Re: Unicode domain names issue (Encrypting a "fake" domain name)

Igor Bukanov <[email protected]> Fri, 21 Apr 2017 13:05:07 +0200
Newsgroups gmane.comp.mozilla.security
Message-ID <CADd11yU24XiEg0386hFu9sECFNnLeQNRf1sox+1mDf7q25VK_w@mail.gmail.com>
On 21 April 2017 at 00:54, Eli the Bearded <*@eli.users.panix.com> wrote:
> Objection. Configuration to not record history is trivial, and even
> if not configured such, some confusables could easily be sites that
> the user doesn't visit often enough to have in history.

Still the history is very valuable to dismiss it because it does not
work in all cases. At the very list in a typical case the history
shows what kind of scripts the user ever visited per top-level domain
allowing to flag unexpected script. For example, personally I will be
very suspicious about a Cyrillic.com domain as those are awkward to
type (one has to change the keyboard layout in the middle). If a site
needs Russian domain, I expect it to use .рф not .com

> More baked: Using the confusables list from Unicode, if a domain label
> consists entirely of letters in one script that are "confusable" to
> another (single) script, start raising red flags.

The problem is that at least for Russian/English language the words
consisting of only confusable characters are frequent enough to bring
way too many false positives to be usable.
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security