How far will IE defenders take this one?
Lots of stuff out about the IDN exploit that is in firefox and lots of other modern browsers but not yet in IE; the register has a good short intro here.
As I’ve had adblock since the beginning, I can solve this by simply adding a short regexp to my block list; here’s the complete procedure for those who don’t have the extension installed yet.
And here is a handy test page.
It’s curious to see anyone use this case to defend IE. The relative openness and configurability of firefox enables a number of workarounds that aren’t there for a blackbox like IE. Downloads are available as soon as fixes are in; if it takes some time this time, it’s because IDN needs a rethink and not because of the development model. Curious minds can read the code and submit a patch if they like. I’m not one of Bill’s new red-scare commies, but on this kind of issue I don’t see how closed source proprietary dev models can ever compete.