Re: Unicode domain names issue (Encrypting a "fake" domain name)

Gervase Markham <[email protected]> Tue, 25 Apr 2017 10:19:04 +0100
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
On 24/04/17 11:53, L. David Baron wrote:
> This makes me wonder:  could we become more suspicious (in terms of
> UI indications) of sites where the script changes between different
> parts of the hostname (or eTLD+1), i.e., move towards expecting that
> non-Latin domain names will be using a non-Latin TLD?

That ends up basically being "no .com for _you_, suspicious-looking
non-Latin script". It's another way of treating some scripts as second
class. Admittedly, it's not the worst way of doing so, and a very
measured approach to this (basically, a TLD _black_list for TLDs which
are actively allowing their customers to attack each other) isn't a
totally terrible idea. The trouble is the collateral damage - those
companies and businesses who are happily using <some Cyrillic
string>.com as their domain name and now find it appears as gibberish in
major browsers after they've spent years building their brand, just
because the letters in their name happen all to have Latin homographs.

Gerv