waving android

I am currently a software engineer at Google, where as a member of the Android platform team I build frameworks and user interfaces.

The blog here at is mostly historical; you can find more recent posts on .

IDN considered harmful.

February 7th, 2005

[2:39] <dsandler> So, I don’t know how to respond to this: http://www.shmoo.com/idn/

[2:40] <dsandler> (the hack: using the Cyrillic ‘a’, which looks exactly like the Roman ‘a’, as the second letter in “paypal.com”)

[2:40] <dsandler> phished!

[2:41] <dsandler> So, what’s the answer here?  Eliminate PunyCode encoding of so-called “international domain names”?  Seems draconian.  What you’d really want to do is come up with some way to trust a website above and beyond the orthographic appearance of its domain.

newer: older: