[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #21961 [Applications/Tor Browser]: should torbrowser enable network.IDN_show_punycode by default?



#21961: should torbrowser enable network.IDN_show_punycode by default?
--------------------------------------+------------------------------
 Reporter:  cypherpunks               |          Owner:  tbb-team
     Type:  enhancement               |         Status:  needs_review
 Priority:  Immediate                 |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Major                     |     Resolution:
 Keywords:                            |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+------------------------------

Comment (by adrelanos):

 A good title would also be {{{very hard to notice Phishing Scam - Firefox
 / Tor Browser URL not showing real Domain Name - Homograph attack
 (Punycode)}}}.

 https://www.xn--80ak6aa92e.com/ shows up as apple.com. Even including
 green SSL lock. But it is a demonstration, proof of concept of a phishing
 side by a security researcher.

 `https://www.xn--80ak6aa92e.com/` shows up as `https://www.apple.com`.

 Screenshot:

 https://www.xudongz.com/static/942a1d48cb68b8678e2713249d1ae7ceaf9fa4c39767562a8caf6cc856626160.png

 References:

 * https://thehackernews.com/2017/04/unicode-Punycode-phishing-attack.html
 * https://www.xudongz.com/blog/2017/idn-phishing/

 I can’t even find Mozilla’s rationale for being adamant about this. 3
 years ago they wrote:

 > We now have an FAQ which makes our position clear:
 > https://wiki.mozilla.org/IDN_Display_Algorithm_FAQ

 Nowadays this wiki page is empty (links to another empty wiki page).

 Please consider setting {{{network.IDN_show_punycode}}} to {{{true}}} by
 default.

 I think the status of this ticket {{{needs_review}}} may be wrong.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/21961#comment:18>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs