You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Some Chinese websites utilize Punycode to make the link display properly. I'd say maybe expose it in preferences at most but keep it off by default. Most websites display links with xn-- anyways.
Some Chinese websites utilize Punycode to make the link display properly. I'd say maybe expose it in preferences at most but keep it off by default. Most websites display links with xn-- anyways.
I oppose against this. To be honest, how many websites use CJK characters as the domain name? Even if so, almost all of those sites have their primary domain names in ASCII alphabets.
Currently,
https://www.xn--80ak6aa92e.com
displays ashttps://www.аррӏе.com
by default in the URL bar.Nowadays, only Firefox and all of its derived browsers (all are latest versions) are affected by this loophole.
Details - https://www.xudongz.com/blog/2017/idn-phishing/
So I suggest to set
network.IDN_show_punycode
totrue
in the initial configs.The text was updated successfully, but these errors were encountered: