dsandler.org

IDN considered harmful.

February 7th, 2005

[2:39] <dsandler> So, I don’t know how to respond to this: http://www.shmoo.com/idn/

[2:40] <dsandler> (the hack: using the Cyrillic ‘a’, which looks exactly like the Roman ‘a’, as the second letter in “paypal.com”)

[2:40] <dsandler> phished!

[2:41] <dsandler> So, what’s the answer here?  Eliminate PunyCode encoding of so-called “international domain names”?  Seems draconian.  What you’d really want to do is come up with some way to trust a website above and beyond the orthographic appearance of its domain.

Both comments and pings are currently closed.

Comments are closed.

newer: YURL, PetNames, etc. older: Adam Cadre on Videophones.