<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Petko Was Playing With Fire&#8230;</title>
	<link>http://hackademix.net/2008/08/14/petko-was-playing-with-fire/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Fri, 12 Mar 2010 17:38:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/08/14/petko-was-playing-with-fire/#comment-9050</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Tue, 19 Aug 2008 08:08:18 +0000</pubDate>
		<guid>http://hackademix.net/2008/08/14/petko-was-playing-with-fire/#comment-9050</guid>
		<description>@&lt;b&gt;surfergirl&lt;/b&gt;:
I read &lt;a href="http://evajmah.com/files/nomore_Rebranded.pdf" target="_blank" rel="nofollow"&gt;the e-book by Mrs. Suggs&lt;/a&gt;, and it's quite different than you're suggesting.
In facts, it explain web marketer why and how to tell users of their e-commerce sites to "disable" NoScript on their sites, i.e. adding them to their whitelists.

There's no technique to "get around the security features" there yet, and I can assure you there's a lot of people more technically skilled than Mrs. Suggs trying every day :)
Have you got an actual example of bypass occurring to you?</description>
		<content:encoded><![CDATA[<p>@<b>surfergirl</b>:<br />
I read <a href="http://evajmah.com/files/nomore_Rebranded.pdf" target="_blank" rel="nofollow">the e-book by Mrs. Suggs</a>, and it&#8217;s quite different than you&#8217;re suggesting.<br />
In facts, it explain web marketer why and how to tell users of their e-commerce sites to &#8220;disable&#8221; NoScript on their sites, i.e. adding them to their whitelists.</p>
<p>There&#8217;s no technique to &#8220;get around the security features&#8221; there yet, and I can assure you there&#8217;s a lot of people more technically skilled than Mrs. Suggs trying every day :)<br />
Have you got an actual example of bypass occurring to you?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: surfergirl54</title>
		<link>http://hackademix.net/2008/08/14/petko-was-playing-with-fire/#comment-9043</link>
		<dc:creator>surfergirl54</dc:creator>
		<pubDate>Tue, 19 Aug 2008 02:34:31 +0000</pubDate>
		<guid>http://hackademix.net/2008/08/14/petko-was-playing-with-fire/#comment-9043</guid>
		<description>I have one for you. A woman by the name of Sunny Suggs published an E-book about Firefox add-ons specifically NoScript and how internet marketers can get around the security features. As a surfer I detest audio and video starting up without my permission. Suddenly I am not able to stop videos using UTube and some other audio and video, despite the fact that I have these disabled.

Is there a way around this problem, because so far I have not been able to find a solution to stop the stuff that is heavy on bandwidth - my opinion is: If I want to look at the video then I can press the button, do not supply me with something that auto-starts. It is the auto-start that needs to be stopped. Darn shame because NoScript has been working so well.</description>
		<content:encoded><![CDATA[<p>I have one for you. A woman by the name of Sunny Suggs published an E-book about Firefox add-ons specifically NoScript and how internet marketers can get around the security features. As a surfer I detest audio and video starting up without my permission. Suddenly I am not able to stop videos using UTube and some other audio and video, despite the fact that I have these disabled.</p>
<p>Is there a way around this problem, because so far I have not been able to find a solution to stop the stuff that is heavy on bandwidth - my opinion is: If I want to look at the video then I can press the button, do not supply me with something that auto-starts. It is the auto-start that needs to be stopped. Darn shame because NoScript has been working so well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sebastian Tschan</title>
		<link>http://hackademix.net/2008/08/14/petko-was-playing-with-fire/#comment-9024</link>
		<dc:creator>Sebastian Tschan</dc:creator>
		<pubDate>Sun, 17 Aug 2008 11:49:27 +0000</pubDate>
		<guid>http://hackademix.net/2008/08/14/petko-was-playing-with-fire/#comment-9024</guid>
		<description>I'd like to throw in that the &lt;a href="http://securelogin.mozdev.org/" rel="nofollow"&gt;Secure Login&lt;/a&gt; add-on makes Firefox Password Manager somewhat more robust against XSS attacks.

