Daniel Veditz wrote:
Jean-Marc Desperrier wrote:
Until a better solution is deployed, here is the work around to make
Moxie Marlinspike's attack ineffective.

Note that the "better fix" will be a default change for this very pref,
and any user-modified value will continue to take precedence. Please
remember to undo this change when we ship a fix or you will not get the
updates.

It'd be good to have a separate pref, network.IDN.blacklist_chars_extra, where users can add additional characters without having to worry about not receiving updates to the list we maintain.

/ Jonas
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security

Reply via email to