Re: Return of i18n attacks with the help of wildcard certificates

2009-03-03 Thread Jean-Marc Desperrier
Gervase Markham wrote: [...] We just turned hostname display UI for SSL on, according to The Burning Edge... This is a nice change, I found out about it on the burning edge too :-) But, and as the link Eddy just reported shows, the attack is far from being only for SSL. I think we should

Re: Return of i18n attacks with the help of wildcard certificates

2009-03-03 Thread Eddy Nigg
On 03/03/2009 04:30 PM, Jean-Marc Desperrier: But, and as the link Eddy just reported shows, the attack is far from being only for SSL. I think we should reconsider the options available to make the domain name more visible for http connexions. What about a white version of the hostname display

Re: Return of i18n attacks with the help of wildcard certificates

2009-03-03 Thread Boris Zbarsky
Jean-Marc Desperrier wrote: But, and as the link Eddy just reported shows, the attack is far from being only for SSL. I think we should reconsider the options available to make the domain name more visible for http connexions. What about a white version of the hostname display for http sites

Re: Return of i18n attacks with the help of wildcard certificates

2009-03-03 Thread Jean-Marc Desperrier
Boris Zbarsky wrote: Jean-Marc Desperrier wrote: But, and as the link Eddy just reported shows, the attack is far from being only for SSL. I think we should reconsider the options available to make the domain name more visible for http connexions. What about a white version of the hostname

Re: Return of i18n attacks with the help of wildcard certificates

2009-03-03 Thread Eddy Nigg
On 03/03/2009 05:51 PM, Boris Zbarsky: Jean-Marc Desperrier wrote: But, and as the link Eddy just reported shows, the attack is far from being only for SSL. I think we should reconsider the options available to make the domain name more visible for http connexions. What about a white version