4 ms·
No it isn't, the URL is unreliable source of truth with Unicode spoofing attacks and things like that. Safari only shows the domain at this point; the URL is a
by nilved 9y ago
No it isn't, the URL is unreliable source of truth with Unicode spoofing attacks and things like that. Safari only shows the domain at this point; the URL is an unimportant implementation detail.
- etplayer 9y agoIt would be cool if browsers could highlight URLs that contain the kind of characters which are commonly used to spoof, though I suppose it would lead people to a false sense of security.
- noisem4ker 9y agoJust set your browser to always show punycode. On Firefox, network.IDN_show_punycode = true URLs are no place for unicode characters to hide in. An xn-- prefix is all the warning you need.
- bzbarsky 9y agoYour claims are false for the majority of the world's population (which lives in non-English speaking countries and may well want to visit sites whose names make sense in their own language).
- eeZah7Ux 9y agoThat's why Firefox detects if the URL mixes together symbols from different languages: https://wiki.mozilla.org/IDN_Display_Algorithm https://wiki.mozilla.org/IDN_Display_Algorithm Much better than showing punycode all the time.
- kuschku 9y agoSo sites such as bücher.de (I originally had a link here to the site, but HN punycodes that: http://xn--bcher-kva.de/ http://xn--bcher-kva.de/ ) shouldn’t exist? That’s a very america-centric world, it’s like enforcing only US-ASCII on all websites. Most of the world doesn’t speak English, and browsers showing domains punycoded leads to mistrust, especially if it’s a legitimate retailer (the one mentioned above actually added a redirect to a romanized version of the URL due to that)
- sp332 9y agoFirefox [0] and Chrome [1] have policies for when to show Unicode and when to show raw punycode. You can also set flags to force them to show punycode all the time. [0] https://wiki.mozilla.org/IDN_Display_Algorithm#Algorithm https://wiki.mozilla.org/IDN_Display_Algorithm#Algorithm [1] https://www.chromium.org/developers/design-documents/idn-in-google-chrome https://www.chromium.org/developers/design-documents/idn-in-...
- wongarsu 9y agoCyrillic Er looks exactly like Latin P, so writing apple with Cyrillic "Er"s would likely be spoofing. But if you highlight all instances of Cyrillic Er, you also have to highlight every P, since the URL of a Russian bank spelt with Cyrillic Er could be spoofed with Latin P. In the end, you would just highlight nearly everything. A more useful approach would be to highlight when you switch script inside a domain name. That seems to be what firefox does for non-whitelisted domains (with some more rules to allow eg www.stマイクロ.jp (ST Microelectronics in japanese))
- caiob 9y agoHow would you differentiate say: "http://googlemail.buyviagra.com" http://googlemail.buyviagra.com" From: "https://mail.google.com" https://mail.google.com" If they looked the same.
- deleted 9y ago[deleted]
- pvdebbe 9y agoUrls to be shown punycoded at all times. Not pretty but might be necessary. This should gain some momentum before emoji urls go mainstream
- kuschku 9y agoYou mean, before the 90% of the global population that doesn’t speak english as first language goes online, right? Because the #1 use case for this isn’t emoji, but sites such as bücher.de (I originally had a link here to the site, but HN punycodes that: http://bücher.de/ http://xn--bcher-kva.de/ ) (which nowadays had to redirect, because the URL displayed in punycode made people believe it was a phishing attempt)