Earlier quoted context omitted.
It still sounds like an improvement: while they might still fall for malicious URLs in their own language, they would not for other scripts. But as someone said, tiny, valid differences are easy to miss anyway, and original URL attacks were replacing similar-looking ASCII graphemes (eg. l for 1), so this will all continue.
> while they might still fall for malicious URLs in their own language, they would not for other scripts. That's totally backwards. If the assumption is that users of language X will legitimately visit sites of language Y with sufficient frequency, then all that language-specific filtering makes no sense.
And seeing punycode in URL bar does not mean a site does not work, it's only a suboptimal experience.