[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [idn] IDN security and ACE leakage
----- Original Message -----
From: "Martin Duerst" <duerst@w3.org>
> >How can we distinguish katakana 'ro-to.com' and hangul 'ma.com'
> >if we haven't learn japanese and korean ?
>
> Well, the main point will be spacing. There are also other font
> differences. But these are made for people who write katakana or
> hangul, not for those that don't.
>
In most cases, the problems come from the similarities, not from spacing.
katakana 'ka' and chinese letter 'power(U+529B)' look the same.
Begali numeral '4' and latin '8' looks the same.
What if japanese or korean customers send us with their IDN-email
addresses and we don't know japanese and korean letters and theri
spacing sematics ?
Still I cannot distinguish between Bengali numerial '4' and latin '8'.
How can we prevent malicious attempts to
forge similiarly-looking but different domains ?
>
> Regards, Martin.
>