[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [idn] nameprep2 and the slash homograph issue
Gervase Markham wrote:
While security-conscious users are always less at risk than ordinary
users, thinking in terms of a tool is IMO wrong.
Perhaps I was wrong to use the word "tool". There is a fundamental
tension between security and user-friendliness. Some applications and
vendors have a history of making their user interfaces *too* friendly,
thereby neglecting to warn users of potential security risks. Other
vendors have tried hard to strike a balance between security and
seamlessness. I believe Netscape and Mozilla have been in this camp
since Day One.
I hope that mozilla.org will deploy a better solution than the TLD and
domain black/whitelists that have been discussed.
It would offer to display domain names in the
safe order, i.e. left-to-right for users whose main language is
left-to-right.
The problem this is supposed to mitigate is mitigated in Firefox by the
domain-only indicator in the status bar.
I just double-checked Firefox 1.0.1, and it just says "Done" at the
lower left. Then I tried a secure (https) site, and, lo and behold, I
saw the "domain-only" indicator at the lower right, next to the padlock
icon. This is very good news (to me). And thank you for educating this
particular user (me) about this security issue. As I have often said,
education is key.
A couple of questions/comments: It might be nice to have this
domain-only display even for non-secure sites (http). Also, do you know
what happens if the domain name is very long? Finally, do you have any
thoughts about the slash homograph problem? Thanks.
In addition, such a tool would offer to display domain names in a
clear font, unlike the sans-serif that is commonly used today. This
would make the distinction between lowercase l and digit 1 clearer.
Assuming we could determine such a font, why would we not always use it?
Why wait for a tool to be deployed?
Indeed, why wait? I filed a bug a while ago:
https://bugzilla.mozilla.org/show_bug.cgi?id=282079
My feeling is that a sans-serif font (such as Arial) places the
characters too close to each other and does not have the serifs that
often serve to distinguish the characters better. How about a fixed
width font with serifs, such as Courier New?
Erik