Re: Unicode domain names issue (Encrypting a "fake" domain name)
Gervase Markham <[email protected]> Mon, 24 Apr 2017 10:04:27 +0100
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
On 21/04/17 19:42, Kyle Hamilton wrote: > In the instant case, the font used in the address bar uses the same > glyph shapes for both Latin and Cyrillic. Might it be appropriate to > use (and provide) a font that uses different glyphs for every > confusable code point, and then provide some kind of user training on > how if the shapes don't match what they're used to it might be > phishing? This would be demonstrably script-neutral. Whose letters get distorted and whose letters get to stay the same? If the differences are only small, the chances are people won't notice. If they don't notice apple.com.example.com, then they won't notice this. > The downside is that it would unduly burden users whose > shape-recognition is sub-par, but pretty much every other idea for > protecting the users has been shot down by Mozilla reps on this list. > I'm sorry, but this is not "somebody else's problem". The users use > your software, and you are the only ones they can hope to save them > from threats that others refuse to take responsibility for. Is it a bird? Is it a plane? No... it's a dinosaur! > Mozilla has always claimed that it's focused on user security. If > you're enforcing the rule "if it works on one Firefox, it works on all > Firefoxes" (in the context of "IDN owners might not use IDN if IDN > doesn't work everywhere") to the detriment of user security and > increasing phishability, are you really focused on user security? Why > is IDN display a sacred cow, when it increases the risk for your users > to be scammed? IDN owners don't apparently provide mindshare to > Mozilla, nor contribute to the installed base. Are you properly assessing the level of the risk? Unlike mixed-script systems, there is at most 1 and normally 0 Cyrillic whole-script homographs of any domain. That means that now we've done this dance, no-one can ever do this to Apple again. I would expect other major domain owners who are paying attention to be going out there and spending all of $7 on the Cyrillic homograph of their domain, if there is one. > Mozilla reps on this list have tried to push the problem off on > everyone else -- the registrars (of which a subset refuse to accept > the responsibility, and cannot be compelled to do so), So it's OK for them to say it's not their responsibility but not OK for us to say it's not our responsibility? Or is what you mean that because we have an open process, there's more chance of shouting at us until we do something than there is of shouting a the registries until they do something? Gerv