Re: Unicode domain names issue (Encrypting a "fake" domain name)

Alex Gaynor <[email protected]> Mon, 24 Apr 2017 09:31:07 -0400
Newsgroups gmane.comp.mozilla.security
Message-ID <CAGzK4uPgSXS_DZzT0xm2izF5S4pSMQdo5iBGfuSAxpEddy6Dhg@mail.gmail.com>
You're right Gerv, everything is a trade-off. If I could resend that email,
I'd stress that "we" is the most important part of that sentence, not "if
there's more, it must be done". Specifically, my position is that just
because the registrars, or someone else, _should_ have done something,
doesn't make a good reason for us _not_ to do something.

We are the user's agent, and we should balance priorities in serving our
users against each other, not against what someone else could have done :-)

As I said, I think the right solution is to invest in more general phishing
mitigation, but if one believes that homoglyphs are particularly
threatening, I don't think it's relevant that registers could have done
something.

Alex

On Mon, Apr 24, 2017 at 5:06 AM, Gervase Markham <[email protected]> wrote:

> On 21/04/17 19:59, Alex Gaynor wrote:
> > But I agree with those who've argued for "the buck stops here" -- if
> > there's more we can do, we must
>
> Can I just note in passing that, independent of what we do here, "if
> there's more we can do, we must" is a terrible, terrible argument?
>
> Everything's a trade-off. Time, money, complexity, risk. Taking one
> particular problem and saying "this risk must be eliminated to the
> uttermost, regardless of how much time, money and added complexity is
> needed" is just not a reasonable position.
>
> Gerv
>