-
Notifications
You must be signed in to change notification settings - Fork 7
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Describe mitigations for homoglyph/typo-squatting attacks and name duplication #128
Conversation
docs/modules/ROOT/pages/index.adoc
Outdated
@@ -904,11 +904,22 @@ Any content including, but not limited to the _<<_named_actor,named actor’s>>_ | |||
|
|||
The effectiveness of such attacks will necessarily be dependent on the language and other related development tooling in use for any given implementation. Beyond reminding implementors that parsing and validation errors are a likely attack surface, it is outside the scope of this specification to provide language-specific guidance. | |||
|
|||
==== Homoglyph and typo-squatting attacks | |||
==== Homoglyph and typo-squatting attacks and name duplication |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"Name collisions"? - Duplication suggests putting it twice?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Speaking of putting things twice, I just realized we have an existing "Name collisions" section. I've cross-referenced the two sections and removed this part of this header.
@@ -892,7 +892,7 @@ NOTE: The above questions target name collisions for individuals, but the same q | |||
|
|||
Whether a name collision is intentional or coincidental, careful attention should be paid as to how to gather the appropriate technical details to allow differentiate distinct _<<_named_actor,named actors>>_ and to meaningfully expose that differentiation in user experience. | |||
|
|||
NOTE: TO DO (link:https://github.com/creator-assertions/identity-assertion/issues/115[issue #115]): Think through identity presentation so as to provide meaningful differentiation between similarly-named _<<_actor,actors>>._ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Removed this TO DO link since we moved #115 to post-1.0 milestone.
Closes #117.