<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Introducing ABE</title>
	<link>http://hackademix.net/2008/12/20/introducing-abe/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Thu, 18 Mar 2010 14:05:32 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Seth Wisely</title>
		<link>http://hackademix.net/2008/12/20/introducing-abe/#comment-15206</link>
		<dc:creator>Seth Wisely</dc:creator>
		<pubDate>Wed, 07 Oct 2009 23:13:02 +0000</pubDate>
		<guid>http://hackademix.net/2008/12/20/introducing-abe/#comment-15206</guid>
		<description>Was there a bit of federalism on your mind when you coined the name?

Have you considered creating a fox 3.5+ GUI manager for Security Policies?

Though as number of security extensions in a profile increases so does the load.  I sometimes pine for proxomitron.</description>
		<content:encoded><![CDATA[<p>Was there a bit of federalism on your mind when you coined the name?</p>
<p>Have you considered creating a fox 3.5+ GUI manager for Security Policies?</p>
<p>Though as number of security extensions in a profile increases so does the load.  I sometimes pine for proxomitron.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net » Meet ABE</title>
		<link>http://hackademix.net/2008/12/20/introducing-abe/#comment-13573</link>
		<dc:creator>hackademix.net » Meet ABE</dc:creator>
		<pubDate>Mon, 29 Jun 2009 23:49:57 +0000</pubDate>
		<guid>http://hackademix.net/2008/12/20/introducing-abe/#comment-13573</guid>
		<description>[...] been quite a long development journey since my first announcement, made possible by NLNet’s foresight, and it required more than one month of beta testing: [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] been quite a long development journey since my first announcement, made possible by NLNet’s foresight, and it required more than one month of beta testing: [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom  T.</title>
		<link>http://hackademix.net/2008/12/20/introducing-abe/#comment-12959</link>
		<dc:creator>Tom  T.</dc:creator>
		<pubDate>Thu, 28 May 2009 08:25:46 +0000</pubDate>
		<guid>http://hackademix.net/2008/12/20/introducing-abe/#comment-12959</guid>
		<description>@&lt;b&gt;Giorgio&lt;/b&gt;: When do you hope to have a dummy-friendly addition to the NoScript FAQ? That would also be good to link to in the support forum --  perhaps in GµårÐïåñ's proposed sticky? 

Minor feat req: Is there any possibility to allow &#34;preview comment&#34; here  for the benefit of poor typist like myself? :)

