Re: Unicode and Security

From: Elliotte Rusty Harold (elharo@metalab.unc.edu)
Date: Thu Feb 07 2002 - 10:34:20 EST


At 11:54 AM -0700 2/6/02, John H. Jenkins wrote:

>Right, but right now is that people are typing things like www.whitehouse.
>com instead of www.whitehouse.gov (or, for that matter,
>www.unicode.com). How likely is it that someone will accidentally
>type www.s?mple.com instead of www.sample.com?
>

Somebody could easily follow a link to such a site, possibly through
a pop-up or some spyware installed on their system, and never realize
they weren't at the actual site.

Security and spoofing are very real issues that were never, as far as
I know, even considered in the design of Unicode. It's unclear
whether or not the problem can be fixed now. The Unicode community
has been in serious denial about this for some time. That other
technologies also have or contribute to these problems in no way
absolves Unicode of its problems.

-- 

+-----------------------+------------------------+-------------------+ | Elliotte Rusty Harold | elharo@metalab.unc.edu | Writer/Programmer | +-----------------------+------------------------+-------------------+ | The XML Bible, 2nd Edition (Hungry Minds, 2001) | | http://www.ibiblio.org/xml/books/bible2/ | | http://www.amazon.com/exec/obidos/ISBN=0764547607/cafeaulaitA/ | +----------------------------------+---------------------------------+ | Read Cafe au Lait for Java news: http://www.cafeaulait.org/ | | Read Cafe con Leche for XML news: http://www.ibiblio.org/xml/ | +----------------------------------+---------------------------------+



This archive was generated by hypermail 2.1.2 : Thu Feb 07 2002 - 10:16:43 EST