I tried to make "Z0rbaTHut" and the UI blocked me, but when I modified the request and forced it to sign up anyway, the account got made.
Unfortunately I lost the original web requests showing that "Z0rbaTHut" was not allowed so I am not 100% sure I found an explicit bug. (But maybe an implicit bug in that we should discourage homographic attacks?)
Jump in the discussion.
No email address required.
Notes -
There is some sort of mechanism for automatically detecting and marking suspected alt accounts. I haven't dug too deeply into exactly how it works or what it does though.
More options
Context Copy link