
« Disengage Blackberry, Re-engage Brain | Main | Wheeeeeee! »
Thursday 10 February 2005
Phishing for a phix
Much hand-wringing, wailing and gnashing of teeth at the revelation of a security flaw in Mozilla, Firefox et. al. Actually, it's a security flaw enabled by the dappy gits who introduced the concept of International characters in domain names. Which in effect means that you could click on a link that appears in your address bar as "paypal.com" but which in fact is linking you to www.xn--pypal-4ve.com. Fixes are on their way. This isn't a problem in Internet Explorer unless you install the plugin which enables you to use international character support.
The good news is that according to Netcraft you can fix this by turning off international character support ...... in Firefox and Mozilla by setting 'network.enableIDN' to false in the browser's configuration (enter about:config in the address bar to access the configuration functions)