I tried to make "Z0rbaTHut" and the UI blocked me, but when I modified the request and forced it to sign up anyway, the account got made.
Unfortunately I lost the original web requests showing that "Z0rbaTHut" was not allowed so I am not 100% sure I found an explicit bug. (But maybe an implicit bug in that we should discourage homographic attacks?)
Jump in the discussion.
No email address required.
Notes -
Practically speaking, the guard is going to be "we ban you if we think you're being a dick about it". There's maybe room for more later, but it's not a priority when we can just spend some admin power on it.
More options
Context Copy link