<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Misterious Ghost Stories</title>
	<link>http://hackademix.net/2008/05/09/misterious-ghost-stories/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Sun, 06 Jul 2008 19:51:54 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Nathan McFeters</title>
		<link>http://hackademix.net/2008/05/09/misterious-ghost-stories/#comment-7897</link>
		<dc:creator>Nathan McFeters</dc:creator>
		<pubDate>Mon, 12 May 2008 15:02:39 +0000</pubDate>
		<guid>http://hackademix.net/2008/05/09/misterious-ghost-stories/#comment-7897</guid>
		<description>Yeah, I would've loved to give you the details to get it fixed.  Apparently the issue has been fixed in IE, so perhaps sirdarkcat's is a new issue... or a new instance of the same attack.

-Nate</description>
		<content:encoded><![CDATA[<p>Yeah, I would&#8217;ve loved to give you the details to get it fixed.  Apparently the issue has been fixed in IE, so perhaps sirdarkcat&#8217;s is a new issue&#8230; or a new instance of the same attack.</p>
<p>-Nate</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://hackademix.net/2008/05/09/misterious-ghost-stories/#comment-7894</link>
		<dc:creator>James</dc:creator>
		<pubDate>Mon, 12 May 2008 09:39:46 +0000</pubDate>
		<guid>http://hackademix.net/2008/05/09/misterious-ghost-stories/#comment-7894</guid>
		<description>Probably not related, but http://www.thomasfrank.se/sessionvars.html is interesting.</description>
		<content:encoded><![CDATA[<p>Probably not related, but <a href="http://www.thomasfrank.se/sessionvars.html" rel="nofollow">http://www.thomasfrank.se/sessionvars.html</a> is interesting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/05/09/misterious-ghost-stories/#comment-7891</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Mon, 12 May 2008 05:50:38 +0000</pubDate>
		<guid>http://hackademix.net/2008/05/09/misterious-ghost-stories/#comment-7891</guid>
		<description>@&lt;b&gt;Nate&lt;/b&gt;:
No need to explain why you can't give away details, the comment of yours I linked to "&lt;a href="http://talkback.zdnet.com/5208-12691-0.html?forumID=1&#038;threadID=47358&#038;messageID=882431&#038;start=0" target="_blank" rel="nofollow external" rel="nofollow"&gt;pretends&lt;/a&gt;" was clear enough.
I added a smile at the end of the statement you quoted: I was only trying to be ironic about the fact we've got an issue announced and looking like a doomsday device threatening "all browsers", known to an audience of &lt;s&gt;hackers&lt;/s&gt; security researchers who may or may not have good intentions, and no information to build a mitigation plan, other than throw-away browser sessions and &lt;a href="http://noscript.net" rel="nofollow"&gt;our best friend&lt;/a&gt;.

Cheers :)</description>
		<content:encoded><![CDATA[<p>@<b>Nate</b>:<br />
No need to explain why you can&#8217;t give away details, the comment of yours I linked to &#8220;<a href="http://talkback.zdnet.com/5208-12691-0.html?forumID=1&#038;threadID=47358&#038;messageID=882431&#038;start=0" target="_blank" rel="nofollow external" rel="nofollow">pretends</a>&#8221; was clear enough.<br />
I added a smile at the end of the statement you quoted: I was only trying to be ironic about the fact we&#8217;ve got an issue announced and looking like a doomsday device threatening &#8220;all browsers&#8221;, known to an audience of <s>hackers</s> security researchers who may or may not have good intentions, and no information to build a mitigation plan, other than throw-away browser sessions and <a href="http://noscript.net" rel="nofollow">our best friend</a>.</p>
<p>Cheers :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathan McFeters</title>
		<link>http://hackademix.net/2008/05/09/misterious-ghost-stories/#comment-7886</link>
		<dc:creator>Nathan McFeters</dc:creator>
		<pubDate>Sun, 11 May 2008 23:35:02 +0000</pubDate>
		<guid>http://hackademix.net/2008/05/09/misterious-ghost-stories/#comment-7886</guid>
		<description>Yo Georgio!

&#34;Then we’ve got two quite reticent posts by Nate McFeters, who was there but pretends he doesn’t remember well enough and/or he can’t disclose such an atomic bomb.&#34;

Why call me out like that?

