Re: Unicode domain names issue (Encrypting a "fake" domain name)
Eli the Bearded <*@eli.users.panix.com> Thu, 20 Apr 2017 22:00:12 -0500
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Organization | Some absurd concept |
| Message-ID | <[email protected]> |
In mozilla.dev.security, Justin Dolske <[email protected]> wrote: > On 4/20/17 3:54 PM, Eli the Bearded wrote: >> Objection. Configuration to not record history is trivial, and even > Yep. > I don't think "browsing history disabled" is necessarily common enough Common or not, it's broken to ignore that case. >> More baked: Using the confusables list from Unicode, if a domain label >> consists entirely of letters in one script that are "confusable" to >> another (single) script, start raising red flags. > Sure, but the angle I found interesting here was to make a guess as to > which one is the legitimate site for the user, based solely on local > user data and avoiding favoring a particular script. I'm not proposing favoring any particular script, just highlight to the user that an IDN is composed entirely of confusables to a single different script. There may be false positives, particalarly on short hostnames, but I suspect that will be unlikely in practice. This site, https://www.xn--80ak6aa92e.com/, uses the Cyrillic alphabet to create a URL that resembles the Latin alphabet "www.apple.com". Do you wish to continue? Elijah ------ bonus for defaulting to "No"