Regards,
Sebastian</description>
		<content:encoded><![CDATA[<p>I&#8217;d like to throw in that the <a href="http://securelogin.mozdev.org/" rel="nofollow">Secure Login</a> add-on makes Firefox Password Manager somewhat more robust against XSS attacks.</p>
<p>Regards,<br />
Sebastian</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/08/14/petko-was-playing-with-fire/#comment-9016</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Sat, 16 Aug 2008 15:06:06 +0000</pubDate>
		<guid>http://hackademix.net/2008/08/14/petko-was-playing-with-fire/#comment-9016</guid>
		<description>@&lt;b&gt;Wladimir Palant&lt;/b&gt;: 
As you know well, relying on AdBlock Plus for security purposes is not advisable, especially until &lt;a href="https://bugzilla.mozilla.org/show_bug.cgi?id=431782" rel="nofollow"&gt;bug 431782&lt;/a&gt; gets fixed.
You don't want to be &lt;a href="http://hackademix.net/2008/06/08/block-rick/" rel="nofollow"&gt;rickrolled&lt;/a&gt; by bad guys, do you? ;)</description>
		<content:encoded><![CDATA[<p>@<b>Wladimir Palant</b>:<br />
As you know well, relying on AdBlock Plus for security purposes is not advisable, especially until <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=431782" rel="nofollow">bug 431782</a> gets fixed.<br />
You don&#8217;t want to be <a href="http://hackademix.net/2008/06/08/block-rick/" rel="nofollow">rickrolled</a> by bad guys, do you? ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wladimir Palant</title>
		<link>http://hackademix.net/2008/08/14/petko-was-playing-with-fire/#comment-9014</link>
		<dc:creator>Wladimir Palant</dc:creator>
		<pubDate>Sat, 16 Aug 2008 14:20:43 +0000</pubDate>
		<guid>http://hackademix.net/2008/08/14/petko-was-playing-with-fire/#comment-9014</guid>
		<description>Password manager has issues, true. Using an external &#34;password manager&#34; is a better solution so far.

As to Prism, even in that unlikely situation, with Adblock Plus and the filter &#34;*$third-party&#34; it will do great (yes, Prism isn't officially supported by Adblock Plus yet, working on that).</description>
		<content:encoded><![CDATA[<p>Password manager has issues, true. Using an external &quot;password manager&quot; is a better solution so far.</p>
<p>As to Prism, even in that unlikely situation, with Adblock Plus and the filter &quot;*$third-party&quot; it will do great (yes, Prism isn&#8217;t officially supported by Adblock Plus yet, working on that).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/08/14/petko-was-playing-with-fire/#comment-8993</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Thu, 14 Aug 2008 09:46:48 +0000</pubDate>
		<guid>http://hackademix.net/2008/08/14/petko-was-playing-with-fire/#comment-8993</guid>
		<description>@&lt;b&gt;Wladimir&lt;/b&gt;:
&lt;blockquote&gt;Well, best solution for this kind of problem is still not staying logged in on a site longer than necessary&lt;/blockquote&gt;
That, and remembering all your passwords without assistance.
If your memory isn't that great and you do use the password manager, I can steal your username and password with no need for you to be logged in (actually, it's even easier when you're logged out).
Regarding Prism, I guess it won't save you either if the malicious content is served by an iframe or an external script embedded in the web application itself.</description>
		<content:encoded><![CDATA[<p>@<b>Wladimir</b>:</p>
<blockquote><p>Well, best solution for this kind of problem is still not staying logged in on a site longer than necessary</p></blockquote>
<p>That, and remembering all your passwords without assistance.<br />
If your memory isn&#8217;t that great and you do use the password manager, I can steal your username and password with no need for you to be logged in (actually, it&#8217;s even easier when you&#8217;re logged out).<br />
Regarding Prism, I guess it won&#8217;t save you either if the malicious content is served by an iframe or an external script embedded in the web application itself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wladimir Palant</title>
		<link>http://hackademix.net/2008/08/14/petko-was-playing-with-fire/#comment-8991</link>
		<dc:creator>Wladimir Palant</dc:creator>
		<pubDate>Thu, 14 Aug 2008 09:00:40 +0000</pubDate>
		<guid>http://hackademix.net/2008/08/14/petko-was-playing-with-fire/#comment-8991</guid>
		<description>Well, best solution for this kind of problem is still not staying logged in on a site longer than necessary. If you need a web application that is constantly running - that's what Prism is for. Separate process, separate environment, no interaction with the browser.</description>
		<content:encoded><![CDATA[<p>Well, best solution for this kind of problem is still not staying logged in on a site longer than necessary. If you need a web application that is constantly running - that&#8217;s what Prism is for. Separate process, separate environment, no interaction with the browser.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
