An IT topic for the first time in a while.

Today, ITPro published an article titled “Vulnerability Allowing Spoofed Address-Bar and Certificate Displays in Firefox, Mozilla, and Others”.

It is a very sensational article, but when you read it carefully, it merely says that, with internationalized domain names, mixing full-width and half-width characters can make it possible to direct people to a site whose domain looks like another domain to the human eye.

Let us look at the example. https://www.pаypal.com/ is a legitimately registered domain, pаypal.com. Its site certificate was also obtained for pаypal.com, so it works properly. It is operating entirely legitimately. It is not hacking of any kind. This means something: trying to prove a site’s legitimacy through a combination of a URL and a certificate is completely meaningless. A certificate means only that the owner of that URL exists.

Still, I wonder whether ITPro, which trumpets this as a “vulnerability,” really understands what the article says???