Re: Unicode domain names issue (Encrypting a "fake" domain name)

Eli the Bearded <*@eli.users.panix.com> Fri, 21 Apr 2017 14:07:35 -0500
Newsgroups gmane.comp.mozilla.security
Organization Some absurd concept
Message-ID <[email protected]>
In mozilla.dev.security, Boris Zbarsky  <[email protected]> wrote:
> On 4/20/17 6:54 PM, Eli the Bearded wrote:
>> More baked: Using the confusables list from Unicode, if a domain label
>> consists entirely of letters in one script that are "confusable" to
>> another (single) script, start raising red flags.
> So just to be clear, per that proposal we should be raising red flags on 
> the "real" epic.com and keep.com and so forth, right?

The (alas unwritten) bit that is important in my proposal is that this
confusable check only happens for punycode DNS labels.

This example I posted elsewhere might be helpful to demonstate my idea:

    This site, https://www.xn--80ak6aa92e.com/, uses the Cyrillic
    alphabet to create a URL that resembles the Latin alphabet
    "www.apple.com". Do you wish to continue?

Elijah
------
might not be good enough for "full baked" yet