Domain name extension ‘could boost cyber-crime’
The introduction of internet addresses in non-Roman scripts could offer fresh opportunities to cyber-criminals, experts have warned. — Next year the Internet Corporation for Assigned Names and Numbers (Icann) will for the first time …
Context & Ripple Effects
Icann's move to allow internet addresses entirely in non-Roman scripts for the first time completes an arc that has run through its governance debates for years — from the 2005 proposal by a firm to rid the net of suffixes altogether to the 2007 probe into insiders snatching reserved domain names. Each step has widened who controls names in the root zone, and each has dragged security questions along with it.
First-order effects
- Registries and registrars must stand up non-Roman-script handling in production for the first time, while Icann inherits responsibility for vetting a namespace whose characters most existing fraud-detection tooling cannot read.
- Brand owners whose trademarks exist only in Roman script become directly exposed to impostor addresses built from visually similar characters in the new scripts — exactly the 'fresh opportunities' the experts quoted in the report warn about.
Second-order effects
- Anti-phishing and brand-protection vendors gain a new monitoring workload: every additional script multiplies the lookalike-address space they must sweep for clients.
- Browser and email providers come under pressure to render or flag non-ASCII addresses visibly, because users cannot distinguish legitimate internationalized addresses from spoofs without client-side help.
Third-order effects
- If the security gap persists, internationalized addressing splits the web's trust layer into a tiered one — global brands pay for expanded protection while smaller sites absorb the spoofing risk, and pressure builds on Icann to make abuse vetting a formal condition of delegating new scripts or, later, new top-level domains generally.
The trend: Namespace expansion at Icann — new scripts now, broader suffix programs next — is outrunning the security vetting that accompanies each delegation.