Re: Unicode domain names issue (Encrypting a "fake" domain name)

"L. David Baron" <[email protected]> Mon, 24 Apr 2017 18:53:20 +0800
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
On Friday 2017-04-21 13:05 +0200, Igor Bukanov wrote:
> On 21 April 2017 at 00:54, Eli the Bearded <*@eli.users.panix.com> wrote:
> > Objection. Configuration to not record history is trivial, and even
> > if not configured such, some confusables could easily be sites that
> > the user doesn't visit often enough to have in history.
> 
> Still the history is very valuable to dismiss it because it does not
> work in all cases. At the very list in a typical case the history
> shows what kind of scripts the user ever visited per top-level domain
> allowing to flag unexpected script. For example, personally I will be
> very suspicious about a Cyrillic.com domain as those are awkward to
> type (one has to change the keyboard layout in the middle). If a site
> needs Russian domain, I expect it to use .рф not .com

This makes me wonder:  could we become more suspicious (in terms of
UI indications) of sites where the script changes between different
parts of the hostname (or eTLD+1), i.e., move towards expecting that
non-Latin domain names will be using a non-Latin TLD?

-David

-- 
𝄞   L. David Baron                         http://dbaron.org/   𝄂
𝄢   Mozilla                          https://www.mozilla.org/   𝄂
             Before I built a wall I'd ask to know
             What I was walling in or walling out,
             And to whom I was like to give offense.
               - Robert Frost, Mending Wall (1914)

_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security
signature.asc (application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCAAGBQJY/dkeAAoJEO/hYSUPhPwhf9QP/2nJA/wMUnmVv6I8ftow9B8H
auG8/io+LueTGIcm967qA3s/ya2Oddra0PdJ5ZnMVJdyiBr1vNjPTg+fCt0FShnx
oLR4ihJk7aJJ217xpr3Aepq+/tBUdacijUGuMWOmGlti4Cncu4BhSo6Ebw8py8PV
aO3HNeqRmbuL0RTSE1qX6DTtTufSmKZSpRWQQJsHUT6hNO9tmk/YsmvsKInVm7rh
LRYNHfUXypRissStktePgjYLwKPiNu0VhaYlWPsl9qTZsvDA84S0C5PZPVV59jqn
nO3E1PfS7dF4FZLdbE/2UAFATbu2LfkkOVnIYY/899SIlNxXeSCfYmh03P8U5f7M
yszmZyG8IpDkMTAyt9SiboBirTZoQazXXRamxKlHYI4jqSdwbcNKE0b3IIbOWpDn
95s54JDKmC9qnPkqVfRBO7E4P7CU/CvKE9k4HgVoF6EdqJRu3q4pYjQen3AojAZE
MfjAUS1QFyCrOnCUlw9CQRA5VBZbE6QZjccoWtdkcq/b3g4+ew2lp3AIS6Ir1Pt8
B6QocYFOcAw41XCzekmj1qdaf4N+wxLVI9qPJA+wuthNYwPsW8QAQ7pd31KTsazz
oCKN6CnjJOHG8DmWN9mJWAIby9EplnUISnIH7Ic8DQa2JZG5d4OePLi+zEKnhx4T
P8MlUSmDoGcKE+92V2Ek
=sJmF
-----END PGP SIGNATURE-----