Tuesday, February 8, 2005, 08:21 PM CET
[mood] fine
[music] wink - 516 acid
let me be the 15,000th to clear things up. this so-called exploit isn't what it seems. it's exactly the expected behavior and the reason why internet explorer isn't vulnerable is because it lacks the whole feature. what *can* be done, however, is give the user an indication of the domain name's internationalized character. the developers should work that one out, but earlier on, i ludicly suggested making the location bar purple—obviously bearing great similarity to the yellow bar on secure sites, of which i don't fully approve because users might use a similar yellow as their default input background. hence it might be ineffective. what i would do is invert the bar's colors or apply a color transformation. but that would sort of break themes. kinda like the whole extension vs. theme row. isn't feature-richness great?
i digress. it's what i do.