Re: Unicode domain names issue (Encrypting a "fake" domain name)
"L. David Baron" <[email protected]> Tue, 18 Apr 2017 22:35:30 +0900
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
On Tuesday 2017-04-18 10:29 +0100, Gervase Markham wrote:
> Neither browsers nor CAs have a database of all domain names, such that
> they can see that one is visually confusable with another. Registries
> have this data, and it is their responsibility to deal with this problem.
So we used to have a whitelist of registries that had sensible
policies for dealing with this, but we stopped using it in
https://bugzilla.mozilla.org/show_bug.cgi?id=843689 .
Should we enable the whitelist approach again?
(One of the big issues with it was that some of the most prominent
domains, like .com, had policies that we saw as unacceptable.)
-David
--
𝄞 L. David Baron http://dbaron.org/ 𝄂
𝄢 Mozilla https://www.mozilla.org/ 𝄂
Before I built a wall I'd ask to know
What I was walling in or walling out,
And to whom I was like to give offense.
- Robert Frost, Mending Wall (1914)
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security
signature.asc
(application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE----- iQIcBAEBCAAGBQJY9hYgAAoJEO/hYSUPhPwhC40P/A5oCIPSw0dXVZX4CJad+d1W iLrCeRthCwYssmjQC9EKvJlr+VlVa22bgmNheu9/bEFTcL9byJ4WvbnWIkOb7w+y sYsZqSer34Qw8uA01rwbiN70QiMTEhFclZ/KzWJ18oT6Dkzpz6YLH1rABXHN5QPF 49EwaavT7m5djABbgqch/AtMvQ+kSVCoCAWz+L2MTgzJSF8rpY0B548sm71BoBfQ M+jx8IPu2aVs4UkOwGHxE5G2BLPb866w1X4f5QK0nUI6RpMp38BSz72NyRkT/Aad AMgqWDZ85RF/mj5R9L6VgPDb0DRGMOx+NzM1OArvKFo0YxQCrZQwvO8gRHcRVByj Ux+5PsP4cBhgAsWyrpP6LNImcFFzZwfr6ROiSgM1ot6aJbJuzHL7A8nj0lTY0DOI OKBGggyeweAAD2SRBNptt9BvO1XmmBckrv3gRwsfjrwJxjqI97g0ygI2siWM2WWp cxKKddtTRCz0K3fMnHzYyzulJcJeqktgHysgZ7WSRDn/Cga/yjVi4wdtgsuDtgGs mB/Wkd7Gc6Rb5QbXMZN15/j6/S/TjlfsBBDwc9guOSoX/qZOOGwrycOu94JqSETo AP54IuD7UOxgR3UyzlJTOaAXfa9Kq0r0zBzdIqdrH676QwesTc0ha93G0QZdOgdh wQMSS5bYX+eK0lsdV3C0 =KpgY -----END PGP SIGNATURE-----