<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Twitter&#8217;s Clickjacking Saga Continues</title>
	<link>http://hackademix.net/2009/02/27/twitters-clickjacking-saga-continues/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Wed, 08 Feb 2012 12:13:23 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: hackademix.net » Mikeyy's StalkDaily Twitter Worm vs NoScript</title>
		<link>http://hackademix.net/2009/02/27/twitters-clickjacking-saga-continues/#comment-11887</link>
		<dc:creator>hackademix.net » Mikeyy's StalkDaily Twitter Worm vs NoScript</dc:creator>
		<pubDate>Mon, 13 Apr 2009 11:28:59 +0000</pubDate>
		<guid>http://hackademix.net/2009/02/27/twitters-clickjacking-saga-continues/#comment-11887</guid>
		<description>[...] heard the tweets: after several other security issues, including “exotic” ones like Clickjacking or JSON hijacking, Twitter is in serious troubles again, this time with a XSS worm which quickly [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] heard the tweets: after several other security issues, including “exotic” ones like Clickjacking or JSON hijacking, Twitter is in serious troubles again, this time with a XSS worm which quickly [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: drongo</title>
		<link>http://hackademix.net/2009/02/27/twitters-clickjacking-saga-continues/#comment-11272</link>
		<dc:creator>drongo</dc:creator>
		<pubDate>Tue, 03 Mar 2009 19:31:14 +0000</pubDate>
		<guid>http://hackademix.net/2009/02/27/twitters-clickjacking-saga-continues/#comment-11272</guid>
		<description>Hi!
I did put in the settings clearclick protection on both trusted and untrusted sites. Could you add a white listing mechanism  that will  remember like a&#34; photo &#34;( specific ID ) to this case, and if  it don't changed-will not ask me again? 
I think, it is not enough to separate to white and black, because scripts can be changed  on trusted sites by malware/hacker too.
Moreover, i think this analogy you can spread on all NoScript. Any script in trusted list will have an  specific ID, if it will be changed - user will be noticed with ability to action.</description>
		<content:encoded><![CDATA[<p>Hi!<br />
I did put in the settings clearclick protection on both trusted and untrusted sites. Could you add a white listing mechanism  that will  remember like a&quot; photo &quot;( specific ID ) to this case, and if  it don&#8217;t changed-will not ask me again?<br />
I think, it is not enough to separate to white and black, because scripts can be changed  on trusted sites by malware/hacker too.<br />
Moreover, i think this analogy you can spread on all NoScript. Any script in trusted list will have an  specific ID, if it will be changed - user will be noticed with ability to action.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Graham</title>
		<link>http://hackademix.net/2009/02/27/twitters-clickjacking-saga-continues/#comment-11266</link>
		<dc:creator>Tom Graham</dc:creator>
		<pubDate>Tue, 03 Mar 2009 09:01:46 +0000</pubDate>
		<guid>http://hackademix.net/2009/02/27/twitters-clickjacking-saga-continues/#comment-11266</guid>
		<description>Yay! Tiny face is spreading</description>
		<content:encoded><![CDATA[<p>Yay! Tiny face is spreading</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom T.</title>
		<link>http://hackademix.net/2009/02/27/twitters-clickjacking-saga-continues/#comment-11233</link>
		<dc:creator>Tom T.</dc:creator>
		<pubDate>Sat, 28 Feb 2009 05:18:42 +0000</pubDate>
		<guid>http://hackademix.net/2009/02/27/twitters-clickjacking-saga-continues/#comment-11233</guid>
		<description>@duryodhan: It needs to be repeated until the tech community, the tech media, and the public at large learn that Fx with NS is the safest possible browser, and that no other comes close. And if the statement is true, which it is, why shouldn't it be said? Cheers!</description>
		<content:encoded><![CDATA[<p>@duryodhan: It needs to be repeated until the tech community, the tech media, and the public at large learn that Fx with NS is the safest possible browser, and that no other comes close. And if the statement is true, which it is, why shouldn&#8217;t it be said? Cheers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2009/02/27/twitters-clickjacking-saga-continues/#comment-11232</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Fri, 27 Feb 2009 20:20:40 +0000</pubDate>
		<guid>http://hackademix.net/2009/02/27/twitters-clickjacking-saga-continues/#comment-11232</guid>
		<description>@&lt;b&gt;duryodhan&lt;/b&gt;:
it's never said enough. Did you notice that &lt;em&gt;The Register&lt;/em&gt; failed to mention it, for instance? And the name is &lt;a href="http://noscript.net/faq#clearclick" rel="nofollow"&gt;ClearClick&lt;/a&gt;, actually :P</description>
		<content:encoded><![CDATA[<p>@<b>duryodhan</b>:<br />
it&#8217;s never said enough. Did you notice that <em>The Register</em> failed to mention it, for instance? And the name is <a href="http://noscript.net/faq#clearclick" rel="nofollow">ClearClick</a>, actually :P</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: duryodhan</title>
		<link>http://hackademix.net/2009/02/27/twitters-clickjacking-saga-continues/#comment-11231</link>
		<dc:creator>duryodhan</dc:creator>
		<pubDate>Fri, 27 Feb 2009 20:14:27 +0000</pubDate>
		<guid>http://hackademix.net/2009/02/27/twitters-clickjacking-saga-continues/#comment-11231</guid>
		<description>I was wondering .. how come giorgio didn't plug noScript here with the usual -- ONLY NOSCRIPT's ClearJack technology will protect against this  etc.

but then  I found there was a mention of that on the actual page ...

(ok .. I love noscript .. so don't mark me as a troll..just that your last so many posts have gotten me pissed)</description>
		<content:encoded><![CDATA[<p>I was wondering .. how come giorgio didn&#8217;t plug noScript here with the usual &#8212; ONLY NOSCRIPT&#8217;s ClearJack technology will protect against this  etc.</p>
<p>but then  I found there was a mention of that on the actual page &#8230;</p>
<p>(ok .. I love noscript .. so don&#8217;t mark me as a troll..just that your last so many posts have gotten me pissed)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Basti</title>
		<link>http://hackademix.net/2009/02/27/twitters-clickjacking-saga-continues/#comment-11227</link>
		<dc:creator>Basti</dc:creator>
		<pubDate>Fri, 27 Feb 2009 18:41:32 +0000</pubDate>
		<guid>http://hackademix.net/2009/02/27/twitters-clickjacking-saga-continues/#comment-11227</guid>
		<description>&#34;Do you need a bigger one&#34; would be a nice Clickjacking question. ;)</description>
		<content:encoded><![CDATA[<p>&quot;Do you need a bigger one&quot; would be a nice Clickjacking question. ;)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

