|
|
|
|
|
by dmckeon
3356 days ago
|
|
Can a browser could track how many language/character sets are
typically used by a browser profile, and warn the user when they are
about to use a new, previously unused set, rather than waving the
duty off as the "responsibility of domain owners"? With now over 1000 top-level domains, and however many homographic
matches among character sets, expecting people to register dozens of
matching domains seems unrealistic. |
|
I think that, plus a "you have never visited this site before" kind of warning could go a long way towards combating these kinds of attacks.
I think the real devil is going to be in the UI. You don't want to make it overly scary (otherwise you penalize domains which use some unicode characters correctly), but it can't be so unnoticable that you won't be able to tell when it matters.