Post a Comment
From reading about this on other places, I have to wonder why they released 1.5b1... They knew about the hole days before the release, and still didn't add it in.
And in general I have to wonder about the bugzilla practices they run... as it is now, if you make sure to get your hands on all newly submitted bug entries, you can potentially get your hands on exploitable holes before anyone gets around to mark these entries as hidden (or whatever it is called).
It's great that Firefox fixes flaws faster than Microsoft, and it's great to know that Firefox is still maintaining some level of security, but I kinda wonder- how many buffer overflows are still in there? How many times are they going to have to re-correct how Firefox handles URLs? I would have thought it would be set to reject bad URLs.
1.5b1 was intended a real beta release, explicitely stated being released for testers and developers. That said, this IDN issue was here for a while, probably overlooked by some busy developer. Still, about 2 seconds after the release of the IDN security hole the workaround could be performed by anyone knowing enough about firefox, by setting network.enableIDN to false in about:config. As you all know by now, this "workaround" slowly but gets its way to all people through variosu news sites. All in all, IMHO this is not a major showstopper bug, and this "workaround" is quite enough for the short period of time till a fix will be released, which - be not afraid - will probably be released soon enough. I think the smoke is so much bigger than the fire in this case.
You're honestly ready to back that load of trash?
http://www.eweek.com/article2/0,1895,1841359,00.asp
Oh, but that of course can't be correct; as you've stated, Opera is perfection made real. Sure sure...
"You're honestly ready to back that load of trash?
" rel="nofollow">http://www.eweek.com/article2/0,1895,1841359,00.asp"
"Load of trash" ? ROTF! I guess you know Opera only by its name. Give it a try, and then tell me if it's a "load of trash" !
This security breach you're quoting is historical. Security breaches are very seldom with Opera. With Firefox it happens every week. That's it.
May I suggest you do some research?
http://dictionary.reference.com/search?q=choice
Does it affect v1.06 ?
Yes it does.
A temporary fix would be entering "about:config" where you would normally enter the http://www.... adresses and edit on the "network.enableIDN" which then goes from enabled to disabled.
The IDN itself is a security mechanism that should protect you against spoofing so this temporary fix isn't really an solution.Konqueror also has this mechanism.
I am running CentOS 4, and Red Hat released a patch yesterday for the bug (hit the CentOS repos today). I'm not sure whether they just applied the workaround, or else if they actually patched the code. Hopefully they patched the code, as this would allow the Mozilla Foundation to release an update using Red Hat's code.
For more info, see:
https://addons.mozilla.org/messages/307259.html
http://mozillanews.org/bugzilla_warning.php3?id=307259
So it only works for long strings of soft hyphens. The number of hyphens is very arbitrary :p (The actual code that might get executed isn't)
According to the bug report, it was opened (reported to Mozilla.org) on Sept 6. Surely the bug had existed for long, but nobody knew about it.
Oh, and the actual analysis was done by the Mozilla.org folks too.
How long have they known about this? I've had two websites in the past two or uh... no, two months that were able to completely lock up FireFox, to the point that I actually have to terminate the FireFox process in order to get out of it. I wouldn't have anyway of knowing if there is any "arbitrary code" being run though. Maybe I'm not even typing this, maybe it's the terroras.
I guess it's because Americans don't see the value of IDNs, but can you please stop praising the Mozilla folks because they fixed this bug so quickly?
Firefox is the only modern browser that does not properly support IDNs. (IE 6 does not count as a modern browser.) Enter www.müller.de in Firefox - it will display the punycode, even though nobody would mistake the ü for an u. There is no danger of "spoofing". Opera and Safari understand that and display www.müller.de correctly.
And with this "fix", Firefox will no longer work at all with www.müller.de
That's no fix, that's ridiculous.
Well duh. Of course this isn't a fix!
Its a temporary solution.
You do know what the word "temporary" means, don't you?
People are praising Mozilla because they're active on security. No, they aren't maintained by companies like Apple or Opera Software with regular incomes. Its by a bunch of volunteers, people who like to program.
The point of open-source if you have the necessary skills and like to add a feature or support something, you can add it in and contribute to the project.
Rather than whine like a no-clue spoilt rich girl, how about you help out. If you see a problem, either point out the problem so the developers can put it on their to-do list OR provide the solution yourself.
As for sterotypically blaming Americans in general, how about you look at their Governments, greedy Corporations, and completely stupid patent laws?
If you really think about it, some Americans disagree with those who are in charge. They also disagree on greedy SOB companies like the RIAA and MPAA...Heck, everyone around the world disagrees on that!
With IE you get almost 100% compatibilty with previous versions and that is what matters for, for example, corporate users.
Last time I checked, almost every Firefox's new version (aka patch release) broke compatibility - ie, problems with extensions.
Having said that, competition is good: Firefox 1.5 will bring better patching system, while Microsoft is working on IE 7.



