Re: Let's try to be productive...

Barry Shein <[email protected]> Mon, 6 Jan 2014 15:34:41 -0500
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On January 6, 2014 at 13:43 [email protected] (Richard Clayton) wrote:
 > -----BEGIN PGP SIGNED MESSAGE-----
 > Hash: SHA1
 > 
 > In message <[email protected]>, Barry Shein
 > <[email protected]> writes
 > 
 > >What has changed recently in the spam-o-verse?
 > 
 > DMARC  ...  now whether is has made a difference is a reasonable
 > question for research to answer !

That's a good topic.

I suppose a next pass for a taxonomy is matching up current efforts in
each area. Even if imperfect it'd be a useful reference.

 > >One obvious and well-discussed problem is homograph fraud.
 > 
 > which, to a first approximation, is non-existent -- the APWG six monthly
 > reports show that the use of non-latin domain names (at all, let alone
 > for misleading) has only ever been countable on the fingers of one or
 > two hands ...

It's still rather new.

Yes it's probably more practical to be reactive but we need to know
where to look and how to determine whether something is within our
stated purview and of course whether that purview needs to be modified
if not.

 > where one _does_ see homographs is in people trying to disguise phishing
 > web pages so that the text looks like "PayPal" but a simple-minded
 > content scanner (operated by the web hosting company perhaps) will not
 > detect the page to be a phish ... &Rho; is useful for that...

I agree, that's the sort of thing I was getting at.

There's also all that work going on largely in Kanji or Hanzi, the
Chinese character set(s). Dennis Jennings has been working on this
w/in ICANN for about two years or so.

There are a lot of domain strings possible in at least East Asian
ideographic scripts which are for all practical purposes analogous to
Latin-1's notion of upper/lower case.

That is, they should be treated identically.

Or so it's been argued successfully by people with a lot more
expertise in this area than I have. Wode putonghua shi bu hao ba!

ICANN's concern is more in the realm of, like upper/lower case, if you
register one should you automatically or implictly be registered for
all of them? Or should they be taken off the market perhaps offering a
right of first refusal? etc etc etc.

But it's much more complicated, you can't just add/sub ASCII space :-)

Well, none of that is directly a concern of spam but where there is a
possibility of confusion there's a possibility of fraud.

And it does raise the issue of how do we (and should we?) possibly
cover an emerging multi-script world?

If nothing else it would be nice to at least acknowledge it where
relevant to other efforts and not be accused of being overly
LATIN-1-centric.

-- 
        -Barry Shein

The World              | [email protected]           | http://www.TheWorld.com
Purveyors to the Trade | Voice: 800-THE-WRLD        | Dial-Up: US, PR, Canada
Software Tool & Die    | Public Access Internet     | SINCE 1989     *oo*
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org