I tried to make "Z0rbaTHut" and the UI blocked me, but when I modified the request and forced it to sign up anyway, the account got made.
Unfortunately I lost the original web requests showing that "Z0rbaTHut" was not allowed so I am not 100% sure I found an explicit bug. (But maybe an implicit bug in that we should discourage homographic attacks?)
Jump in the discussion.
No email address required.
Notes -
There is some sort of mechanism for automatically detecting and marking suspected alt accounts. I haven't dug too deeply into exactly how it works or what it does though.
More options
Context Copy link
Practically speaking, the guard is going to be "we ban you if we think you're being a dick about it". There's maybe room for more later, but it's not a priority when we can just spend some admin power on it.
More options
Context Copy link