There is two points I can say, 

1.) I did see the talk and understand the attack, but I'm not certain I can accurately recount the entire attack vector, nor is it my place since it was someone else's research (Manuel).
2.) I discussed this at length with Microsoft and they asked me not to talk about it for now, as this may still be a useable attack vector on several browsers.  Being that they invited me to a private conference for discussions about research I was working on, and NOT as a journalist, I respect their wishes.  They gave me exclusive coverage of the event, which was very cool of them, and so respecting their wishes about this issue was a small thing to give up.

I just had a look at sirdarkcat's posting... I think it is very similar, but I don't think it's the exact same thing.  Certainly he understands the concepts, but I'll let Manuel or one of the other attendees confirm that.  I wasn't really taking notes on the whole ordeal, as I had some other work I was also doing at the time for my real job, so like I said, not 100% certain of how he did it, the general idea sounds very similar to what sirdarkcat has done, which is very serious in any case.

-Nate</description>
		<content:encoded><![CDATA[<p>Yo Georgio!</p>
<p>&quot;Then we’ve got two quite reticent posts by Nate McFeters, who was there but pretends he doesn’t remember well enough and/or he can’t disclose such an atomic bomb.&quot;</p>
<p>Why call me out like that?</p>
<p>There is two points I can say, </p>
<p>1.) I did see the talk and understand the attack, but I&#8217;m not certain I can accurately recount the entire attack vector, nor is it my place since it was someone else&#8217;s research (Manuel).<br />
2.) I discussed this at length with Microsoft and they asked me not to talk about it for now, as this may still be a useable attack vector on several browsers.  Being that they invited me to a private conference for discussions about research I was working on, and NOT as a journalist, I respect their wishes.  They gave me exclusive coverage of the event, which was very cool of them, and so respecting their wishes about this issue was a small thing to give up.</p>
<p>I just had a look at sirdarkcat&#8217;s posting&#8230; I think it is very similar, but I don&#8217;t think it&#8217;s the exact same thing.  Certainly he understands the concepts, but I&#8217;ll let Manuel or one of the other attendees confirm that.  I wasn&#8217;t really taking notes on the whole ordeal, as I had some other work I was also doing at the time for my real job, so like I said, not 100% certain of how he did it, the general idea sounds very similar to what sirdarkcat has done, which is very serious in any case.</p>
<p>-Nate</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net » Who You Gonna Call?</title>
		<link>http://hackademix.net/2008/05/09/misterious-ghost-stories/#comment-7885</link>
		<dc:creator>hackademix.net » Who You Gonna Call?</dc:creator>
		<pubDate>Sun, 11 May 2008 22:25:44 +0000</pubDate>
		<guid>http://hackademix.net/2008/05/09/misterious-ghost-stories/#comment-7885</guid>
		<description>[...] Misterious Ghost Stories      12 05 2008 [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Misterious Ghost Stories      12 05 2008 [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/05/09/misterious-ghost-stories/#comment-7883</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Sun, 11 May 2008 22:10:06 +0000</pubDate>
		<guid>http://hackademix.net/2008/05/09/misterious-ghost-stories/#comment-7883</guid>
		<description>@&lt;b&gt;Sirdarckcat&lt;/b&gt;:
I Ain't 'fraid of no catz :)
10x!</description>
		<content:encoded><![CDATA[<p>@<b>Sirdarckcat</b>:<br />
I Ain&#8217;t &#8216;fraid of no catz :)<br />
10x!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sirdarckcat</title>
		<link>http://hackademix.net/2008/05/09/misterious-ghost-stories/#comment-7882</link>
		<dc:creator>sirdarckcat</dc:creator>
		<pubDate>Sun, 11 May 2008 21:59:34 +0000</pubDate>
		<guid>http://hackademix.net/2008/05/09/misterious-ghost-stories/#comment-7882</guid>
		<description>Can I Haz Ghostz?
http://sirdarckcat.blogspot.com/2008/05/browsers-ghost-busters.html 


(lol catz have ruined my life)</description>
		<content:encoded><![CDATA[<p>Can I Haz Ghostz?<br />
<a href="http://sirdarckcat.blogspot.com/2008/05/browsers-ghost-busters.html" rel="nofollow">http://sirdarckcat.blogspot.com/2008/05/browsers-ghost-busters.html</a> </p>
<p>(lol catz have ruined my life)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
