1 Jul 2005 12:19
Re: Fwd: Notification re UTR #36, Security Issues
Jeff Williams <jwkckid1 <at> ix.netcom.com>
2005-07-01 10:19:17 GMT
2005-07-01 10:19:17 GMT
Ben and all, It may be advisable that the FTC and other EU equivalents should be notified of this so as to get at least a warning more broadly decimated... Ben Laurie wrote: > Paul Hoffman wrote: > >> Due to computer security issues, a set of guidelines is being > >> drafted that can impact the use of future International Domain > >> Names (i.e., http://m¸ller.de/ ) and identifiers. The computer > >> security issues that have arisen involve spoofing of letters or > >> numbers (e.g., in a recent case, unsuspecting users were sending > >> credit card information to "PayPal.com" which was spelled with a > >> capital "I" in place of lowercase "L", because the two are not > >> visibly distinct in some fonts). Similarly Cyrillic or Greek > >> letters could be used in lieu of similar looking Latin letters in > >> domain names. > > I'd note that this first issue is _not_ an IDN issue, but applies to > traditional domain names. This would appear to have rather serious > impact on the DNS, if we decide to take this report seriously (I'm > assuming it includes recommendations that related to I vs. l, since I > have not been able to actually reach the site since I saw this post). > > Of course, what this is really pointing to is what we all surely know: > the domain name is a really stupid place to base trust. Is there any > interest in fixing this fundamental issue? > > Cheers,(Continue reading)
RSS Feed