3 ms·
As much as I like Firefox, I don't really agree with their reason for not considering this to be a bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1332714 htt
by gommm 9y ago
As much as I like Firefox, I don't really agree with their reason for not considering this to be a bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1332714 https://bugzilla.mozilla.org/show_bug.cgi?id=1332714
> Indeed. Our IDN threat model specifically excludes whole-script homographs, because they can't be detected
> programmatically and our "TLD whitelist" approach didn't scale in the face of a large number of new TLDs. If you are
> buying a domain in a registry which does not have proper anti-spoofing protections (like .com), it is sadly the
> responsibility of domain owners to check for whole-script homographs and register them.
> We can't go blacklisting standard Cyrillic letters.