Re: Unicode domain names issue (Encrypting a "fake" domain name)
Chaddaï Fouché <[email protected]> Fri, 21 Apr 2017 10:25:27 -0700 (PDT)
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
Le vendredi 21 avril 2017 12:28:41 UTC+2, Gervase Markham a écrit : > > Before we do another canter through the six different ideas that always > occur to people when first presented with this issue, the very unofficial > https://wiki.mozilla.org/Gerv%27s_IDN_Display_Algorithm_FAQ > might help shortcut the process. The initial proposition of Igor Bukanov (that every domain name be preceded by an icon indicating the writing system, yes, even the latin ones) seems completely neutral regarding non-latin languages and not very obtrusive. I'm pretty sure most non-technical people don't even look at the url bar and don't care about the icons that already appear there : info, lock, read mode, zooming state, reload. Adding just one more probably won't suddenly overload them and it would allow every technically minded people to see instantly if the domain name is in the writing system they expect. Your IDN algorithm already compute this information anyway. Your reaction amounting to "we give priority to our ideal of handling every language equally over security (of everyone, regardless of their language) because we consider 1) that it's the fault of the registrars (irrelevant from the user point of view, and unlikely to be fixed from that side) and 2) that our users are fragile little flowers that will be scared by any additional UI element (that's insulting by the way even if a cleaner UI is a worthy goal)" is giving me second thoughts about staying with Firefox after almost 15 years with Mozilla (since the 1.0 version)... Ideals are one of the reason I stayed with the Mozilla foundation so I'm not faulting you on that but on your priorities : security for your users should really be more important than avoiding *anything* that could offense their sensibility. -- Chaddaï Fouché _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security