3 ms·
It would be cool if browsers could highlight URLs that contain the kind of characters which are commonly used to spoof, though I suppose it would lead people to
by etplayer 9y ago
It would be cool if browsers could highlight URLs that contain the kind of characters which are commonly used to spoof, though I suppose it would lead people to a false sense of security.
- noisem4ker 9y agoJust set your browser to always show punycode. On Firefox, network.IDN_show_punycode = true URLs are no place for unicode characters to hide in. An xn-- prefix is all the warning you need.
- bzbarsky 9y agoYour claims are false for the majority of the world's population (which lives in non-English speaking countries and may well want to visit sites whose names make sense in their own language).
- eeZah7Ux 9y agoThat's why Firefox detects if the URL mixes together symbols from different languages: https://wiki.mozilla.org/IDN_Display_Algorithm https://wiki.mozilla.org/IDN_Display_Algorithm Much better than showing punycode all the time.
- kuschku 9y agoSo sites such as bücher.de (I originally had a link here to the site, but HN punycodes that: http://xn--bcher-kva.de/ http://xn--bcher-kva.de/ ) shouldn’t exist? That’s a very america-centric world, it’s like enforcing only US-ASCII on all websites. Most of the world doesn’t speak English, and browsers showing domains punycoded leads to mistrust, especially if it’s a legitimate retailer (the one mentioned above actually added a redirect to a romanized version of the URL due to that)
- sp332 9y agoFirefox [0] and Chrome [1] have policies for when to show Unicode and when to show raw punycode. You can also set flags to force them to show punycode all the time. [0] https://wiki.mozilla.org/IDN_Display_Algorithm#Algorithm https://wiki.mozilla.org/IDN_Display_Algorithm#Algorithm [1] https://www.chromium.org/developers/design-documents/idn-in-google-chrome https://www.chromium.org/developers/design-documents/idn-in-...
- wongarsu 9y agoCyrillic Er looks exactly like Latin P, so writing apple with Cyrillic "Er"s would likely be spoofing. But if you highlight all instances of Cyrillic Er, you also have to highlight every P, since the URL of a Russian bank spelt with Cyrillic Er could be spoofed with Latin P. In the end, you would just highlight nearly everything. A more useful approach would be to highlight when you switch script inside a domain name. That seems to be what firefox does for non-whitelisted domains (with some more rules to allow eg www.stマイクロ.jp (ST Microelectronics in japanese))