📜 ⬆️ ⬇️

PayPal or is it RauRal?

Probably everyone remembers well that ICANN approved the introduction of non-Latin domain names ( HABR ), including those consisting of letters of the Russian alphabet. And most recently, most American resources, including the notorious Mashable, published a shocking news for the American Internet.

It is believed that in the Russian alphabet there are many letters very similar in Latin characters. Here is what Mashable writes:
Cyrillic scripts, which is the basis for the Russian language, shares some of the same letterforms as the Latin alphabet. What this means is that potential evil-doers could register a domain using non-Latin characters that appears to spell out a Latin word.

As an example that Mashable draws attention to, a potential attacker registers the domain raural.com (in the domain of the letter in Russian) and catches cheap fish (her credit card details, etc.), which does not notice the differences in the writing of the fake domain and the original paypal:


And now my presentation of the case :
')
As far as I know, there was no news from ICANN about hybrid domains on the Internet - if you can use both Russian and English letters in their names. Otherwise, yes, there is a possibility of substitution of a domain (pay attention to two examples - paypal.com, written with the help of Russian and Latin and the usual raural.com). I don’t think that there are really people on the Internet who can’t distinguish between ordinary paypal.com and Raural.com. Moreover, registration of Cyrillic domains was allowed only in .eu, .rf, .su, but not in .com.

Those. In the near future, such a problem should not arise, especially in the .com domain.
And if you look, the permissions for Cyrillic subdomains in .eu, ., .su are only because there are no other identical letter equivalents for these domains in Cyrillic / Latin.

Thus, we are dealing with when someone began to sow panic, without understanding the case. Mashable , believing another, seemingly less popular source, TimesOnline , has published information about possible phishing Cyrillic domains. Even as an example, the notorious “paypal” is given, which cannot be written in Cyrillic to make it look identical.

In fact, it is surprising that such a “hot” news everyone believes - the topic on mashable has more than a thousand retweets and ~ 2000 diggs. By the way, I unsubscribed from Mashable a long time ago, because this is not the same resource on which they are talking about new interesting things. Too much panic, advertisements, and web-like content similarity.

By the way, test Russian ICANN domain with their wiki:
IDNwiki

Source: https://habr.com/ru/post/79991/


All Articles