Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Link preview should show punycode encoded domain name (not decoded IDN) #1004

Open
bsclifton opened this issue Sep 7, 2018 · 1 comment
Open

Comments

@bsclifton
Copy link
Member

@bsclifton bsclifton commented Sep 7, 2018

Opening per comment in brave/browser-laptop#5220 on browser-laptop

When you hover over a link on a page in browser-laptop, it shows the punycode encoded domain name (example here is an IDN being hovered over w/ mouse in browser-laptop):
screenshot 2016-10-28 15 54 52

@diracdeltas notes:

We display punycode-only to prevent homograph attacks, see for instance https://thehackernews.com/2017/04/unicode-Punycode-phishing-attack.html. Google has some standards for what unicode characters should be displayed as punycode. https://www.chromium.org/developers/design-documents/idn-in-google-chrome

@bsclifton bsclifton added this to the Triage Backlog milestone Sep 7, 2018
@bsclifton bsclifton modified the milestones: Triage Backlog, 2.x Backlog Sep 7, 2018
@bbondy bbondy modified the milestones: 2.x Backlog, 1.x Backlog Sep 30, 2018
@rebron rebron modified the milestone: 1.x Backlog Feb 7, 2019
@tomlowenthal
Copy link
Member

@tomlowenthal tomlowenthal commented Aug 6, 2019

This may already be resolved by work in Chrome.

@tomlowenthal tomlowenthal added priority/P4 and removed sec-low labels Aug 6, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
4 participants
You can’t perform that action at this time.