Language Selection

English French German Italian Portuguese Spanish

Non-English Domain Names Likely Delayed

Filed under
Web

Concerns about "phishing" e-mail scams will likely delay the expansion of domain names beyond non-English characters, the chairman of the Internet's key oversight agency said Friday.

Vint Cerf, head of the Internet Corporation for Assigned Names and Numbers, would not speculate on when such characters might appear but said Internet engineers must now spend time "trying to winnow down, frankly, the number of character (sets) that are allowed to be registered."

Demand for non-English domain names is high outside the United States and a U.N. panel studying Internet governance said in a report Thursday that "insufficient progress has been made toward multilingualization." It cited the lack of international coordination and technical hurdles as among the problems.

Officially, the Internet's Domain Name System supports only 37 characters - the letters of the Latin alphabet, 10 numerals and a hyphen.

But in recent years, in response to a growing Internet population worldwide, engineers have been working on ways to trick the system into understanding other languages, such as Arabic, Chinese and Japanese.

Engineers have rallied around a character system called Unicode.

But security experts warned earlier this year of a potential exploit that takes advantage of the fact that characters that look alike can have two separate codes in Unicode and thus appear to the computer as different. For example, Unicode for "a" is 97 under the Latin alphabet, but 1072 in Cyrillic.

Subbing one for the other can allow a scammer to register a domain name that looks to the human as "paypal.com," tricking users into giving passwords and other sensitive information at what looks like a legitimate site. It's much like how scammers now use the numeral "1" sometimes instead of the letter "l" to trick users.

"In some of the early tests, ... it became clear we had opened up the opportunity for registering very misleading names," Cerf said in a conference call wrapping up ICANN's meetings this week in Luxembourg. "This kind of potential confusion leads to parties going to what they think are valid Web sites."

Cerf said it may be possible to proceed with character sets that aren't at risk of confusion as the standards-setting Internet Engineering Task Force tackles the broader security concerns with non-English names.

Tests of non-English characters have been going on for years, and in a few cases they are fully operational. Last year, operators of the German ".de" domain began offering 92 accented and other special characters, including the umlaut common in German names.

But ICANN has yet to approve domain names entirely in another language; all addresses now must end with an English string such as ".com."

Associated Press

More in Tux Machines

Samsung Leftovers

OSS Leftovers

  • FOSDEM 2018 Real-Time Communications Call for Participation
  • Top Bank, Legal and Software Industry Executives to Keynote at the Open Source Strategy Forum
  • Copyleft is Dead. Long live Copyleft!
    As you may have noticed, we recently re-licensed mgmt from the AGPL (Affero General Public License) to the regular GPL. This is a post explaining the decision and which hopefully includes some insights at the intersection of technology and legal issues.
  • Crowdsourcing the way to a more flexible strategic plan
    Trust the community. Opening a feedback platform to anyone on campus seems risky, but in hindsight I'd do it again in a heartbeat. The responses we received were very constructive; in fact, I rarely received negative and unproductive remarks. When people learned about our honest efforts at improving the community, they responded with kindness and support. By giving the community a voice—by really democratizing the effort—we achieved a surprising amount of campus-wide buy-in in a short period of time. Transparency is best. By keeping as many of our efforts as public as possible, we demonstrated that we were truly listening to our customers and understanding the effects of the outdated technology policies and decisions that were keeping them from doing their best work. I've always been a proponent of the idea that everyone is an agent of innovation; we just needed a tool that allowed everyone to make suggestions. Iterate, iterate, iterate. Crowdsourcing our first-year IT initiatives helped us create the most flexible and customer-centric plan we possibly could. The pressure to move quickly and lay down a comprehensive strategic plan is very real; however, by delaying that work and focusing on the evolving set of data flowing from our community, we were actually able to better demonstrate our commitment to our customers. That helped us build critical reputational capital, which paid off when we did eventually present a long-term strategic plan—because people already knew we could achieve results. It also helped us recruit strong allies and learn who we could trust to advance more complicated initiatives.
  • Reform is a DIY, modular, portable computer (work in progress)
    Want a fully functional laptop that works out of the box? There are plenty to choose from. Want a model that you can upgrade? That’s a bit tougher to find: some modern laptops don’t even let you replace the RAM. Then there’s the Reform. It’s a new DIY, modular laptop that’s designed to be easy to upgrade and modify. The CAD designs will even be available if you want to 3D print your own parts rather than buying a kit. You can’t buy a Reform computer yet. But developer Lukas Hartmann and designer Ana Dantes have developed a prototype and are soliciting feedback on the concept.
  • New neural network teaches itself Go, spanks the pros
    While artificial intelligence software has made huge strides recently, in many cases, it has only been automating things that humans already do well. If you want an AI to identify the Higgs boson in a spray of particles, for example, you have to train it on collisions that humans have already identified as containing a Higgs. If you want it to identify pictures of cats, you have to train it on a database of photos in which the cats have already been identified.

Ubuntu Leftovers

Server: MAAS, OPNFV, 'DevOps', and Docker

  • MAAS KVM Pods
    OpenStack is the dominant solution in the IaaS space, fueled by the need for reliable, scalable and interoperable private cloud infrastructure to accommodate cloud native applications. Through OpenStack’s open APIs, tenants can easily deploy elaborate virtual (overlay) networks, integrate with a variety of storage backends, even leverage modern hypervisor-like machine containers (LXD) for bare metal performance. Although the tooling allows a full fledged OpenStack deployment on just a single machine, the intrinsic efficiencies that OpenStack’s design promises, materialize at a certain scale — typically at least 12 servers.
  • DevOps for NFV: OPNFV Infrastructure and Continuous Integration
    In this article series, we have been discussing the Understanding OPNFV book. Previously, we provided an introduction to network functions virtualization (NFV), discussed the role of OPNFV in network transformation, and looked at how OPNFV integrates and enhances upstream projects. We continue our series with in-depth insight into the OPNFV DevOps toolchain, hardware labs, continuous integration (CI) pipeline, and deployment tools (installers) from chapters 6 and 7 of the book.  
  • A Chat with Chef about the DevOps Movement and Habitat Builder
    Last week at our annual user conference, Node.js Interactive, we announced several new members to the Node.js Foundation. One of the members that joined is Chef. Chef works with more than a thousand companies around the world to deliver their vision of digital transformation. We sat down with the team at Chef to talk about how Node.js fits within the DevOps movement, why they joined the Node.js Foundation, and also about a new offering from the group called Habitat Builder.
  • Why Use Docker with R? A DevOps Perspective
    There have been several blog posts going around about why one would use Docker with R. In this post I’ll try to add a DevOps point of view and explain how containerizing R is used in the context of the OpenCPU system for building and deploying R servers.
  • Docker on Docker at DockerCon EU 17
    Docker Inc. the company behind the open-source Docker container technology doesn't just build docker, it also used the same technology to power its own services.