Re: Unicode domain names issue (Encrypting a "fake" domain name)
Kyle Hamilton <[email protected]> Tue, 18 Apr 2017 18:13:32 -0700
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CADgtLZ6xbjwwzj=pfynp09YeT+aE3Lr0E1k6JyF=vrR65KPcmA@mail.gmail.com> |
How did the algorithm in https://bugzilla.mozilla.org/show_bug.cgi?id=722299 (which points to https://wiki.mozilla.org/IDN_Display_Algorithm#Algorithm ) fail to help in this instance? Are there other instances in which it could be expected to fail? If there are, the hypothesis set forth in https://bugzilla.mozilla.org/show_bug.cgi?id=843689 (that the new IDN display algorithm was sufficient enough to prevent IDN weirdnesses that the whitelist could be removed) is shown to be false, and Mozilla either needs to either find a better solution, or go back to the whitelist. -Kyle H On Tue, Apr 18, 2017 at 6:35 AM, L. David Baron <[email protected]> wrote: > On Tuesday 2017-04-18 10:29 +0100, Gervase Markham wrote: >> Neither browsers nor CAs have a database of all domain names, such that >> they can see that one is visually confusable with another. Registries >> have this data, and it is their responsibility to deal with this problem. > > So we used to have a whitelist of registries that had sensible > policies for dealing with this, but we stopped using it in > https://bugzilla.mozilla.org/show_bug.cgi?id=843689 . > > Should we enable the whitelist approach again? > > (One of the big issues with it was that some of the most prominent > domains, like .com, had policies that we saw as unacceptable.) > > -David > > -- > 𝄞 L. David Baron http://dbaron.org/ 𝄂 > 𝄢 Mozilla https://www.mozilla.org/ 𝄂 > Before I built a wall I'd ask to know > What I was walling in or walling out, > And to whom I was like to give offense. > - Robert Frost, Mending Wall (1914) > > _______________________________________________ > dev-security mailing list > [email protected] > https://lists.mozilla.org/listinfo/dev-security > _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security