Re: Unicode domain names issue (Encrypting a "fake" domain name)
Henri Sivonen <[email protected]> Tue, 18 Apr 2017 13:28:21 +0300
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CAJQvAueWcwKesJ8Vv7YKWCYf2LEZPn3gDiSQo_75M7cj9nteSg@mail.gmail.com> |
On Tue, Apr 18, 2017 at 12:29 PM, Gervase Markham <[email protected]> wrote: > Neither browsers nor CAs have a database of all domain names, such that > they can see that one is visually confusable with another. Registries > have this data, and it is their responsibility to deal with this problem. Indeed, registries could normalize names first to remove diacritics and then to map confusables to a canonical exemplar of each confusion group (e.g. map Cyrillic ะพ to Latin o or the other way round) and then require that names that become the same under such confusability normalization belong to the same registrant. Sadly, it seems that .com in particular doesn't care and it seems that ICANN doesn't care to require this kind of thing. Solving this would require putting security ahead of greed at the ICANN level, and the financial incentives (ability to make money by allowing confusing names to be sold) go against security. (I think ICANN's failure to solve this doesn't mean that CA policy should try to solve this.) -- Henri Sivonen [email protected] https://hsivonen.fi/ _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security