PDA

View Full Version : Let's see unencoded Unicode characters in addresses


Albright
2008-02-20, 08:59 PM
…please. Attached is a picture of Safari and OmniWeb looking at the same page in Japanese. Guess which address bar is more usable?

OmniWeb also shows us the encoded address in the status bar when we mouse over a link which links to an address with unicode characters. It makes it pretty much impossible to read where the link is going to. I'd really like to see OmniWeb mimic Safari's behavior in this regard and show us the human-readable Unicode characters in both places.

Other than that, thanks for the great browser!

Floach
2008-02-21, 05:32 AM
I second this request.

JKT
2008-02-21, 04:05 PM
Isn't this a huge security hole in Safari? Isn't it the same feature that allows phishers to easily spoof real websites by using characters that look like letters in place of the actual letter?

Albright
2008-02-21, 08:34 PM
That's theoretically possible, but I don't see that so much as a security hole as an unintended consequence…

Ken Case
2008-02-21, 09:36 PM
We used to decode Unicode characters in the URL, but phishing sites started taking advantage of that browser feature to try to spoof sites like paypal and get people to enter their financial data.

Secunia reported this security issue to us (see their Multiple Browsers IDN Spoofing Test (http://secunia.com/multiple_browsers_idn_spoofing_test/)), and we quickly released an OmniWeb 5.1.1 patch to turn off that support and close that hole. We left a preference in place called DecodeIDNHostnames which people could use to turn that support back on, but we accidentally lost that support in 5.5 when we rewrote a lot of that code during the move from WebCore to WebKit.

We intend to bring back that preference and to make it site-specific, so you can decide to turn it on for sites you trust but leave it off by default. But (according to our bug database) we only get asked about it about once every two years, so it hasn't been a very high priority. If you want to vote for these features, they're in our database as <bug://bugs/30963> (Regression: Reimplement IDN support) and <bug://bugs/21439> (Add a site preference for DecodeIDNHostnames).

Albright
2008-02-22, 06:10 AM
Pardon my ignorance, but where would I find this database? I poked around Omni's site but didn't see anything that looked like a bug-tracker or anything.

Ken Case
2008-02-22, 07:02 AM
Pardon my ignorance, but where would I find this database? I poked around Omni's site but didn't see anything that looked like a bug-tracker or anything.

Oh, sorry! That database is internal. To vote for those features, please send feedback to our support ninjas (by selecting Send Feedback from OmniWeb's Help menu or just writing omniweb@omnigroup.com) and mention that you're interested in those things.

Thanks!

Chiller
2008-02-23, 05:08 PM
Oh, sorry! That database is internal. To vote for those features, please send feedback to our support ninjas (by selecting Send Feedback from OmniWeb's Help menu or just writing omniweb@omnigroup.com) and mention that you're interested in those things.

Thanks!

And thus, the negative side of software that is not open source. FWIW, I would really like to see what is on the plate for features, what is still bugs, etc. However, I am nitpicking. Us OW users are a discriminating type and only want the best for our browser of choice. Thanks!