Multiple Browsers URL Spoofing Security Issue

This recently publicised problem with almost all browsers (except IE) occurs when “domain names with certain international characters” look like common domain names. It’s not a new issue however, being a well known problem for several years.
You can test your own browser by following this link – does the url say http://www.paypal.com/?
For Firefox users there’s Spoof Stick which “prominently displays only the most relevant domain information”. It’s not foolproof though, and Secunia recommends that users:

Don’t follow links from untrusted sources.
Manually type the URL in the address bar.

Later… Richard Eibrand has the scoop in an ILUG post. Here’s how to disable this feature in Firefox:

  • Visit about:config
  • Search for “idn” in the search box.
  • By default it’ll be “true”, but double click on it to set it to false.
  • You don’t need to restart your browser, just go to the test page to see if it works. It did for me!

As a side note, Fuzzbucket says that IDN isn’t used much so it might be worth while having it disabled by default!
Later Still… That’s only a temporary fix as it’s reset the next time you restart Firefox. Here’s a more permanent fix using an extension that warns of IDN characters – Japanese and other sites that use those characters will still work!

Householders Against Service Charges

This afternoon while I was in town I saw a peaceful protest against household service charges on Cork’s Patricks Street. Stories in the newspapers have been accompanied by photographs of garbage piled high on the streets of Cork as the Corporation refuses to collect rubbish bins without tags. Unfortunately, bins put out at night quite often have their tags stolen. Local TD Kathleen Lynch has complained but the City Manager is on record as saying that there’s no problem!
The People’s Republic of Cork have their own analysis of the problem, offering suggestions for what Corkonians can expect for their hard earned cash.

Imagine it. A loud hailer booms: “Ladies and Gentlemen! Roll up! Roll up! For JUST A FIVER (plus the annual standing charge) have your bin collected by the amazing, the spectacular, the heavily unionised Cork City Rubbish collectors!”

At least this time I had a camera, the last time I was on Patrick’s Street 2 elephants went running past and this is all I got with my pitiful camera phone..

What makes a camera/photographer obvious?

Two related photography questions: What makes a camera/photographer obvious?

Hawaiian shirt. Bright yellow shorts. Black socks and wingtips.

People won’t even notice you have a camera.

Strategies for candid photography
Excellent answers to both questions in the photo.net forums. (besides the obvious tshirt troll above!)
(via delicious)

My New Mooslim Friend

Amanda has a new friend! Here’s the story of when they first met!

the day the new mooslim girl came to class mrs clark intoduced her and asked the class if we knew anything about the mooslim religion. i know a lot about false religions, so I informed the class that mooslims are a brown race from mooslim country who worship an elefant god named ganisha. they dont celebrate christmas like normal people, there equivalent is called ramada inn, and their jesus is called ibraham. the only ways to get into mooslim heaven are to either kill a virgin or blow yourself up

Edit: link is dead unfortunately, and if you’re reading this please don’t take it seriously. The piece above is a joke!

What's the GPL? WordPress and PEAR Cache Problems

Ben Ramsey explores some of the issues when you write GPLed code that uses code from the PEAR library.
I had forgotten about the differing licenses used by PEAR and WordPress. They’re unfortunately incompatible and you can’t ship PHP licensed code in a GPL project without an “exception clause” in your GPL license. A change to the license of WordPress would require the agreement of *all* copyright holders of code in the project AFAIK.
Thankfully, I don’t ship PEAR Cache with WordPress MU. I use it if it’s installed already, WPMU isn’t dependant on PEAR Cache being available to work.
I think that gets around the incompatibility. Doesn’t it?