Re: Work-around for Moxie Marlinspike's Blackhat attack

2009-03-02 Thread Gervase Markham
On 28/02/09 00:32, Jonas Sicking wrote: It'd be good to have a separate pref, network.IDN.blacklist_chars_extra, where users can add additional characters without having to worry about not receiving updates to the list we maintain. If users have to add chars to this list manually, that's

Re: Return of i18n attacks with the help of wildcard certificates

2009-03-02 Thread Gervase Markham
On 27/02/09 14:48, Boris Zbarsky wrote: It's not clear to me that the person who added the list even knew the page existed. Neil added the list, and he wrote the second half of the page. So there was mutual knowledge. The list isn't documented on the page because, strictly speaking, it's not

Re: Return of i18n attacks with the help of wildcard certificates

2009-03-02 Thread Eddy Nigg
Subject was [Fwd: Facebook message - Received Messages Quickly] I've received it a few minutes ago. The URL doesn't us SSL, but it shows exactly what I posted in this thread not long ago...see forwarded message below: Regards Signer: Eddy Nigg, StartCom Ltd. http://www.startcom.org/