[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-bugs] #21961 [Applications/Tor Browser]: should torbrowser enable network.IDN_show_punycode by default?
#21961: should torbrowser enable network.IDN_show_punycode by default?
--------------------------------------+------------------------------
 Reporter:  cypherpunks               |          Owner:  tbb-team
     Type:  enhancement               |         Status:  needs_review
 Priority:  Immediate                 |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Major                     |     Resolution:
 Keywords:                            |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+------------------------------
Comment (by adrelanos):
 A good title would also be {{{very hard to notice Phishing Scam - Firefox
 / Tor Browser URL not showing real Domain Name - Homograph attack
 (Punycode)}}}.
 https://www.xn--80ak6aa92e.com/ shows up as apple.com. Even including
 green SSL lock. But it is a demonstration, proof of concept of a phishing
 side by a security researcher.
 `https://www.xn--80ak6aa92e.com/` shows up as `https://www.apple.com`.
 Screenshot:
 https://www.xudongz.com/static/942a1d48cb68b8678e2713249d1ae7ceaf9fa4c39767562a8caf6cc856626160.png
 References:
 * https://thehackernews.com/2017/04/unicode-Punycode-phishing-attack.html
 * https://www.xudongz.com/blog/2017/idn-phishing/
 I can’t even find Mozilla’s rationale for being adamant about this. 3
 years ago they wrote:
 > We now have an FAQ which makes our position clear:
 > https://wiki.mozilla.org/IDN_Display_Algorithm_FAQ
 Nowadays this wiki page is empty (links to another empty wiki page).
 Please consider setting {{{network.IDN_show_punycode}}} to {{{true}}} by
 default.
 I think the status of this ticket {{{needs_review}}} may be wrong.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/21961#comment:18>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs