Re: Unicode domain names issue (Encrypting a "fake" domain name)

Daniel Veditz <[email protected]> Tue, 18 Apr 2017 08:27:23 -0700
Newsgroups gmane.comp.mozilla.security
Message-ID <CADYDTCD5sgKNdvf91MH5G+UX48E3-kTj7DExxdkDqLMAT0dR0g@mail.gmail.com>
On Tue, Apr 18, 2017 at 3:03 AM, Igor Bukanov <[email protected]> wrote:

> So as a simple heuristic a browser can show
> ​ ​
> the domain as xn-- if it

encodes a name that does not require xn--encoding.


​Are there are no legitimate Russian words made only of the 11 or so
letters that look like latin script? Should we tell Russians (and
Ukrainians, Bulgarians, Kazakhs, etc) to get the hell off our American
Internet?​ Should the browser ship with dictionaries of words in those
languages (or a subset using only the confusable characters) and check that
a cyrillic domain name maps to a legit word? What about non-word brand
names? Or the other way checking against English: we could map 'epic' and
'apple' to latin script and find those in an English dictionary. But what
about 'plaece.com', a new hypothetical social brand? Or what if it's a
cyrillic German or French word?


> Of cause that does not help when somebody uses
> xn--eic-0ed.com which is eрic.com with the Cyrillic letter "р", but
> that is a different and indeed hard to solve problems with homographs
> in Unicode.
>

​That one is the easy case: mixing scripts is not allowed. It's extremely
unlikely to be legitimate (the toys-Я-us brand notwithstanding) and that
domain will only be shown in the punycode form​.

-
​Dan Veditz​
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security