« Interactive blackboards | Main | UC school administrative bonuses anger students »

February 07, 2005

The Schmoo Group pwnz domains

Schmoocon finished today. And The Schmoo Group released an exploit that has no current defense. SSL certifications mean nothing. With this exploit, any browser will be vulnerable to middleman snooping attacks.

Workaround for Firefox
1) about:config
2) disable network.enableIDN

All browsers that support IDN (International Domain Names) are effected. A feature championed by Verisign. Internet Explorer not effected since it does not follow the common standard.

See the effects here. Advisory here.

Via BoingBoing < Schmoo

Posted by darkmoon at February 7, 2005 02:27 AM

Trackback Pings

TrackBack URL for this entry:
http://life.firelace.com/mt-cgi/mt-tb.cgi/285

Comments

Post a comment




Remember Me?

(you may use HTML tags for style)