[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-bugs] #21961 [Applications/Tor Browser]: should torbrowser enable network.IDN_show_punycode by default?
#21961: should torbrowser enable network.IDN_show_punycode by default?
--------------------------------------+------------------------------
Reporter: cypherpunks | Owner: tbb-team
Type: enhancement | Status: needs_review
Priority: Immediate | Milestone:
Component: Applications/Tor Browser | Version:
Severity: Major | Resolution:
Keywords: | Actual Points:
Parent ID: | Points:
Reviewer: | Sponsor:
--------------------------------------+------------------------------
Comment (by adrelanos):
A good title would also be {{{very hard to notice Phishing Scam - Firefox
/ Tor Browser URL not showing real Domain Name - Homograph attack
(Punycode)}}}.
https://www.xn--80ak6aa92e.com/ shows up as apple.com. Even including
green SSL lock. But it is a demonstration, proof of concept of a phishing
side by a security researcher.
`https://www.xn--80ak6aa92e.com/` shows up as `https://www.apple.com`.
Screenshot:
https://www.xudongz.com/static/942a1d48cb68b8678e2713249d1ae7ceaf9fa4c39767562a8caf6cc856626160.png
References:
* https://thehackernews.com/2017/04/unicode-Punycode-phishing-attack.html
* https://www.xudongz.com/blog/2017/idn-phishing/
I can’t even find Mozilla’s rationale for being adamant about this. 3
years ago they wrote:
> We now have an FAQ which makes our position clear:
> https://wiki.mozilla.org/IDN_Display_Algorithm_FAQ
Nowadays this wiki page is empty (links to another empty wiki page).
Please consider setting {{{network.IDN_show_punycode}}} to {{{true}}} by
default.
I think the status of this ticket {{{needs_review}}} may be wrong.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/21961#comment:18>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs