticed with respect to the address ‘,'” McCarthy reports. “So what is this, how does it work, and why does it still exist?”

MacDailyNews Take: Ⅼеτ’ѕ Ье ϲагеғυⅼ оυτ τһеге. ⋃ѕе а геаⅼ Ьгоѡѕег!


  2. Safari and Internet Explorer are in the clear. Well I use Safari only so that said not an issue. Also you shouldn’t click on links from other sources that you don’t know of anyways.

    1. Been using Opera lately because of its free VPN feature. Hoping Apple does that for Safari soon. I don’t want my ISP knowing what sites I visit and what I do there, let alone selling that information to whomever they want. And I don’t like scumbag sites tracking me by IP address and browser fingerprinting, so the VPN addresses most of that.

      Opera’s a bit buggy, but is filling most of my privacy needs.

      Not currently using Opera for viewing MDN as the default setting I have on it is to block ads and MDN denies you access if you do that. However, my intent is not to block ads, just all the tracking beacons and other BS associated with them.

    1. Safari did’t fall for it, but Chrome did.
      Not sure what you are using.

      A real eye opener. Can’t think of a better reason to keep using Safari.

      1. For Chrome (Version 57.0.2987.133 (64-bit)) the “” results in “Server could not be reached; аррӏе.com’s server DNS address could not be found.” The “” however went through. Pasting the latter provided URL in notepad makes it obvious the “www” portion of the URL is not ‘normal’.

  3. MDN: yes, but when Safari just doesn’t work for a website (happens a lot) users will get fed up and use something else.

    Why do I have to use Chrome instead of Safari for dime sites (quite a lot if sites actually)?

