3.4 Enable IDN Show Punycode

Information

This setting determines whether Internationalized Domain Names (IDNs) displayed in the browser are displayed as Punycode or as Unicode.

Rationale:

IDNs displayed in Punycode are easier to identify and therefore help mitigate the risk of accessing spoofed web pages.

Solution

To establish the recommended configuration, set network.IDN_show_punycode to true:

Type about:config in the address bar

Type network.IDN_show_punycode in the filter

Configure the setting as prescribed.

OR

Open the mozilla.cfg file in the installation directory with a text editor

Add the following lines to mozilla.cfg:

lockPref('network.IDN_show_punycode', true);

Default Value:

False

See Also

https://workbench.cisecurity.org/files/4299

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Unix

Control ID: fe97e1a080aef38f928e19691f2de9db7dc9986b4f7f1e1decf6e3267d0fb16e