For Apple users without latest security updates, the letter 'd' is not always the letter 'd'

Science & Tech 14:09 20.11.2018

Most Apple users install updates, but there's always a small group of people who, for various reasons, lag behind when it comes to installing updates, for one reason or another, legitimate, or not.

If you're one of the users in the latter category, then you should be aware that the letter "d" is not always the letter "d" when displayed inside the Safari address bar.

This might sound like a non-issue, but it's actually a very important problem that all Apple users who don't run the latest OS software need to be aware of, as they could fall victims to what security researchers call "IDN homograph attacks."

IDN homograph attacks happen when someone registers a domain using Unicode characters that look like standard Latin letters, but they are not. For example, coinḃase.com is an IDM homograph attack for coinbase.com (notice the dot above the letter b).

These lookalike domains are usually used for phishing, tricking users into thinking they accessed a legitimate site when they're on a cleverly crafted clone.

IDN homograph attacks have been an issue over the past year, and several incidents have been reported in the security news media about homograph attacks against cryptocurrency exchanges in 2017 and 2018.

Driven by this new wave of homograph attacks, xisigr, a security researcher at Tencent Security Xuanwu Lab, has recently taken a look at how Apple products handle Unicode characters.

What the researcher found is that Apple does a good job with most Unicode characters, except one --which is the letter dum (ꝱ) (U+A771), part of the extended Latin alphabet character set.

The letter looks like a normal Latin lowercase letter 'd', except it comes with a lower apostrophe. But xisigr found that Safari did not render the small lower apostrophe, displaying the letter dum as a Latin letter d.

apple-letter-d-dum.png

The Tencent researcher reported his findings to Apple, who issued security updates in July for Safari, iOS, macOS, tvOS, and watchOS.

Unfortunately, users who have not applied those updates are still vulnerable to phishing attacks. An attacker can record domain names that include the letter dum and he can launch phishing campaigns against Apple users.

Xisigr says the issue should not be ignored because he found that the letter d is part of almost 25 percent of all Top 10,000 domains, providing attackers with a huge phishing surface.

Some of the domains that a phisher could impersonate include LinkedIn, Baidu, Dropbox, Adobe, WordPress, Reddit, or GoDaddy, just to name a few.

Furthermore, even if some domain registrars prevent users from registering domain names that contain Unicode characters, this limitation doesn't apply to the letter dum because it's part of the extended Latin character alphabet, and hence, is considered a standard Latin character.

If Apple users can't update, for the time being, they should at least take notice that the letter "d" in Safari's URL bar may not actually be "d" and they should use another browser to navigate the web until they can apply Apple's July security patches.

IEPF issued a statement regarding Azerbaijani children at the UN Human Rights Council

News line

Members of the Public Council under ANAMA have visited the region
16:52 08.05.2025
The "Roots of Peace" organization will host the "Peace Walk"
16:49 08.05.2025
"Since 1948 SL Heads of State have ‘relayed’ on the Ethnic conflict"
15:32 08.05.2025
A conference on the topic "Heydar Aliyev-Independence and Glorious Victory" was held in Lachin
12:44 08.05.2025
Azerbaijan showcases tourism opportunities in Israel
12:39 08.05.2025
''Azerbaijan House'' opened in Lebanon
12:33 08.05.2025
Vietnam prioritizes strategic and political cooperation with Azerbaijan
12:27 08.05.2025
Opening of new Baku City Prosecutor's Office building held
12:23 08.05.2025
Azerbaijani and Morocco may organize mutual cultural days
12:15 08.05.2025
Sahiba Gafarova: Heydar Aliyev's personality is symbol of wisdom for every Azerbaijani
12:09 08.05.2025
Milli Majlis to adopt statement on Heydar Aliyev's 102nd birth anniversary
12:03 08.05.2025
Azerbaijan Confederation of Trade Unions organized an event
11:58 08.05.2025
The 102nd anniversary of the birth of National Leader Heydar Aliyev was celebrated in Berlin
11:52 08.05.2025
Azerbaijan's First Lady Mehriban Aliyeva attended session at Antalya Diplomacy Forum
11:43 08.05.2025
Azerbaijan, Vietnam explore prospects for educational cooperation
11:37 08.05.2025
Petrovietnam aims to expand cooperation with Azerbaijan
11:32 08.05.2025
The heads of state of Azerbaijan and Vietnam made statements to the press
11:29 08.05.2025
Kamran Aliyev:' 'Heydar Aliyev had unparalleled role as founder of Azerbaijani statehood''
11:24 08.05.2025
Azerbaijani and Vietnamese discuss strategic partnership
11:21 08.05.2025
Azerbaijan ready for further coordination and cooperation with Syria
11:16 08.05.2025
Scientists have discovered a possible candidate for the ninth planet in the solar system
11:12 08.05.2025
Business Council to be established between Azerbaijan and Vietnam
11:08 08.05.2025
May 8 is World Thalassemia Day
11:03 08.05.2025
Special session of Milli Majlis dedicated to year of Constitution and sovereignty
10:59 08.05.2025
General Secretary of the Central Committee Of Vietnam visited the Alley of Martyrs
10:51 08.05.2025
General Secretary of the Central Committee of Vietnam visits the Old City
10:47 08.05.2025
Azerbaijan's position with China as a reliable partner is strengthening
10:43 08.05.2025
The Aztelekom flag was raised at the Heydar Aliyev Summit
10:39 08.05.2025
President: There are great prospects for cooperation between Azerbaijan and Vietnam in the defense industry
10:34 08.05.2025
Azerbaijani and Iraqi FMs explore regional issues
10:25 08.05.2025
Joint Statement opens new chapter in the history of Vietnam-Azerbaijan relations
10:12 08.05.2025
Leaders of Azerbaijan and Vietnam viewed exhibition of Vietnamese paintings
10:09 08.05.2025
Azerbaijani Foreign Minister meets with Iraqi PM
10:02 08.05.2025
Rebuilding hope amid the landmines Thembisa Fakude writting...
13:45 07.05.2025
How TikTok and Instagram Became New Tools of Diplomacy?
12:44 07.05.2025
Students of one of Turkey's leading universities were informed about the legacy of the great Nizami Ganjavi
12:26 07.05.2025
Azerbaijani energy minister holds several meetings in Türkiye
12:21 07.05.2025
Azerbaijan-Iran bilateral cooperation agenda discussed in Baku
12:18 07.05.2025
Azerbaijan shows progress in banking regulatory reforms
12:17 07.05.2025
About 20 Azerbaijani citizens returned from Germany yesterday
12:13 07.05.2025
Hamısı