Apple Blocks IDN Spoofing in Safari

By Nate Mook | Published March 22, 2005, 9:44 AM

Following in the footsteps of Mozilla and Opera, Apple has issued its monthly Mac OS X security update with a fix for the spoofing vulnerability caused by Internationalized Domain Names (IDN). Apple's Safari Web browser will now only display URL characters from an approved list, which can be customized by the user.

The problem with IDN -- uncovered in early February -- stems from its use of the Unicode character set to enable domain names that include international letters. Unicode URLs must be converted by a Web browser into a format called "Punycode," which opens the door for a malicious Web site to mimic a trusted URL, including its SSL security certificate.

Like Opera, Safari will now display URLs with non-approved characters in their native Punycode form in order to lessen the risk of spoofing. Apple, however, has not followed Opera's example of providing more details about the origin of SSL certificates.

According to Apple, "The default list does not include Latin lookalike scripts (Cherokee, Cyrillic, and Greek) that could be used to trick users into navigating to malicious sites. You can edit the list of allowed scripts to specify exactly what scripts you want displayed."

Mozilla Firefox was updated last month to block the display of any IDN URLs by default. For those using URLs with international characters, the feature can be re-enabled. Microsoft's Internet Explorer is the only Web browser not affected by the problem, as it was never updated to support the IDN specification.

Opera, meanwhile, has called on the industry to band together in developing a long-term solution to the issues surrounding IDN.

"Opera stands behind its statement made to BetaNews on Feb. 18, 2005, asserting that the IDN problem is not one that can be solved alone, but rather together with other browser vendors, domain name registries, certificate authorities and other members of the Internet community," the company said last month.

Mac OS X users can download the March security fix via Software Update.

Comments

View comments by with a score of at least

"Mozilla Firefox was updated last month to block the display of any IDN URLs by default."

For the record; Mozilla Firefox shows IDN (Internationalized Domain Names) in punycode (http://www.faqs.org/rfcs/rfc3492.html) format (by default) so it will *not* block you from visiting any IDN's.

Score: 0

|

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

AOL's decision to rebrand as Aol. takes a bad brand and makes it worse

The idea behind the social Web is to crowd source before bringing out something new. But not at AOL, which new logo debuted with a cry of "fail!" across the blogosphere and Twittersphere today.

Microsoft's Bob Muglia and Ray Ozzie on Silverlight vs. standards

Bob Muglia: "We're trying to provide people with an environment that has capabilities that you just simply can't do today in the standards-based world."

Uh-oh, netbooks -- not Windows 7 -- will lift 2009 PC sales

Santa may bring a lump of coal to the Windows PC industry this holiday season. Netbook sales will sap PC margins, while weak Windows 7 PC sales could further drive down average selling prices.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

Microsoft's .NET Micro Framework is now free and open source

The latest version of Microsoft's .NET Micro framework is now in the hands of the FOSS community.

Google's value proposition for Chrome OS: Should we feel insulted?

For a search engine that has direct access to all the world's online history, it appears to have taught Google nothing about selling a machine.