Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Suggestion - Fix punycode by default #149

Open
win98se opened this issue Mar 7, 2024 · 2 comments
Open

Suggestion - Fix punycode by default #149

win98se opened this issue Mar 7, 2024 · 2 comments

Comments

@win98se
Copy link

win98se commented Mar 7, 2024

Currently, https://www.xn--80ak6aa92e.com displays as https://www.аррӏе.com by default in the URL bar.

Nowadays, only Firefox and all of its derived browsers (all are latest versions) are affected by this loophole.

Details - https://www.xudongz.com/blog/2017/idn-phishing/

So I suggest to set network.IDN_show_punycode to true in the initial configs.

@aaronliu0130
Copy link

Some Chinese websites utilize Punycode to make the link display properly. I'd say maybe expose it in preferences at most but keep it off by default. Most websites display links with xn-- anyways.

@win98se
Copy link
Author

win98se commented Mar 8, 2024

Some Chinese websites utilize Punycode to make the link display properly. I'd say maybe expose it in preferences at most but keep it off by default. Most websites display links with xn-- anyways.

I oppose against this. To be honest, how many websites use CJK characters as the domain name? Even if so, almost all of those sites have their primary domain names in ASCII alphabets.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants