Phishing and/or visual deception protections
Nobody has claimed this yet.
- Dominant language
- HTML
- Stars
- 3.6k
- Forks
- 831
- Avg merge
- 7h 55m
- Merged PRs (30d)
- 4
Description
I was reading this article from Wiz the other day, and the use of homoglyphs for deception stuck with me because I've tackled the same problem many years ago.
That particular issue is easy to solve (for any authoritative names, have validations that don't allow mixing of alphabets), but surely we can research and distill other similar requirements. ASVS currently doesn't have any, and I can't think of a good reason why not. Perhaps just over-focusing on pure programming logic?
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the linked Wiz article and reviewing the existing ASVS requirements to identify how phishing, homoglyphs, and visual deception are currently covered. The work is complete when the project agrees on concrete, actionable verification requirements and their appropriate place in ASVS.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100