this post was submitted on 28 Aug 2025
48 points (87.5% liked)
Technology
74872 readers
3157 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
No fucking way I am clicking that URL.
It's punycode, it displays as japanese characters in a real browser.
https://en.m.wikipedia.org/wiki/Punycode
For those curious, the characters are katakana (the syllabary often used in Japan for foreign words, onomatopoeia, etc) and they'd be read as "ma-ri-u-su", which is possibly intended to represent "Marius" under Japanese spelling conventions.
I didn't know about that, thanks for sharing.
Thx TIL
Which is a major security risk and you should avoid those "real browsers".
by displaying Unicode characters an attacker can send you a link that clearly shows its yahoo.com and you see in the browser url that its yahoo.com but in reality its unicode letters that look similar to latin one.
that's really bad
Not everyone uses English. Many languages can't be written with only ASCII characters.
I get why it was introduced. I am telling you why its dangrous
I'm not aware of a modern browser that doesn't render it by default. I meant a real browser as in a browser not a lemmy client
you are right.
You could disable it though in firefox: "about:config" and find "network.IDN_show_punycode" and set to true.
https://www.forbes.com/sites/leemathews/2017/04/17/chrome-and-firefox-adding-protection-against-this-nasty-phishing-trick/
Others have explained the unicode-in-URL aspect sufficiently, but I can speak to the author of the site somewhat. His or her blog posts have hit the fediverse several times before. They're often insightful and skeptical, highly privacy conscious. I hope they don't mind if I take this part from their FAQ:
So, you monolingual? 🙂
Woah are you a monophobe or something?
Hey Monnie! sneer voice
xn--gck...whatever is famous in some circles!
Its fine. Trust me /s
Actually probably good on you to not trust everything on the internet.
This individual has a strange url but generally has some really insightful articles.
It's not really a "strange url" it's just the way we decided to implement unicode into URLs, which for the purposes of phishing links is catastrophically dangerous, so it's never really been widely adopted and most sites choose by default to show the raw URL, for safety. This is why we can't have nice things (and instead need to have xn-dfg344jlb5jsdfl543sdfsd.com)