Re: upstream and downstream

Gervase Markham <[email protected]> Mon, 21 Feb 2005 00:00:26 +0000
Newsgroups gmane.ietf.idn
Organization mozilla.org
Message-ID <[email protected]>
Adam M. Costello wrote:
> I'm with you both.  I wanted the IDN working group to define a subset,
> but ultimately I was persuaded that it was not feasible for the IETF to
> reach consensus on such a subset, and that subsetting could and should
> be done on a per-registry basis, inside the registry rather than the
> applications.  But the slash-homograph attack now makes that approach
> (in its pure form) appear hopeless.

Just to delurk for a moment... I'm currently kicking around ideas here 
at mozilla.org for dealing with this issue. We hope to be able to 
present a proposal soon.

What someone posted a day ago about "/" homograph attacks has meant that 
one thing we plan to do is have a short number of characters which are 
completely forbidden in IDN domains at any level - in that, mozilla.org 
products would refuse to recognise IDNs containing them.

My initial list includes the homographs of ":", ".", "/" and probably 
"\" too, plus all the space characters.

Of course, there may be some good reason why this doesn't fly.

Gerv

P.S. Of course, the slash homograph attack wouldn't fool the Firefox SSL 
domain security indicator anyway, which would still display the entire 
domain, fake slashes and all.