Re: Unicode domain names issue (Encrypting a "fake" domain name)

Kyle Hamilton <[email protected]> Tue, 18 Apr 2017 13:52:47 -0700
Newsgroups gmane.comp.mozilla.security
Message-ID <CADgtLZ6OXFo-Gfp94Mikvxyh_JxcvusFXxzysQ4GhaJ8rCrwvw@mail.gmail.com>
Why not display the encoding of the host name in the area with the
security indicator, to the left of the address bar?  That is the area
where security-related displays are already made.

-Kyle H

On Tue, Apr 18, 2017 at 1:13 PM, Kai Engert <[email protected]> wrote:
> Trying to come up with some ideas, without knowing the history of ideas already
> discussed.
>
> Could the browser UI always display the xn-- encoding in addition, if it isn't
> plain ASCII, like:
>   URL bar showing: https:// www. еріс .com (xn--e1awd7f.com)
>
> If there's worry that the hostname could be very long, longer than the user's
> display, which results in the trailing (xn--) not being inside the visible
> display, maybe the URL bar display could alternate between showing the nicely
> rendered hostname, and the xn-- name, for 2 seconds each?
>
> Alternatively, could the URL bar show the name of the identified script?
>
> https:// www. еріс .com (cyrillic)
>
> Maybe "cyrillic" and the subset of the letters in that script could be displayed
> using highlighting, like a different color (same color for the word cyrillic and
> the cyrillic letters), or underlining?
>
> https:// www. epic .com (cyrillic)
>               ----       --------
>
> How about indicating the script as part of the protocl? Absent means
> latin/ascii.
>
> https-cyrillic:// www. epic .com
>
> Kai
>
> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security