Re: Unicode domain names issue (Encrypting a "fake" domain name)

Daniel Veditz <[email protected]> Tue, 25 Apr 2017 18:24:26 -0700
Newsgroups gmane.comp.mozilla.security
Message-ID <CADYDTCDCY7_t8KEavMn1f2TxM7f2ZZ1YZpisQ-hbzS-H0iW1fQ@mail.gmail.com>
On Mon, Apr 24, 2017 at 3:53 AM, L. David Baron <[email protected]> wrote:

> This makes me wonder:  could we become more suspicious (in terms of
> UI indications) of sites where the script changes between different
> parts of the hostname (or eTLD+1), i.e., move towards expecting that
> non-Latin domain names will be using a non-Latin TLD?
>

​It would be nice and sometimes we could (I think I read that the .ru
registrar only allows ascii domains, and the Cyrillic version of their
ccTLD only has Cyrillic domains) but not in other cases. Of course .com is
a complete mess, but even with more thoughtful registries you have .eu
which explicitly accepts Cyrillic domains because Bulgaria is an EU member.

That would come back around to a TLD whitelist (or blacklist?) scheme.

-Dan Veditz
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security