Re: Unicode domain names issue (Encrypting a "fake" domain name)
"L. David Baron" <[email protected]> Tue, 25 Apr 2017 18:28:44 +0800
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
On Tuesday 2017-04-25 10:19 +0100, Gervase Markham wrote:
> On 24/04/17 11:53, L. David Baron wrote:
> > This makes me wonder: could we become more suspicious (in terms of
> > UI indications) of sites where the script changes between different
> > parts of the hostname (or eTLD+1), i.e., move towards expecting that
> > non-Latin domain names will be using a non-Latin TLD?
>
> That ends up basically being "no .com for _you_, suspicious-looking
> non-Latin script". It's another way of treating some scripts as second
> class. Admittedly, it's not the worst way of doing so, and a very
> measured approach to this (basically, a TLD _black_list for TLDs which
> are actively allowing their customers to attack each other) isn't a
> totally terrible idea. The trouble is the collateral damage - those
> companies and businesses who are happily using <some Cyrillic
> string>.com as their domain name and now find it appears as gibberish in
> major browsers after they've spent years building their brand, just
> because the letters in their name happen all to have Latin homographs.
Couldn't it be done in a pretty limited way? For example, we could
use the punycode representation if:
* the component before the eTLD consists entirely of characters
that are homographs for characters in a single other script, and
* the component before the eTLD is in a different script from the
eTLD.
If there are some legitimate sites that this would catch, maybe we
could then whitelist them?
(I'm assuming we already require each component to be
single-script.)
-David
--
𝄞 L. David Baron http://dbaron.org/ 𝄂
𝄢 Mozilla https://www.mozilla.org/ 𝄂
Before I built a wall I'd ask to know
What I was walling in or walling out,
And to whom I was like to give offense.
- Robert Frost, Mending Wall (1914)
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security
signature.asc
(application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE----- iQIcBAEBCAAGBQJY/yTaAAoJEO/hYSUPhPwhDSIP/AgrQkeIsIx9eyc4y5mW1/z8 Zy+Qora36K6DrpetTOZyAMKR5og3D082k1Y78ljxyjKouwwVHFcQ57WbmrzIERRn TB1lBMUgqMprX8joSMq5Rr2Oduy3yx4jf5NJqdt6d1BlbspYH1obRmIarIMef8cA veboPxVv2wrv2VMe/+KOlzLE1ISw2jtb/GmgfHVtoYcTN6oiS9jUXrfO8nxLxlvE rMWZPGF9StEDgsw9In7R19fB7LcY2gil8OYjbSWSX8lPX9ShE/ZBX+Iab2FwiUlm 1r1g7Aidp9SxIL/8LoihNNCepLt6/s6ij6B2gDoUPdzyqKqRKs+RUjeOiTHa0fxP 5CSqvr3eIYaercfqglIbYmN/lLfoAracQRCBBr1ayWh/j3VkzllaCjqwFbVd2nj5 mh4UjGL6JwlbMSfIa53BxoxIQL1LiLgBsO8Mjs8tVoCzhHXhNb7+nJMbs+VE16k7 H4bkuX7p5ME3TtndRQ/iCeMprXGOfXC+dKpum6mPLtpFL5PwJ0KHO5gDDS313jvF ZirGUhUYsnJ59FUzGn/5xbtcstdYGgb3+sWC4FocbA6K42kH/jmKtGTHuwobeLkK pu986+V6NgHAqrxALdflAM7obAsNdA/p5sxCXILefRnMliTSo3pU78n8HI5nfRqm N5YO76HPvd9QW+kncsGt =o9DY -----END PGP SIGNATURE-----