Re: Unicode domain names issue (Encrypting a "fake" domain name)

Henri Sivonen <[email protected]> Tue, 18 Apr 2017 13:28:21 +0300
Newsgroups gmane.comp.mozilla.security
Message-ID <CAJQvAueWcwKesJ8Vv7YKWCYf2LEZPn3gDiSQo_75M7cj9nteSg@mail.gmail.com>
On Tue, Apr 18, 2017 at 12:29 PM, Gervase Markham <[email protected]> wrote:
> Neither browsers nor CAs have a database of all domain names, such that
> they can see that one is visually confusable with another. Registries
> have this data, and it is their responsibility to deal with this problem.

Indeed, registries could normalize names first to remove diacritics
and then to map confusables to a canonical exemplar of each confusion
group (e.g. map Cyrillic ะพ to Latin o or the other way round) and then
require that names that become the same under such confusability
normalization belong to the same registrant.

Sadly, it seems that .com in particular doesn't care and it seems that
ICANN doesn't care to require this kind of thing. Solving this would
require putting security ahead of greed at the ICANN level, and the
financial incentives (ability to make money by allowing confusing
names to be sold) go against security.

(I think ICANN's failure to solve this doesn't mean that CA policy
should try to solve this.)

-- 
Henri Sivonen
[email protected]
https://hsivonen.fi/
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security