Re: Unicode domain names issue (Encrypting a "fake" domain name)

Kyle Hamilton <[email protected]> Tue, 18 Apr 2017 18:13:32 -0700
Newsgroups gmane.comp.mozilla.security
Message-ID <CADgtLZ6xbjwwzj=pfynp09YeT+aE3Lr0E1k6JyF=vrR65KPcmA@mail.gmail.com>
How did the algorithm in
https://bugzilla.mozilla.org/show_bug.cgi?id=722299 (which points to
https://wiki.mozilla.org/IDN_Display_Algorithm#Algorithm ) fail to
help in this instance?

Are there other instances in which it could be expected to fail?

If there are, the hypothesis set forth in
https://bugzilla.mozilla.org/show_bug.cgi?id=843689 (that the new IDN
display algorithm was sufficient enough to prevent IDN weirdnesses
that the whitelist could be removed) is shown to be false, and Mozilla
either needs to either find a better solution, or go back to the
whitelist.

-Kyle H


On Tue, Apr 18, 2017 at 6:35 AM, L. David Baron <[email protected]> wrote:
> On Tuesday 2017-04-18 10:29 +0100, Gervase Markham wrote:
>> Neither browsers nor CAs have a database of all domain names, such that
>> they can see that one is visually confusable with another. Registries
>> have this data, and it is their responsibility to deal with this problem.
>
> So we used to have a whitelist of registries that had sensible
> policies for dealing with this, but we stopped using it in
> https://bugzilla.mozilla.org/show_bug.cgi?id=843689 .
>
> Should we enable the whitelist approach again?
>
> (One of the big issues with it was that some of the most prominent
> domains, like .com, had policies that we saw as unacceptable.)
>
> -David
>
> --
> 𝄞   L. David Baron                         http://dbaron.org/   𝄂
> 𝄢   Mozilla                          https://www.mozilla.org/   𝄂
>              Before I built a wall I'd ask to know
>              What I was walling in or walling out,
>              And to whom I was like to give offense.
>                - Robert Frost, Mending Wall (1914)
>
> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security
>
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security