About Safari International Domain Name support

Jesus H. What will they think of next?

About Safari International Domain Name support:


The Issue


Safari can display Unicode characters in URLs, allowing you to access foreign language websites using their native language. For example, you could enter the Japanese language URL “宝島.jp” to visit the website instead of using the Latin alphabet that represents that domain name to get there.


However, lookalike characters could be used to make users believe that they are viewing a different site than what they actually are. For example, the Cyrillic letter “a” could be used in place of the Latin letter “a,” making it difficult for a user to tell if they are at “www.apple.com” or a malicious imposter website that's designed to look like the real one. These sites can be used to collect account numbers, passwords, and other personal information. This can affect any web browser with support for International Domain Names. Security Update 2005-003 addresses this issue.


The Solution


Security Update 2005-003 provides a user-editable list of scripts that are allowed to be displayed natively in domain names. The default list does not include Latin lookalike scripts (Cherokee, Cyrillic, and Greek) that could be used to trick users into navigating to malicious sites.

{}

About this Entry

This page contains a single entry by Seth A. published on March 21, 2005 6:44 PM.

Poems was the previous entry in this blog.

Robert Johnson photos is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Pages

Powered by Movable Type 4.37