<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Clickjacking Protection by Default</title>
	<link>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Sat, 20 Mar 2010 15:06:54 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: ross alba</title>
		<link>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9761</link>
		<dc:creator>ross alba</dc:creator>
		<pubDate>Sat, 01 Nov 2008 07:03:29 +0000</pubDate>
		<guid>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9761</guid>
		<description>give it atry</description>
		<content:encoded><![CDATA[<p>give it atry</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#124; TechUniverse</title>
		<link>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9631</link>
		<dc:creator>&#124; TechUniverse</dc:creator>
		<pubDate>Tue, 14 Oct 2008 08:37:51 +0000</pubDate>
		<guid>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9631</guid>
		<description>[...] ultime versioni dell’italica estensione, oltre a impedire l’esecuzione di elementi Flash o codice JavaScript non gradito, introducono [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] ultime versioni dell’italica estensione, oltre a impedire l’esecuzione di elementi Flash o codice JavaScript non gradito, introducono [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clickjacking - Scary New Cross Brower Exploit</title>
		<link>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9561</link>
		<dc:creator>Clickjacking - Scary New Cross Brower Exploit</dc:creator>
		<pubDate>Thu, 09 Oct 2008 02:37:19 +0000</pubDate>
		<guid>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9561</guid>
		<description>[...] solution at the moment is to use Firefox with Noscript(an extension for Firefox) addons since specific anti-clickjacking countermeasures are included in latest version (1.8.2) of NoScript. Opera users need to disable Java, Javascript [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] solution at the moment is to use Firefox with Noscript(an extension for Firefox) addons since specific anti-clickjacking countermeasures are included in latest version (1.8.2) of NoScript. Opera users need to disable Java, Javascript [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hello ClearClick, Goodbye Clickjacking! &#124; 洋葱圈</title>
		<link>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9540</link>
		<dc:creator>Hello ClearClick, Goodbye Clickjacking! &#124; 洋葱圈</dc:creator>
		<pubDate>Wed, 08 Oct 2008 11:49:09 +0000</pubDate>
		<guid>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9540</guid>
		<description>[...] NoScript 1.8.2.1 is out, featuring the announced new anti-clickjacking countermeasures enabled by default, independent from IFRAME and plugin [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] NoScript 1.8.2.1 is out, featuring the announced new anti-clickjacking countermeasures enabled by default, independent from IFRAME and plugin [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net » Hello ClearClick, Goodbye Clickjacking!</title>
		<link>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9528</link>
		<dc:creator>hackademix.net » Hello ClearClick, Goodbye Clickjacking!</dc:creator>
		<pubDate>Tue, 07 Oct 2008 22:27:53 +0000</pubDate>
		<guid>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9528</guid>
		<description>[...] Clickjacking Protection by Default      08 10 2008 [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Clickjacking Protection by Default      08 10 2008 [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shadow Security - ¿Clickjacking con Firefox y NoScript instalado? (II)</title>
		<link>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9515</link>
		<dc:creator>Shadow Security - ¿Clickjacking con Firefox y NoScript instalado? (II)</dc:creator>
		<pubDate>Tue, 07 Oct 2008 00:06:50 +0000</pubDate>
		<guid>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9515</guid>
		<description>[...] la información ya que Maone confirma lo preguntado por mí y también menciona que en NoScript se habilita la protección de IFRAMES por defecto en la última versón y en 0×000000 confirman lo dicho por Maone. Además Maone también explica algunas formas de [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] la información ya que Maone confirma lo preguntado por mí y también menciona que en NoScript se habilita la protección de IFRAMES por defecto en la última versón y en 0×000000 confirman lo dicho por Maone. Además Maone también explica algunas formas de [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9500</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Sat, 04 Oct 2008 14:48:21 +0000</pubDate>
		<guid>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9500</guid>
		<description>@&lt;b&gt;questioner&lt;/b&gt;:
If Ronald did not disclose the OBJECT-based IFRAME blocking work-around, I would have said just wait for 1.8.2 keeping "Forbid IFRAME" on, but now  there's a slight chance some bad guy already figured how clickjacking works (easy) and deems valuable the extra effort to bypass IFRAME protection (less likely), therefore my recommendation to get 1.8.1.9 -- thank Ronald for this hassle ;)
Anyway I'll release 1.8.2 tomorrow at most.</description>
		<content:encoded><![CDATA[<p>@<b>questioner</b>:<br />
If Ronald did not disclose the OBJECT-based IFRAME blocking work-around, I would have said just wait for 1.8.2 keeping &#8220;Forbid IFRAME&#8221; on, but now  there&#8217;s a slight chance some bad guy already figured how clickjacking works (easy) and deems valuable the extra effort to bypass IFRAME protection (less likely), therefore my recommendation to get 1.8.1.9 &#8212; thank Ronald for this hassle ;)<br />
Anyway I&#8217;ll release 1.8.2 tomorrow at most.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: questioner</title>
		<link>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9499</link>
		<dc:creator>questioner</dc:creator>
		<pubDate>Sat, 04 Oct 2008 14:41:09 +0000</pubDate>
		<guid>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9499</guid>
		<description>Hi - I have a question because I am a little confused: 

As an usual everyday user -  is there a special reson (like an accute actual security threat) to make this very big upgrade neccessary? or can I simply wait until the newest versions (my actual here is V. 1.8.1.3) without any harm???</description>
		<content:encoded><![CDATA[<p>Hi - I have a question because I am a little confused: </p>
<p>As an usual everyday user -  is there a special reson (like an accute actual security threat) to make this very big upgrade neccessary? or can I simply wait until the newest versions (my actual here is V. 1.8.1.3) without any harm???</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rvdh</title>
		<link>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9495</link>
		<dc:creator>rvdh</dc:creator>
		<pubDate>Sat, 04 Oct 2008 01:55:39 +0000</pubDate>
		<guid>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9495</guid>
		<description>Curious, it seems fixed as well in the new build I just tested. Good job Giorgio! I can get some sleep again :)</description>
		<content:encoded><![CDATA[<p>Curious, it seems fixed as well in the new build I just tested. Good job Giorgio! I can get some sleep again :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rvdh</title>
		<link>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9494</link>
		<dc:creator>rvdh</dc:creator>
		<pubDate>Sat, 04 Oct 2008 01:29:30 +0000</pubDate>
		<guid>http://hackademix.net/2008/10/02/clickjacking-protection-by-default/#comment-9494</guid>
		<description>I was saying: You forgot EMBED SRC=&#34;&#34; as well. it got stripped somehow.</description>
		<content:encoded><![CDATA[<p>I was saying: You forgot EMBED SRC=&quot;&quot; as well. it got stripped somehow.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
