Re: Unicode domain names issue (Encrypting a "fake" domain name)

Robert Kaiser <[email protected]> Mon, 24 Apr 2017 13:40:41 +0200
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
Gervase Markham schrieb:
> Everything's a trade-off. Time, money, complexity, risk. Taking one
> particular problem and saying "this risk must be eliminated to the
> uttermost, regardless of how much time, money and added complexity is
> needed" is just not a reasonable position.

While that's true, right now, our position has the risk of the 
completely wrong point that Mozilla doesn't care if phishing happens to 
our users or by extension about their security. Now, we all know that 
this is both extremely far from the truth  - but esp. if other browsers 
"do something" (no matter how useful that "something" is) and we "do 
nothing" and "play the blame game" by saying it's someone else's fault 
(Douglas Adams fans would call it a "SEP field") then it's easy for 
outsiders to get that wrong improession.

It's also a truism that being right is not always enough to make the 
right things. I think we need to do some kind of "mitigation" in the 
light of not looking worse than our competitors (which we do often 
enough unfortunately).

I think, in hindsight, it was a bad idea to abandon the whitelisting 
approach - even though it looked perfectly fine back then. We probably 
would have needed to a model somewhat similar to how we run the root CA 
list: After seeing the whitelists with what we had from our own research 
before, only add new TLDs that request that from their side and prove 
that they follow certain rules (esp. anti-homograph-attack ones). Move 
as much of the burden to those that actually make money selling IDN 
domains. The maintenenace of the list and setting of rules could 
potentially have been even in some common form between all or some of 
Mozilla, Google, Microsoft, and Apple. The alternative would have been 
to not allow IDN for new TLDs at all unless ICANN enforces rules of that 
kind (given that ICANN makes money with granting TLDs, that also would 
fit the "put the burden where the financial incentive is) - and that 
could potentially have been in accordance with other browser vendors as 
well.

Maybe we can now have some influence on ICANN so they actually set up 
anti-homograph-attack rules for TLDs, are we in talks with them on that?

That said, if any activities on the side of registires cannot be reached 
fast, I fear we need to ship "somthing" in Firefox that doesn't 
"something" to help or we risk being stamped "insecure" or 
"phisihing-friendly" even if that's not true.

KaiRo