Re: Unicode domain names issue (Encrypting a "fake" domain name)

Frederik Braun <[email protected]> Mon, 24 Apr 2017 18:11:14 +0200
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
On 24.04.2017 13:40, Robert Kaiser wrote:
> Gervase Markham schrieb:
>> Everything's a trade-off. Time, money, complexity, risk. Taking one
>> particular problem and saying "this risk must be eliminated to the
>> uttermost, regardless of how much time, money and added complexity is
>> needed" is just not a reasonable position.
> 
> While that's true, right now, our position has the risk of the
> completely wrong point that Mozilla doesn't care if phishing happens to
> our users or by extension about their security. Now, we all know that
> this is both extremely far from the truth  - but esp. if other browsers
> "do something" (no matter how useful that "something" is) and we "do
> nothing" and "play the blame game" by saying it's someone else's fault
> (Douglas Adams fans would call it a "SEP field") then it's easy for
> outsiders to get that wrong improession.

FWIW, if this web page was actively phishing users, we would block it
through Safe Browsing. This one is not.

So the problem here is about deducing (from the domain name) if a
website is phishy. That's admittedly hard.