Re: Unicode domain names issue (Encrypting a "fake" domain name)
Igor Bukanov <[email protected]> Fri, 21 Apr 2017 13:05:07 +0200
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CADd11yU24XiEg0386hFu9sECFNnLeQNRf1sox+1mDf7q25VK_w@mail.gmail.com> |
On 21 April 2017 at 00:54, Eli the Bearded <*@eli.users.panix.com> wrote: > Objection. Configuration to not record history is trivial, and even > if not configured such, some confusables could easily be sites that > the user doesn't visit often enough to have in history. Still the history is very valuable to dismiss it because it does not work in all cases. At the very list in a typical case the history shows what kind of scripts the user ever visited per top-level domain allowing to flag unexpected script. For example, personally I will be very suspicious about a Cyrillic.com domain as those are awkward to type (one has to change the keyboard layout in the middle). If a site needs Russian domain, I expect it to use .рф not .com > More baked: Using the confusables list from Unicode, if a domain label > consists entirely of letters in one script that are "confusable" to > another (single) script, start raising red flags. The problem is that at least for Russian/English language the words consisting of only confusable characters are frequent enough to bring way too many false positives to be usable. _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security