Re: Unicode domain names issue (Encrypting a "fake" domain name)
Daniel Veditz <[email protected]> Tue, 25 Apr 2017 18:24:26 -0700
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CADYDTCDCY7_t8KEavMn1f2TxM7f2ZZ1YZpisQ-hbzS-H0iW1fQ@mail.gmail.com> |
On Mon, Apr 24, 2017 at 3:53 AM, L. David Baron <[email protected]> wrote: > This makes me wonder: could we become more suspicious (in terms of > UI indications) of sites where the script changes between different > parts of the hostname (or eTLD+1), i.e., move towards expecting that > non-Latin domain names will be using a non-Latin TLD? > It would be nice and sometimes we could (I think I read that the .ru registrar only allows ascii domains, and the Cyrillic version of their ccTLD only has Cyrillic domains) but not in other cases. Of course .com is a complete mess, but even with more thoughtful registries you have .eu which explicitly accepts Cyrillic domains because Bulgaria is an EU member. That would come back around to a TLD whitelist (or blacklist?) scheme. -Dan Veditz _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security