Bugtraq mailing list archives
Re: Thoughts and a possible solution on homograph attacks
From: Valdis.Kletnieks () vt edu
Date: Tue, 15 Mar 2005 16:09:31 -0500
On Tue, 15 Mar 2005 12:27:09 +0100, Riccardo Murri said:
I would rather suggest that the string comparison function used in IDN takes "homograph caracters"[1] into account: just like the current DNS considers 'a' == 'A', the IDN DNS should consider "LATIN SMALL LETTER a" == "CYRILLIC SMALL LETTER a" == "CYRILLIC CAPITAL LETTER A" == "GREEK CAPITAL LETTER A"[2], and similarly for the other homograph chars.
The problem here is that defining what characters are "similar" enough to be homographs is a very fuzzy concept. Glyphs that may look similar on a 1600x1200 display on my laptop may not look similar when the *same exact* 1600x1200 is being displayed on the 21" monitor hanging off my docking station. Also, the point size in use may matter - that macron that's easily visible at 15pt may be invisible at 11pt. Bitmap and outline fonts will have different behaviors in this regard, and anti-aliasing adds another twist to the equations.... And even if you program all *that* sort of knowledge in, there's no way in the near future that the software will know if I'm wearing my contacts or if I'm wearing my glasses, and if I'm wearing contacts, if I happen to have my reading glasses handy.....
Attachment:
_bin
Description:
Current thread:
- Re: thoughts and a possible solution on homograph attacks, (continued)
- Re: thoughts and a possible solution on homograph attacks James Youngman (Mar 07)
- Re: thoughts and a possible solution on homograph attacks Thomas Wana (Mar 07)
- Re: thoughts and a possible solution on homograph attacks Benjamin Franz (Mar 07)
- Re: thoughts and a possible solution on homograph attacks Dmitry Yu. Bolkhovityanov (Mar 08)
- RE: thoughts and a possible solution on homograph attacks Scovetta, Michael V (Mar 07)
- Re: thoughts and a possible solution on homograph attacks Mike Nice (Mar 08)
- Re: houghts and a possible solution on homograph attacks Sven Putteneers (Mar 08)
- Re: houghts and a possible solution on homograph attacks Nick FitzGerald (Mar 10)
- Re: Thoughts and a possible solution on homograph attacks Paul Smith (Mar 12)
- Re: Thoughts and a possible solution on homograph attacks Riccardo Murri (Mar 15)
- Re: Thoughts and a possible solution on homograph attacks Valdis . Kletnieks (Mar 15)
- Re: Thoughts and a possible solution on homograph attacks khockenb (Mar 16)
- Re: Thoughts and a possible solution on homograph attacks Riccardo Murri (Mar 16)
- Re: Thoughts and a possible solution on homograph attacks Nick FitzGerald (Mar 22)