movable tripe

 

dustbinman.com 

« Disengage Blackberry, Re-engage Brain | Main | Wheeeeeee! »

Thursday 10 February 2005

Phishing for a phix

Much hand-wringing, wailing and gnashing of teeth at the revelation of a security flaw in Mozilla, Firefox et. al.

Actually, it's a security flaw enabled by the dappy gits who introduced the concept of International characters in domain names.

Which in effect means that you could click on a link that appears in your address bar as "paypal.com" but which in fact is linking you to www.xn--pypal-4ve.com.


The good news is that according to Netcraft you can fix this by turning off international character support ...

... in Firefox and Mozilla by setting 'network.enableIDN' to false in the browser's configuration (enter about:config in the address bar to access the configuration functions)

Fixes are on their way. This isn't a problem in Internet Explorer unless you install the plugin which enables you to use international character support.

Posted by dustbinman at 20:44 | Permalink

Comments




All content © Dan Wright 2001-2006 unless otherwise stated. Contact dan at dustbinman dot com.