Re: Unicode domain names issue (Encrypting a "fake" domain name)
Kyle Hamilton <[email protected]> Mon, 24 Apr 2017 13:36:49 -0700
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CADgtLZ59LJihdYap+A=FO2z25BT93RrJ14WC5bgZURnrXK9QAA@mail.gmail.com> |
On Mon, Apr 24, 2017 at 2:04 AM, Gervase Markham <[email protected]> wrote: > On 21/04/17 19:42, Kyle Hamilton wrote: >> In the instant case, the font used in the address bar uses the same >> glyph shapes for both Latin and Cyrillic. Might it be appropriate to >> use (and provide) a font that uses different glyphs for every >> confusable code point, and then provide some kind of user training on >> how if the shapes don't match what they're used to it might be >> phishing? This would be demonstrably script-neutral. > > Whose letters get distorted and whose letters get to stay the same? Anything that is not U+0020 to U+007F gets altered. > If the differences are only small, the chances are people won't notice. > If they don't notice apple.com.example.com, then they won't notice this. Then it's probably a user training issue: how many people even look at the address bar after they click a link? Create a UI that trains them to look at it. Or, you know, a UI that pops up a "if this is supposed to be Apple Computer, it should look like 'apple.com'. If the letters don't look the same as this, you are not at Apple Computer's site." or something. >> The downside is that it would unduly burden users whose >> shape-recognition is sub-par, but pretty much every other idea for >> protecting the users has been shot down by Mozilla reps on this list. >> I'm sorry, but this is not "somebody else's problem". The users use >> your software, and you are the only ones they can hope to save them >> from threats that others refuse to take responsibility for. > > Is it a bird? Is it a plane? No... it's a dinosaur! > >> Mozilla has always claimed that it's focused on user security. If >> you're enforcing the rule "if it works on one Firefox, it works on all >> Firefoxes" (in the context of "IDN owners might not use IDN if IDN >> doesn't work everywhere") to the detriment of user security and >> increasing phishability, are you really focused on user security? Why >> is IDN display a sacred cow, when it increases the risk for your users >> to be scammed? IDN owners don't apparently provide mindshare to >> Mozilla, nor contribute to the installed base. > > Are you properly assessing the level of the risk? Unlike mixed-script > systems, there is at most 1 and normally 0 Cyrillic whole-script > homographs of any domain. That means that now we've done this dance, > no-one can ever do this to Apple again. I would expect other major > domain owners who are paying attention to be going out there and > spending all of $7 on the Cyrillic homograph of their domain, if there > is one. ...I'm sure that Apple and Epic and whoever else are going to be quite happy going through the UDHR process to seize ownership of their homograph domains from whoever do currently own them. You realize that costs a bit more than $7, right? >> Mozilla reps on this list have tried to push the problem off on >> everyone else -- the registrars (of which a subset refuse to accept >> the responsibility, and cannot be compelled to do so), > > So it's OK for them to say it's not their responsibility but not OK for > us to say it's not our responsibility? Correct. They don't have contracts in place (EULAs) with individual users, whereas you do. They don't advertise that they operate for the benefit or safety of the people who look up using their software or services, whereas you do. You're the ones whose software is actually used by the users, with one-on-one relationships with you. You're the last and only line of defense for your users against the uncaring policies of the rest of the Internet world. (More importantly, Chrome and Safari have accepted responsibility for their users' security on this topic, and Mozilla is now the outlier.) > Or is what you mean that because we have an open process, there's more > chance of shouting at us until we do something than there is of shouting > a the registries until they do something? Wow. Someone's taking this personally. No, I mean that Mozilla has always in the past acted toward its users' security, has always acted against homograph and easily-confusable domains, and has always advertised that record. This lack of action is a marked departure from what it has done, and a marked departure from its advertising. It's not far-fetched to worry that there could be legal liability here for false advertising. Mozilla does have the ability to act for the benefit of its users here. But it seems that it no longer feels interested in doing so. -Kyle H