Re: Unicode domain names issue (Encrypting a "fake" domain name)
Kai Engert <[email protected]> Tue, 18 Apr 2017 22:27:25 +0200
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
How the ideas could look like with URLs that include a path: On Tue, 2017-04-18 at 22:13 +0200, Kai Engert wrote: > Trying to come up with some ideas, without knowing the history of ideas > already > discussed. > > Could the browser UI always display the xn-- encoding in addition, if it isn't > plain ASCII, like: > URL bar showing: https:// www. еріс .com (xn--e1awd7f.com) https:// www. еріс .com (xn--e1awd7f.com) /more/of/url.html > If there's worry that the hostname could be very long, longer than the user's > display, which results in the trailing (xn--) not being inside the visible > display, maybe the URL bar display could alternate between showing the nicely > rendered hostname, and the xn-- name, for 2 seconds each? > > Alternatively, could the URL bar show the name of the identified script? > > https:// www. еріс .com (cyrillic) > Maybe "cyrillic" and the subset of the letters in that script could be > displayed > using highlighting, like a different color (same color for the word cyrillic > and > the cyrillic letters), or underlining? > > https:// www. epic .com (cyrillic) > ---- -------- https:// www. epic .com (cyrillic) /more/of/url.html ---- -------- > How about indicating the script as part of the protocl? Absent means > latin/ascii. > > https-cyrillic:// www. epic .com https-cyrillic:// www. epic .com /more/of/url.html _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security