<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: NoScript vs Insecure Cookies</title>
	<link>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Wed, 08 Feb 2012 12:01:04 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: hackademix.net » You Don't Know What My Twitter Leaks</title>
		<link>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-10360</link>
		<dc:creator>hackademix.net » You Don't Know What My Twitter Leaks</dc:creator>
		<pubDate>Mon, 12 Jan 2009 22:10:16 +0000</pubDate>
		<guid>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-10360</guid>
		<description>[...] to your HTTPS behavior forced list and enabling automatic secure cookies management, to defeat cookie hijacking [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] to your HTTPS behavior forced list and enabling automatic secure cookies management, to defeat cookie hijacking [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9932</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Thu, 27 Nov 2008 21:29:09 +0000</pubDate>
		<guid>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9932</guid>
		<description>@&lt;b&gt;Keybounce&lt;/b&gt;:
account info (not service authorization!) is on cookie belonging to www.google.com. This means that you can leak your user id token, but not your authorization token.
BTW, there's no default for forcing secure cookies anymore.
For your purposes, putting "google.com" in your &lt;em&gt;NoScript Options&#124;Advanced&#124;HTTPS&#124;Cookies&#124;Force encryption for all the cookies...&lt;/em&gt; list should suffice.</description>
		<content:encoded><![CDATA[<p>@<b>Keybounce</b>:<br />
account info (not service authorization!) is on cookie belonging to <a href="http://www.google.com." rel="nofollow">www.google.com.</a> This means that you can leak your user id token, but not your authorization token.<br />
BTW, there&#8217;s no default for forcing secure cookies anymore.<br />
For your purposes, putting &#8220;google.com&#8221; in your <em>NoScript Options|Advanced|HTTPS|Cookies|Force encryption for all the cookies&#8230;</em> list should suffice.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Keybounce</title>
		<link>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9931</link>
		<dc:creator>Keybounce</dc:creator>
		<pubDate>Thu, 27 Nov 2008 20:58:52 +0000</pubDate>
		<guid>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9931</guid>
		<description>... 1.8.0.6 switches to an opt-in policy controlled by the noscript.secureCookiesForced preference, whose default will be “www.google.com, gmail.google.com”. ...

What about all the rest of the stuff at google?

Reader, maps, news, personalized home page, ** DOCS **, etc.

Most of the pages support secure stuff. Right now I have &#34;Always use HTTPS&#34; in gmail, and I have the newest noscript, yet going to the insecure pages (such as www.google.com) still identify me by email.

Gaa, there's a noscript warning below me, with a recaptcha. Hope this works.</description>
		<content:encoded><![CDATA[<p>&#8230; 1.8.0.6 switches to an opt-in policy controlled by the noscript.secureCookiesForced preference, whose default will be “www.google.com, gmail.google.com”. &#8230;</p>
<p>What about all the rest of the stuff at google?</p>
<p>Reader, maps, news, personalized home page, ** DOCS **, etc.</p>
<p>Most of the pages support secure stuff. Right now I have &quot;Always use HTTPS&quot; in gmail, and I have the newest noscript, yet going to the insecure pages (such as <a href="http://www.google.com" rel="nofollow">www.google.com</a>) still identify me by email.</p>
<p>Gaa, there&#8217;s a noscript warning below me, with a recaptcha. Hope this works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wat sind eigentlich flash-cookies? &#124; Der Gretzer</title>
		<link>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9584</link>
		<dc:creator>Wat sind eigentlich flash-cookies? &#124; Der Gretzer</dc:creator>
		<pubDate>Fri, 10 Oct 2008 17:49:16 +0000</pubDate>
		<guid>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9584</guid>
		<description>[...] NoScript vs Insecure Cookies [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] NoScript vs Insecure Cookies [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blaise Alleyne</title>
		<link>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9310</link>
		<dc:creator>Blaise Alleyne</dc:creator>
		<pubDate>Fri, 19 Sep 2008 17:42:27 +0000</pubDate>
		<guid>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9310</guid>
		<description>@Giorgio
Turns out I did have an older version, it was just auto-updated to 1.8.1.3 and the Twitter fix was explicitly mentioned in the release notes. Thanks!</description>
		<content:encoded><![CDATA[<p>@Giorgio<br />
Turns out I did have an older version, it was just auto-updated to 1.8.1.3 and the Twitter fix was explicitly mentioned in the release notes. Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9306</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Thu, 18 Sep 2008 21:55:25 +0000</pubDate>
		<guid>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9306</guid>
		<description>@&lt;b&gt;Blaise Alleyne&lt;/b&gt;:
some of the early versions could, but latest &lt;a href="http://noscript.net/getit#direct" rel="nofollow"&gt;stable&lt;/a&gt; and &lt;a href="http://noscript.net/getit#develt" rel="nofollow"&gt;development&lt;/a&gt; versions of NoScript have no problem with  logins.</description>
		<content:encoded><![CDATA[<p>@<b>Blaise Alleyne</b>:<br />
some of the early versions could, but latest <a href="http://noscript.net/getit#direct" rel="nofollow">stable</a> and <a href="http://noscript.net/getit#develt" rel="nofollow">development</a> versions of NoScript have no problem with  logins.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blaise Alleyne</title>
		<link>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9305</link>
		<dc:creator>Blaise Alleyne</dc:creator>
		<pubDate>Thu, 18 Sep 2008 21:29:10 +0000</pubDate>
		<guid>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9305</guid>
		<description>In the last few days, I've been unable to log into del.icio.us, Twitter and Fire Eagle. I just disabled NoScript, and now I can login fine.

Could this new feature be getting in my way?</description>
		<content:encoded><![CDATA[<p>In the last few days, I&#8217;ve been unable to log into del.icio.us, Twitter and Fire Eagle. I just disabled NoScript, and now I can login fine.</p>
<p>Could this new feature be getting in my way?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ammad</title>
		<link>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9258</link>
		<dc:creator>ammad</dc:creator>
		<pubDate>Thu, 11 Sep 2008 23:25:12 +0000</pubDate>
		<guid>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9258</guid>
		<description>What if Noscript checks whether a site sends bad cookies and just warns the user, like xss does now?</description>
		<content:encoded><![CDATA[<p>What if Noscript checks whether a site sends bad cookies and just warns the user, like xss does now?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zero Day mobile edition</title>
		<link>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9253</link>
		<dc:creator>Zero Day mobile edition</dc:creator>
		<pubDate>Thu, 11 Sep 2008 13:36:09 +0000</pubDate>
		<guid>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9253</guid>
		<description>[...] 10 free security utilities you should already be using ]  Maone described the new feature as a countermeasure against Mike Perry's automated HTTPS cookie-hijacking attack (see CookieMonster tool) that's [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] 10 free security utilities you should already be using ]  Maone described the new feature as a countermeasure against Mike Perry&#8217;s automated HTTPS cookie-hijacking attack (see CookieMonster tool) that&#8217;s [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Philipp</title>
		<link>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9252</link>
		<dc:creator>Philipp</dc:creator>
		<pubDate>Thu, 11 Sep 2008 12:55:13 +0000</pubDate>
		<guid>http://hackademix.net/2008/09/10/noscript-vs-insecure-cookies/#comment-9252</guid>
		<description>PS: It may be noted however that this Add-on unfortunately does not work with sites redirected to by POST or embedded content (images, objects).</description>
		<content:encoded><![CDATA[<p>PS: It may be noted however that this Add-on unfortunately does not work with sites redirected to by POST or embedded content (images, objects).</p>
]]></content:encoded>
	</item>
</channel>
</rss>

