Mozilla and Firefox Disable IDN Support

MOUNTAIN VIEW, Calif. – The recently uncovered security threat from international domain names that has been demonstrated in vulnerable web browsers such as Opera and Firefox is creating a firestorm of activity among developers seeking to mitigate this exploit.

As previously reported by XBiz, the vulnerability is a variation of the "homograph attack" which targets weaknesses in the methods that certain web browsers interpret Unicode in order to display domain names using non-English characters, carried out in a way that exploits character resemblance. For instance, the number "0" and the letter "O" are similar enough to fool unwary users into believing that a fraudulent site is actually the website the surfer was trying to reach.

In response to this threat, Mozilla's developers have announced their intention to disable default support for Internationalized Domain Names (IDN) in future releases of the Mozilla and Firefox web browsers.

Opera, and the Mac Safari browser will remain vulnerable, however Microsoft's Internet Explorer web browser is unaffected by this exploit.

A simple solution to the vulnerability in Mozilla and Firefox is had by setting "network.enableIDN" to "false" within the browser's configuration panel, accessed by entering "about:config" in the browser's address bar. This will be the new default setting going forward, but users who require IDN support may use the same configuration process to enable it.

"This is obviously an unsatisfactory solution in the long term and it is hoped that a better fix can be developed in time for Firefox 1.1," read a statement on mozillaZine. "For now, the Mozilla Foundation (and other browser vendors such as Opera Software) maintain that the problem is mostly the fault of domain name registries and registrars that let people register homographic variants of existing domain names."

"There are now many ways to display any domain name on a browser, as there are a huge number of codepages / scripts which look very similar to Latin charsets," said an advisory from the The Shmoo Group, the organization which first demonstrated the exploit. "[For] a business trying to protect their identity, IDN makes their life very difficult. It is expected there will be many domain name related conflicts related to IDN."

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Proposed New Hampshire AV Bill Appears to Violate Constitution

A bill in the New Hampshire state legislature, aimed at requiring adult sites to age-verify users in that state, contains a provision that seemingly contradicts the Supremacy Clause in Article VI of the U.S. Constitution.

AEBN Publishes Report on Fetish Trends

AEBN has published a report on fetish categories from its straight and gay theaters.

Online Child Protection Hearing to Include Federal AV Bill

A House subcommittee will hold a hearing next week on a slate of bills aimed at protecting minors online, including the SCREEN Act, which would make site-based age verification of users seeking to access adult content federal law.

Industry Photographer, 'Payout' Founder Mike B Passes Away

Longtime industry photographer and publisher Michael Bartholomey, known widely as Mike B, passed away Saturday.

FSC Announces 2025 Board of Directors Election Nominees

The Free Speech Coalition (FSC) has announced the nominees for its 2025 Board of Directors election.

AdultHTML Launches Black Friday Web Design, Development Promo

AdultHTML has launched its annual Black Friday/Cyber Monday promo for web design and development, running through Dec. 5.

Canada Exempts Online Adult Content From 'CanCon' Quotas

The Canadian Radio-television and Telecommunications Commission (CRTC) has updated its broadcasting regulatory policies, exempting streaming adult content from “made in Canada” requirements that apply to other online material.

Creator Law Firm 'OnlyFirm' Launches

Entertainment attorney Alex Lonstein has officially launched OnlyFirm.com for creators.

German Court Puts Pornhub, YouPorn 'Network Ban' on Hold

The Administrative Court of Düsseldorf has temporarily blocked the State Media Authority of North Rhine-Westphalia (LfM) from forcing telecom providers to cut off access to Aylo-owned adult sites Pornhub and YouPorn.

FSC: NC Law Invalidating Model Contracts Takes Effect December 1

The Free Speech Coalition (FSC) has issued a notice that North Carolina's Prevent Exploitation of Women and Minors Act goes into effect on December 1.

Show More