I-D Action: draft-klensin-idna-rfc5891bis-00.txt

Andrew Sullivan ajs at anvilwalrusden.com
Sun Mar 12 09:05:46 CET 2017


On Sat, Mar 11, 2017 at 10:14:58PM -0800, Asmus Freytag wrote:
> There's an absolute limit on what you can achieve on the "per code point"
> level. Because users interact with the system on the "per label" level.

I'd say even worse: users interact with the system on the "domain
name" level, or maybe on the level of thinking that anything with a
dot in it is a domain name and that they follow natual language
spelling rules.  I don't think most users have a theory of domain
names as distinct from names in the DNS, and I think even less they
have a theory of the various delegation points of the DNS.  They
_might_ have a theory (thanks to things user interfaces have been
doing) that the stuff near the end of the domain name is somehow more
important or the "real" domain or something.

> The proper strategy seems to me consists of a set of nested defenses.

On this I think we completely agree.

A

-- 
Andrew Sullivan
ajs at anvilwalrusden.com


More information about the Idna-update mailing list