@Emathion 1. This is because of laissez-faire practices of the .com domain
2. Don’t click links based on what the link text says
3. Don’t teach people to click on links based on that the link text says
Very much this.
Calling @shortridge
https://hachyderm.io/@shortridge/111785270795814084
Do not click links on the Link Clicking machine, indeed.
Attached: 1 image @rmi@cloudisland.nz I created this meme forever ago to describe the devolution of information security, feel free to frame it 1970s & 1980s: Our mission is to achieve deterministic security and deductive, proof-based certainty of that security in our systems. 2010s & 2020s: Our hope rests in stopping laypeople from clicking on things on the thing-clicking machine.
@Emathion I still want a browser that always shows both the “pretty” domain name and the IDNA encoded domain name, so that kind of meddling is always obvious.
In practice, I only get suspicious when a link comes from something unexpected or the browser autofill of passwords doesn’t happen