Hacker News new | ask | show | jobs
by hartz 3353 days ago
I think it would be useful to implement some security against this at the registrar level (until a better fix is more broadly available). For example, if I'm registering "epic.com" (the ASCII version), the registrar could suggest that I also register "epic.com" (the Cyrillic version), or vice versa. This could at least help site owners avoid phishing attacks on their own domains.

Unfortunately, this would require all the big registrars to be on board for it to actually be effective.

2 comments

In order to prevent anything, you would need to register every combination of latin and cyrilic. For a short domain like "epic" this constitutes 16 domains. For a 7 character domain it would be 128 domains. In either case it would be a heavy multiplier on the base cost of the domain.
I don't think you're allowed to combine Latin and Cyrillic in a domain name. The issue is mainly that the two sets have identical looking characters.
If you remind them there would be an increase in sales - especially if they point out the danger and then upsell the ASCII version - then they'd like implemenet it; at least they should A/B test it. Not great - but that's how I see them doing it.