Re: Unicode domain names issue (Encrypting a "fake" domain name)
Martin Heaps <[email protected]> Mon, 17 Apr 2017 11:43:10 -0700 (PDT)
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
On Monday, 17 April 2017 16:54:27 UTC+1, Anne van Kesteren wrote: > On Mon, Apr 17, 2017 at 4:38 PM, Martin Heaps wrote: > > LetsEncrypt has a valid encryption certificate for the fake domain, > > It's not a fake domain, it just looks alike, but it's a valid domain > for all intents and purposes and Let's Encrypt should not do a > registrar's job. That registrars allow lookalikes to be assigned to > different entities is a problem. > https://bugzilla.mozilla.org/show_bug.cgi?id=1332714 tracks this. > > > -- > https://annevankesteren.nl/ No, a clear destinction should be made; the certificate is for the domain "xn--e1awd7f.com" but in certain browsers this is presented to the user as "epic.com" . It may not be the certificates authority to provide trust to the user that the domain certified is valid; but they should as a bare minimum have an understanding with browser providers that the certificate name is not misconstrued in any way; and that a certificate for "xn--e1awd7f.com" can never be confused with applying to "epic.com". THIS is the issue I am raising here. The word "fake" is probably an inpracise word to use, but in the context that the domain name as registered is perporting to be another domain name it is not; this is fake. The SSL provider; LetsEncrypt in this case seems to not be able to ensure with browsers that there is a clear destinction between the two names of the domain certified by the CA.