Re: Let's try to be productive...
Barry Shein <[email protected]> Mon, 6 Jan 2014 15:34:41 -0500
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On January 6, 2014 at 13:43 [email protected] (Richard Clayton) wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > In message <[email protected]>, Barry Shein > <[email protected]> writes > > >What has changed recently in the spam-o-verse? > > DMARC ... now whether is has made a difference is a reasonable > question for research to answer ! That's a good topic. I suppose a next pass for a taxonomy is matching up current efforts in each area. Even if imperfect it'd be a useful reference. > >One obvious and well-discussed problem is homograph fraud. > > which, to a first approximation, is non-existent -- the APWG six monthly > reports show that the use of non-latin domain names (at all, let alone > for misleading) has only ever been countable on the fingers of one or > two hands ... It's still rather new. Yes it's probably more practical to be reactive but we need to know where to look and how to determine whether something is within our stated purview and of course whether that purview needs to be modified if not. > where one _does_ see homographs is in people trying to disguise phishing > web pages so that the text looks like "PayPal" but a simple-minded > content scanner (operated by the web hosting company perhaps) will not > detect the page to be a phish ... Ρ is useful for that... I agree, that's the sort of thing I was getting at. There's also all that work going on largely in Kanji or Hanzi, the Chinese character set(s). Dennis Jennings has been working on this w/in ICANN for about two years or so. There are a lot of domain strings possible in at least East Asian ideographic scripts which are for all practical purposes analogous to Latin-1's notion of upper/lower case. That is, they should be treated identically. Or so it's been argued successfully by people with a lot more expertise in this area than I have. Wode putonghua shi bu hao ba! ICANN's concern is more in the realm of, like upper/lower case, if you register one should you automatically or implictly be registered for all of them? Or should they be taken off the market perhaps offering a right of first refusal? etc etc etc. But it's much more complicated, you can't just add/sub ASCII space :-) Well, none of that is directly a concern of spam but where there is a possibility of confusion there's a possibility of fraud. And it does raise the issue of how do we (and should we?) possibly cover an emerging multi-script world? If nothing else it would be nice to at least acknowledge it where relevant to other efforts and not be accused of being overly LATIN-1-centric. -- -Barry Shein The World | [email protected] | http://www.TheWorld.com Purveyors to the Trade | Voice: 800-THE-WRLD | Dial-Up: US, PR, Canada Software Tool & Die | Public Access Internet | SINCE 1989 *oo* - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org