Advertisement
Promo

Office applications Toolkit

Opera fixes IDN 'vulnerability'

Munir Kotadia ZDNet Australia

Published: 28 Feb 2005 09:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Norwegian software developer Opera released a second beta version of its browser on Saturday. Beta 2 plugs a recently discovered vulnerability that could be used in phishing attacks.

The problem arose because certain browsers support a standardised way of representing domain names in the letters or characters of any language. The Internationalised Domain Names (IDN) vulnerability, which affects non-Microsoft browsers such as Opera, Apple's Safari and Firefox, could help phishers create legitimate-looking Web sites.

Christen Krogh, vice-president of engineering at Opera, explained that when visiting secure Web sites, the browser will now display a yellow security bar containing the name of the organisation owning the site’s security certificate and only display ‘trusted’ top level domains (TLDs).

"One of the most important measures to counter phishing attacks is the use of security certificates. The challenge for browser vendors is to better explain the verification of certificates and to make the user more aware of this additional verification before entering into secure transactions," said Krogh.

To specifically address the IDN vulnerability, Opera's updated browser will only display certain TLDs that have been registered with the company.

According to a statement from Opera, the company "will regularly update its list of trusted TLDs, ensuring maximum protection and the best possible user experience".

In addition to improved security, Opera has made Beta 2 easier to customise and added support for Atom newsfeeds. The browser is available for download from the Opera Web site.

The Mozilla Foundation last week updated its Firefox Web browser to fix the IDN vulnerability, among other bugs.

Is your browser vulnerable to the IDN issue? Security Web site Secunia has constructed a test that can check if your browser is affected.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
99 out of 180 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Vista Upgrade Blog

PreSales Canabalize Retailers' Opening...

(My attempt at writing a tabloid headline.) A Very Interesting Microsoft event just occurred. Microsoft is offering at a deep discount and through direct retail sale their FUTURE... More

Post a comment

Windows 7 on a Read-only Flash Drive?

Considering that the price of a 4GB USB flash drive has been as low as 5 dollars on close-out specials, financially it wouldn't make sense UNLESS Microsoft decides to go into the Flash... More

Post a comment

Bizarre Windows 7 Downgrade/Upgrade Po...

Over at the ZDNet U.S. site, Adrian Kingsley-Hughes has posted about what will apparently be a new low in bizarre downgrade/upgrade policies involving Windows 7, Windows Vista and Windows... More

4 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters