7 ms·
An important benefit of punycode is that it provides some protection against homograph attacks [0]. There are so many similar-looking characters in Unicode tha
by drewmate 8y ago
An important benefit of punycode is that it provides some protection against homograph attacks [0]. There are so many similar-looking characters in Unicode that it seems reasonable to trim the allowed characters to a subset. Of course it's a compromise and ASCII's not perfect, but it's a lot easier to spot g00gle.com compared to gооgle.com.
[0] https://en.wikipedia.org/wiki/IDN_homograph_attack https://en.wikipedia.org/wiki/IDN_homograph_attack
- deleted 8y ago[deleted]
- kuschku 8y agoAt the same time there's sites like flüge.de which is not reachable under any domain except the unicode domain, and while ü could be written as ue, fluege.de is already owned by a competitor. Over time, punycode is going to cause more phishing problems in non-ascii countries than it's going to solve, because users aren't going to see a difference between xn-blabla.de and xn-blablu.de if all domains are unreadable to them.
- btown 8y agoI feel like this is a browser UX problem, right? A browser designed to prevent phishing of readers of both ASCII and non-ASCII languages might display both the punycode and unicode versions of a website, and if a heuristic is detected that a homograph is used that would otherwise result in an Alexa Top 100k site, display a dialog to warn against a phishing attack. (Your flüge.de example shouldn't trigger that warning, for instance.) https://github.com/phishai/phish-protect https://github.com/phishai/phish-protect is an attempt to do this, but I think there's a better middle ground for international users that doesn't simply block-by-default all punycode domains.