Re: Unicode domain names issue (Encrypting a "fake" domain name)
Daniel Veditz <[email protected]> Tue, 18 Apr 2017 08:27:23 -0700
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CADYDTCD5sgKNdvf91MH5G+UX48E3-kTj7DExxdkDqLMAT0dR0g@mail.gmail.com> |
On Tue, Apr 18, 2017 at 3:03 AM, Igor Bukanov <[email protected]> wrote: > So as a simple heuristic a browser can show > > the domain as xn-- if it encodes a name that does not require xn--encoding. Are there are no legitimate Russian words made only of the 11 or so letters that look like latin script? Should we tell Russians (and Ukrainians, Bulgarians, Kazakhs, etc) to get the hell off our American Internet? Should the browser ship with dictionaries of words in those languages (or a subset using only the confusable characters) and check that a cyrillic domain name maps to a legit word? What about non-word brand names? Or the other way checking against English: we could map 'epic' and 'apple' to latin script and find those in an English dictionary. But what about 'plaece.com', a new hypothetical social brand? Or what if it's a cyrillic German or French word? > Of cause that does not help when somebody uses > xn--eic-0ed.com which is eрic.com with the Cyrillic letter "р", but > that is a different and indeed hard to solve problems with homographs > in Unicode. > That one is the easy case: mixing scripts is not allowed. It's extremely unlikely to be legitimate (the toys-Я-us brand notwithstanding) and that domain will only be shown in the punycode form. - Dan Veditz _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security