Re: Unicode domain names issue (Encrypting a "fake" domain name)

Eli the Bearded <*@eli.users.panix.com> Thu, 20 Apr 2017 22:00:12 -0500
Newsgroups gmane.comp.mozilla.security
Organization Some absurd concept
Message-ID <[email protected]>
In mozilla.dev.security, Justin Dolske  <[email protected]> wrote:
> On 4/20/17 3:54 PM, Eli the Bearded wrote:
>> Objection. Configuration to not record history is trivial, and even
> Yep.
> I don't think "browsing history disabled" is necessarily common enough 

Common or not, it's broken to ignore that case.

>> More baked: Using the confusables list from Unicode, if a domain label
>> consists entirely of letters in one script that are "confusable" to
>> another (single) script, start raising red flags.
> Sure, but the angle I found interesting here was to make a guess as to 
> which one is the legitimate site for the user, based solely on local 
> user data and avoiding favoring a particular script.

I'm not proposing favoring any particular script, just highlight to the
user that an IDN is composed entirely of confusables to a single
different script. There may be false positives, particalarly on short
hostnames, but I suspect that will be unlikely in practice.

    This site, https://www.xn--80ak6aa92e.com/, uses the Cyrillic
    alphabet to create a URL that resembles the Latin alphabet
    "www.apple.com". Do you wish to continue?

Elijah
------
bonus for defaulting to "No"