1.1.18.9 (L2) Ensure 'network.IDN_show_punycode' is set to 'Enabled'

Information

This setting determines whether Internationalized Domain Names (IDNs) displayed in the browser are displayed as Punycode or as Unicode.

The recommended state for this setting is: Enabled

IDNs displayed in Punycode are easier to identify and therefore help mitigate the risk of accessing spoofed web pages.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Preferences (Deprecated)\network.IDN_show_punycode

Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this

link

.

Impact:

IDNs will be displayed in Punycode.

See Also

https://workbench.cisecurity.org/benchmarks/18454

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 76d209358108094eee084920335295c870e28ad5f8c9c6fb7eda9e1dfb386d7e