Hacker News new | ask | show | jobs
by beagle3 4336 days ago
What are the security implications?

Does anyone know how canonicalization is handled? Does every mail program need to know how to precompose/decompose etc? How do you protect against impersonation using look-alike letters?

This is, as far as I know, not yet a solved problem even at the domain name level[0], and it's likely to open a whole new can of worms at the account level.

[0] http://en.wikipedia.org/wiki/IDN_homograph_attack

2 comments

Something like hashing or petnames, maybe.
One small fix would be to mark non-latin characters in an email address.
I have a "non-latin" letter in my surname, and I find highlighting it as somehow wrong or suspicious offensive.