the current security.policy restricts connects to
fibs.com only, but the config dialog allows the user to
change the target host to something other than fibs.com
(which will fail the security check). need to do
something to grant permission for other hosts