πŸ“£ Post by bagder

2024-12-14

Remember: IDN is crazy. And just not just a little.
daniel.haxx.se/blog/2022/12/14…

bagder

https://mastodon.social/@bagder/113650752304420701

https://daniel.haxx.se/blog/2022/12/14/idn-is-crazy/

πŸ’¬ Replies

2024-12-14 bortzmeyer ┃ 1πŸ”— 2#️ 2πŸ’¬

@bagder For once, you write wrong things. Just one: the "crazy" example you show is disallowed since IDN does not allow many of these characters: afnic.fr/en/observatory-and-re…
#IDN #Unicode

2024-12-14 pmevzek ┃ 2πŸ”—

@bagder IDNs use IDNA not just punycode. While punycode is an algorithm that can encode any Unicode character into ASCII, IDNA adds further rules and hence not all characters can end up in a […]

2024-12-14 mort

@bagder The really sad part? All this complexity, all this surface area for nasty bugs, all these opportunities for social engineering.. and they don't even work for their intended purpose!! […]

2024-12-14 jk ┃ 1πŸ”—

@bagder
Hey, and this does not include the shenanigans with right-to-left-override and its left-to-right counterpart.
[…]

2024-12-14 pemensik ┃ 1πŸ’¬

@bagder it would be fair if you used for homographs examples domains, where registrars allow mixing of such letters. I am quite certain .com is not such domain, doubt .se also. Registrars are […]

2024-12-14 n

@bagder
Nice read.
[…]

2024-12-14 Flexheat ┃ 1πŸ”—

@bagder
Get 50% Off FlexHeat Portable Heater – Stay Warm & Save Big! Enjoy efficient, portable heating this winter with our limited-time offer! - bit.ly/4flo5Lt

2024-12-14 anopka ┃ 1πŸ’¬

@bagder IDN-based phishing is the reason I turned of punycode translation in Firefox. So, whenever I see a URL beginning with "xn--" I know this is most likely a phishing attempt.
And if one […]

2024-12-14 waldschnecke

@bagder and once you start thinking about anti-malware and potential false positives… and/or a clean implementation…

────

View thread

────

πŸ“‘ Local feed

πŸ•οΈ Communities

πŸ”₯ Hashtags

πŸ”Ž Search posts

πŸ”‘ Sign in

πŸ“Š Status

πŸ›Ÿ Help