Source: http://www.domaining.ws/general-news/2005/12/23/new-ie-beta-will-support-intl-domains
-------------------------------------------------------------------
The release of a new Internet Explorer will use APIs to support international domain names. It will convert domain names to punycode, making them compatable to be displayed.
In the new IE 7, domain names will be converted from their Unicode format into Punycode, then immediately be resolved and sent to the proxy.
Users would be able to turn off international domain name support by going to options, then under “International”. An IE developer, Vishu Gupta, states, “IE 7 would then function the same as IE 6.”
There are numerous sites under foreign-character domain names (Arab, Greek, Russian, etc), but many English-speaking users are unable to access them because their browsers do not support international characters.
While this would open up accessability to the Internet, it would increase the chance of spoofing attacks. Standard homograph attacks use similar characters to make a domain look legitimate. (e.g. Using a 1 instead of an “L” or “I”.)
Conversion to IDNs opens up the spoof character set from “a few dozen characters to many thousands of characters from all of the world’s languages, thereby increasing the attack surface for spoofing attacks immensely,” Gupta wrote.
Sometimes spooofs are unnoticable with IDNs. For example, the Cyrillic character “a” is substituted for the Latin “a,” which makes it impossible - visually - to tell whether the domain is fraudulent or not. Microsoft says they will implement features to notify the user of a possible spoofing attack.
---------------------------------------------------------------
Sigh, just more IE security/fraud problems... Firefox disables these for a good reason.
-Matt
-------------------------------------------------------------------
The release of a new Internet Explorer will use APIs to support international domain names. It will convert domain names to punycode, making them compatable to be displayed.
In the new IE 7, domain names will be converted from their Unicode format into Punycode, then immediately be resolved and sent to the proxy.
Users would be able to turn off international domain name support by going to options, then under “International”. An IE developer, Vishu Gupta, states, “IE 7 would then function the same as IE 6.”
There are numerous sites under foreign-character domain names (Arab, Greek, Russian, etc), but many English-speaking users are unable to access them because their browsers do not support international characters.
While this would open up accessability to the Internet, it would increase the chance of spoofing attacks. Standard homograph attacks use similar characters to make a domain look legitimate. (e.g. Using a 1 instead of an “L” or “I”.)
Conversion to IDNs opens up the spoof character set from “a few dozen characters to many thousands of characters from all of the world’s languages, thereby increasing the attack surface for spoofing attacks immensely,” Gupta wrote.
Sometimes spooofs are unnoticable with IDNs. For example, the Cyrillic character “a” is substituted for the Latin “a,” which makes it impossible - visually - to tell whether the domain is fraudulent or not. Microsoft says they will implement features to notify the user of a possible spoofing attack.
---------------------------------------------------------------
Sigh, just more IE security/fraud problems... Firefox disables these for a good reason.
-Matt















