The great equivocation

Opinion
Feb 26, 20052 mins

In an upcoming story for the March issue of Network World’s Network Life, I write about browser vulnerabilities that make it easier for phishers to mask their real IP addresses behind what looks to be a legitimate URL.

One of the vulnerabilities is the International Domain Name (IDN) standard approved by ICANN and adopted by most major browsers, with the exception of Microsoft’s Internet Explorer. Unfortunately, this standard now makes it possible for phishers to use international characters in place of English language characters to create a real-looking URL such as www.paypal.com. See here.

This means even users savvy enough to check the legitimacy of a site will be fooled.

So far, IE remains invulnerable to this type of IDN spoofing attack because

it hasn’t yet adopted the IDN standard. So the big question is, will Microsoft adopt it?

I called Microsoft’s IE public relations firm and asked them to find the answer for me. Two phone calls and two days later, I get this e-mail response:

“Thanks again for your patience with this request and my apologies for the elayed response. I just heard back from my colleagues, and below is our response to your question, attributable to a Microsoft spokesperson:

“In principle and in practice, industry standards are critical to ensuring the Internet remains open and accessible to everyone. But 100 percent compliance with all standards is neither necessary nor necessarily the best option. The needs of customers and site developers must be balanced with what these standards seek to achieve. In Internet Explorer, Microsoft supports the standards that make the most sense for our customers and continues to be a supporter and active participant in numerous standards bodies.”

My editor said this is the best example of a non-answer she’d seen in a long time. No amount of additional prodding would get an answer out of the guy.

I think Microsoft is saying it won’t support the IDN standard any time soon, though, which is good news. But god forbid should it come out against the standard and be your security champion.

deb_radcliff

Deb Radcliff is an investigative journalist and analyst focused on computer crime and security. Her work has appeared on Security Boulevard, the SANS Cyber Security Blog, and SC Media, among other outlets. She stood up an analyst program for SANS Institute and ran it for 15 years before joining the Cyber Risk Alliance as strategic analyst on the business intelligence unit. She is author of the popular cyber thriller series, “Breaking Backbones,” available at Amazon.

Deb won two Neal Awards for investigative business reporting. She holds a Bachelor’s degree in journalism from San Jose State University.

More from this author