@&lt;b&gt;GµårÐïåñ&lt;/b&gt;: If you are going to do a forum sticky, perhaps you could also draft the FAQ addition in plain language accessible to novice-to-average users, and help take that load off Giorgio? This would reduce the need for individual forum questions even more. Thanks.</description>
		<content:encoded><![CDATA[<p>@<b>Giorgio</b>: When do you hope to have a dummy-friendly addition to the NoScript FAQ? That would also be good to link to in the support forum &#8212;  perhaps in GµårÐïåñ&#8217;s proposed sticky? </p>
<p>Minor feat req: Is there any possibility to allow &quot;preview comment&quot; here  for the benefit of poor typist like myself? :)</p>
<p>@<b>GµårÐïåñ</b>: If you are going to do a forum sticky, perhaps you could also draft the FAQ addition in plain language accessible to novice-to-average users, and help take that load off Giorgio? This would reduce the need for individual forum questions even more. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GµårÐïåñ</title>
		<link>http://hackademix.net/2008/12/20/introducing-abe/#comment-11909</link>
		<dc:creator>GµårÐïåñ</dc:creator>
		<pubDate>Tue, 14 Apr 2009 02:57:43 +0000</pubDate>
		<guid>http://hackademix.net/2008/12/20/introducing-abe/#comment-11909</guid>
		<description>Giorgio, can I make this post a sticky on the forum for NoScript. I believe it will reduce the repeated requests for having true-site-specific blocking/allowing feature requests. This tells them its in the works and should reduce the forum load. Let me know and I will prepare and post a summary and link to this.</description>
		<content:encoded><![CDATA[<p>Giorgio, can I make this post a sticky on the forum for NoScript. I believe it will reduce the repeated requests for having true-site-specific blocking/allowing feature requests. This tells them its in the works and should reduce the forum load. Let me know and I will prepare and post a summary and link to this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: owaspscrubbr - Search your databases for stored cross-site scripting (XSS) attacks. &#124; PenTestIT</title>
		<link>http://hackademix.net/2008/12/20/introducing-abe/#comment-11401</link>
		<dc:creator>owaspscrubbr - Search your databases for stored cross-site scripting (XSS) attacks. &#124; PenTestIT</dc:creator>
		<pubDate>Sat, 14 Mar 2009 08:40:35 +0000</pubDate>
		<guid>http://hackademix.net/2008/12/20/introducing-abe/#comment-11401</guid>
		<description>[...] Introducing ABE [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Introducing ABE [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net » IE8's &#34;Clickjacking Protection&#34; Exposed</title>
		<link>http://hackademix.net/2008/12/20/introducing-abe/#comment-10654</link>
		<dc:creator>hackademix.net » IE8's &#34;Clickjacking Protection&#34; Exposed</dc:creator>
		<pubDate>Wed, 28 Jan 2009 15:18:40 +0000</pubDate>
		<guid>http://hackademix.net/2008/12/20/introducing-abe/#comment-10654</guid>
		<description>[...] support: that’s relatively easy, since I can hook in the work I’m already doing for the ABE module. It’s worth noticing, though, that this is just a cross-browser compatibility effort: neither [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] support: that’s relatively easy, since I can hook in the work I’m already doing for the ABE module. It’s worth noticing, though, that this is just a cross-browser compatibility effort: neither [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net » Ehy IE8, I Can Has Some Clickjacking Protection?</title>
		<link>http://hackademix.net/2008/12/20/introducing-abe/#comment-10628</link>
		<dc:creator>hackademix.net » Ehy IE8, I Can Has Some Clickjacking Protection?</dc:creator>
		<pubDate>Tue, 27 Jan 2009 14:46:05 +0000</pubDate>
		<guid>http://hackademix.net/2008/12/20/introducing-abe/#comment-10628</guid>
		<description>[...] suggested as fix #1 in Michal Zalewski historical “UI Redressing” post and to ABE’s SUBdocument rules) offers an alternate options which, currently, works only in IE8 RC1. Funny how Microsoft can turn [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] suggested as fix #1 in Michal Zalewski historical “UI Redressing” post and to ABE’s SUBdocument rules) offers an alternate options which, currently, works only in IE8 RC1. Funny how Microsoft can turn [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/12/20/introducing-abe/#comment-10420</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Thu, 15 Jan 2009 17:44:55 +0000</pubDate>
		<guid>http://hackademix.net/2008/12/20/introducing-abe/#comment-10420</guid>
		<description>@&lt;b&gt;tlu&lt;/b&gt;:
dom.disable_cookie_* is not a CSRF countermeasure at all. 
It might mitigate some XSS attacks (those which specifically try to log session cookie on a remote server by reading document.cookie), but would break lots of web sites and would not prevent session-riding attacks, which just need you to be logged in: this means a good part of XSS attacks and the totality of the CSRF ones.</description>
		<content:encoded><![CDATA[<p>@<b>tlu</b>:<br />
dom.disable_cookie_* is not a CSRF countermeasure at all.<br />
It might mitigate some XSS attacks (those which specifically try to log session cookie on a remote server by reading document.cookie), but would break lots of web sites and would not prevent session-riding attacks, which just need you to be logged in: this means a good part of XSS attacks and the totality of the CSRF ones.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tlu</title>
		<link>http://hackademix.net/2008/12/20/introducing-abe/#comment-10416</link>
		<dc:creator>tlu</dc:creator>
		<pubDate>Thu, 15 Jan 2009 16:18:51 +0000</pubDate>
		<guid>http://hackademix.net/2008/12/20/introducing-abe/#comment-10416</guid>
		<description>Very good work, Giorgio, as usual.

What do you think about adding

user_pref(&#34;dom.disable_cookie_get&#34;,true);
user_pref(&#34;dom.disable_cookie_set&#34;,true);

to user.js as a CSRF countermeasure?</description>
		<content:encoded><![CDATA[<p>Very good work, Giorgio, as usual.</p>
<p>What do you think about adding</p>
<p>user_pref(&quot;dom.disable_cookie_get&quot;,true);<br />
user_pref(&quot;dom.disable_cookie_set&quot;,true);</p>
<p>to user.js as a CSRF countermeasure?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/12/20/introducing-abe/#comment-10337</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Sat, 10 Jan 2009 17:06:05 +0000</pubDate>
		<guid>http://hackademix.net/2008/12/20/introducing-abe/#comment-10337</guid>
		<description>@&lt;b&gt;botted&lt;/b&gt;:
Current NoScript in its default configuration (without ABE) is enough to easily defeat JavaScript-based malware.
Notice that script files aren't even requested by Firefox if blocked by NoScript, therefore an external firewall shouldn't complain (opposite to what suggested by one poster on that thread) unless the detected sample is inlined in an HTML file.</description>
		<content:encoded><![CDATA[<p>@<b>botted</b>:<br />
Current NoScript in its default configuration (without ABE) is enough to easily defeat JavaScript-based malware.<br />
Notice that script files aren&#8217;t even requested by Firefox if blocked by NoScript, therefore an external firewall shouldn&#8217;t complain (opposite to what suggested by one poster on that thread) unless the detected sample is inlined in an HTML file.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
