Re: Unicode domain names issue (Encrypting a "fake" domain name)
Craig Francis <[email protected]> Wed, 19 Apr 2017 10:18:33 +0100
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
For those who use Latin characters "most of the time" (US, UK, etc), then why not apply a highlight to any non-Latin characters? i.e. characters you would not expect to see normally. As per the screenshot attached, or if attachments get removed, at this URL: https://www.krang.org.uk/misc/unicode-domain.jpg Notes: - I only highlighted the first character, in this case it should have been the whole word. - I am a little unsure about this approach from an accessibility point of view (which might not be as much of an issue for screen readers, e.g. VoiceOver says something like "yeris dot com"). - This does not consider that Chinese and Spanish are the most spoken languages. > On 19 Apr 2017, at 08:47, Igor Bukanov <[email protected]> wrote: > > On 18 April 2017 at 23:41, Kai Engert <[email protected]> wrote: >> Could the browser use the configured default language, to know the expected usual script, and use special hightlighting (looking like a warning) whenever the domain uses a non-matching script? > > The default language does not work for countries using Cyrillic > script. The vast majority of domains there are in Latin. That makes > fishing attacks more effective as domains are not expected to be typed > at all. They either come from search engines or links in email or > social media. > _______________________________________________ > dev-security mailing list > [email protected] > https://lists.mozilla.org/listinfo/dev-security