Apple Blocks IDN Spoofing in Safari

By Nate Mook | Published March 22, 2005, 9:44 AM

Following in the footsteps of Mozilla and Opera, Apple has issued its monthly Mac OS X security update with a fix for the spoofing vulnerability caused by Internationalized Domain Names (IDN). Apple's Safari Web browser will now only display URL characters from an approved list, which can be customized by the user.

The problem with IDN -- uncovered in early February -- stems from its use of the Unicode character set to enable domain names that include international letters. Unicode URLs must be converted by a Web browser into a format called "Punycode," which opens the door for a malicious Web site to mimic a trusted URL, including its SSL security certificate.

Like Opera, Safari will now display URLs with non-approved characters in their native Punycode form in order to lessen the risk of spoofing. Apple, however, has not followed Opera's example of providing more details about the origin of SSL certificates.

According to Apple, "The default list does not include Latin lookalike scripts (Cherokee, Cyrillic, and Greek) that could be used to trick users into navigating to malicious sites. You can edit the list of allowed scripts to specify exactly what scripts you want displayed."

Mozilla Firefox was updated last month to block the display of any IDN URLs by default. For those using URLs with international characters, the feature can be re-enabled. Microsoft's Internet Explorer is the only Web browser not affected by the problem, as it was never updated to support the IDN specification.

Opera, meanwhile, has called on the industry to band together in developing a long-term solution to the issues surrounding IDN.

"Opera stands behind its statement made to BetaNews on Feb. 18, 2005, asserting that the IDN problem is not one that can be solved alone, but rather together with other browser vendors, domain name registries, certificate authorities and other members of the Internet community," the company said last month.

Mac OS X users can download the March security fix via Software Update.

Comments

"Mozilla Firefox was updated last month to block the display of any IDN URLs by default."

For the record; Mozilla Firefox shows IDN (Internationalized Domain Names) in punycode (http://www.faqs.org/rfcs/rfc3492.html) format (by default) so it will *not* block you from visiting any IDN's.

Score: 0

|

Silverlight 3 goes live on Microsoft's servers

Microsoft's answer to Adobe's Flash is (unofficially) here, with prospects of higher-speed, higher-resolution video and for the first time, 3D.

Three Android phones on the way from T-Mobile in 2009

T-Mobile's myTouch 3G, launched Wednesday, will be followed by two more Android phones later this year, but neither of them will be HTC's Hero.

Best Buy-brand TVs to get TiVo

A new alliance will place the retailer's own brand alongide the manufacturers, and could also lead to future partnerships on services.

LTE still lacks a voice

The 4G Wireless standard that Verizon hopes to show off before this year is out is still at a loss for (spoken) words.

Data sharing among online advertisers: Is sanity in sight?

Lockdown with Angela Gunn In the middle of a 15-page plea not to get regulated, a spark of smart thinking.

T-Mobile's strategy to combat Apple's iPhone with Android

With a trio of Android phones now in the pipeline for 2009, T-Mobile hopes to break the iPhone's emerging stranglehold.

EC's Reding: Government should act as broker for media downloads

If Internet media services don't step up and build an attractive way for users to start paying for downloads, a commissioner says, government may do the job instead.

Sony TVs get Netflix, still no PS3

Though it's coming in behind LG, Samsung, and Microsoft, Sony will begin to offer Netflix streaming, too.

Google Chrome OS: Too little, too early

Carmi Levy: Wide Angle Zoom Don't start the revolution just yet, says Carmi, who isn't so certain Chrome OS will be the "Windows Killer."

GAO pen test brings the hammer down on federal rent-a-cops

But are the computers to blame for the contract-guard fiasco at FPS?

What's Next: Chrome OS will have at least some friends in high places

Also: South Korea takes another round of DDoS abuse, and Neelie Kroes and Steve Ballmer may shake hands before she exits stage left.

Report: Evidence of further creativity with Windows 7 upgrade prices

A ZDNet blogger did some serious digging for clues as to a reported price break on multiple Windows 7 Home Premium licenses, and may have found it.