Re: Unicode domain names issue (Encrypting a "fake" domain name)
Alex Gaynor <[email protected]> Mon, 24 Apr 2017 09:31:07 -0400
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CAGzK4uPgSXS_DZzT0xm2izF5S4pSMQdo5iBGfuSAxpEddy6Dhg@mail.gmail.com> |
You're right Gerv, everything is a trade-off. If I could resend that email, I'd stress that "we" is the most important part of that sentence, not "if there's more, it must be done". Specifically, my position is that just because the registrars, or someone else, _should_ have done something, doesn't make a good reason for us _not_ to do something. We are the user's agent, and we should balance priorities in serving our users against each other, not against what someone else could have done :-) As I said, I think the right solution is to invest in more general phishing mitigation, but if one believes that homoglyphs are particularly threatening, I don't think it's relevant that registers could have done something. Alex On Mon, Apr 24, 2017 at 5:06 AM, Gervase Markham <[email protected]> wrote: > On 21/04/17 19:59, Alex Gaynor wrote: > > But I agree with those who've argued for "the buck stops here" -- if > > there's more we can do, we must > > Can I just note in passing that, independent of what we do here, "if > there's more we can do, we must" is a terrible, terrible argument? > > Everything's a trade-off. Time, money, complexity, risk. Taking one > particular problem and saying "this risk must be eliminated to the > uttermost, regardless of how much time, money and added complexity is > needed" is just not a reasonable position. > > Gerv >