Re: Unicode domain names issue (Encrypting a "fake" domain name)
Robert Kaiser <[email protected]> Mon, 24 Apr 2017 13:40:41 +0200
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
Gervase Markham schrieb: > Everything's a trade-off. Time, money, complexity, risk. Taking one > particular problem and saying "this risk must be eliminated to the > uttermost, regardless of how much time, money and added complexity is > needed" is just not a reasonable position. While that's true, right now, our position has the risk of the completely wrong point that Mozilla doesn't care if phishing happens to our users or by extension about their security. Now, we all know that this is both extremely far from the truth - but esp. if other browsers "do something" (no matter how useful that "something" is) and we "do nothing" and "play the blame game" by saying it's someone else's fault (Douglas Adams fans would call it a "SEP field") then it's easy for outsiders to get that wrong improession. It's also a truism that being right is not always enough to make the right things. I think we need to do some kind of "mitigation" in the light of not looking worse than our competitors (which we do often enough unfortunately). I think, in hindsight, it was a bad idea to abandon the whitelisting approach - even though it looked perfectly fine back then. We probably would have needed to a model somewhat similar to how we run the root CA list: After seeing the whitelists with what we had from our own research before, only add new TLDs that request that from their side and prove that they follow certain rules (esp. anti-homograph-attack ones). Move as much of the burden to those that actually make money selling IDN domains. The maintenenace of the list and setting of rules could potentially have been even in some common form between all or some of Mozilla, Google, Microsoft, and Apple. The alternative would have been to not allow IDN for new TLDs at all unless ICANN enforces rules of that kind (given that ICANN makes money with granting TLDs, that also would fit the "put the burden where the financial incentive is) - and that could potentially have been in accordance with other browser vendors as well. Maybe we can now have some influence on ICANN so they actually set up anti-homograph-attack rules for TLDs, are we in talks with them on that? That said, if any activities on the side of registires cannot be reached fast, I fear we need to ship "somthing" in Firefox that doesn't "something" to help or we risk being stamped "insecure" or "phisihing-friendly" even if that's not true. KaiRo