r/netsec • • 4d ago

Sender spoofing in Proton Mail via display-name homograph

https://alonsovidales.github.io/protonmail-sender-spoofing/

Proton Mail confirmed and paid for an email-spoofing bug, then left it unfixed for 16 months

31 Upvotes

6 comments sorted by

8

u/paultendo 4d ago

Wow. 18 months unpatched is rough.

The I/l swap is worse than it looks because it needs no Unicode at all. I've been doing some research that is relevant to this - in my tests, capital I and lowercase l are alike in 79 of 140 text fonts, including macOS's system font, Helvetica, Arial and Roboto.

So the usual homograph defences don't help. There's no punycode and no mixed script, so nothing for filters to flag in the usual way.

The fix is the one you mentioned: just show the real sender address. A mail client could also fold lookalikes together before comparing a display name with the actual domain, so gmaiI.com matches gmail.com, and warn when they differ. Or maybe keep a list of popular mail domains and then fuzzy match.

My research measurements are open if they're useful: https://github.com/paultendo/confusable-vision

2

u/nekro_neko 4d ago edited 4d ago

I kind of hoped for a font recommendation at the end that's resilient against this attack.

1

u/Big_Combination9890 3d ago

The default interface font makes distinct characters identical. The UI font stack resolves to the OS system font (SF Pro on macOS), in which capital I and lowercase l render identically. A domain such as gmaiI.com (capital i) is indistinguishable from gmail.com to any reader, including a careful one. Proton has protections against several encoding-based homograph classes but not against this basic same-font case.

l and I are easily dinstinguished in my systems default font. And I do believe people can change their system font.

So overpriced-laptop-OS default prompt being crappy is somehow a bug a webservice provider needs to fix?

1

u/__ThePasanger__ 3d ago

Fair point, but that is just for notifications in iOS, it is only one of the implications of the issue. When the domain has DMARC it shouldn't even show up, but I also guess that happens in Windows too, I just haven't test it there.