Re: Unicode domain names issue (Encrypting a "fake" domain name)
Igor Bukanov <[email protected]> Wed, 19 Apr 2017 09:47:14 +0200
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CADd11yU=HuUjEym_COR0erLeAC5r1EhfmJDQnuoCtZENcmwmwg@mail.gmail.com> |
On 18 April 2017 at 23:41, Kai Engert <[email protected]> wrote: > Could the browser use the configured default language, to know the expected usual script, and use special hightlighting (looking like a warning) whenever the domain uses a non-matching script? The default language does not work for countries using Cyrillic script. The vast majority of domains there are in Latin. That makes fishing attacks more effective as domains are not expected to be typed at all. They either come from search engines or links in email or social media.