<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Start Panicking!</title>
	<link>http://hackademix.net/2009/05/08/start-panicking/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Tue, 07 Feb 2012 09:19:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2009/05/08/start-panicking/#comment-13174</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Sun, 07 Jun 2009 09:38:16 +0000</pubDate>
		<guid>http://hackademix.net/2009/05/08/start-panicking/#comment-13174</guid>
		<description>@&lt;a href="http://hackademix.net/2009/05/08/start-panicking/#comment-13159" rel="nofollow"&gt;rvdh&lt;/a&gt;:
Did you notice the OP starts with "Nothing new" linked to a... what? ... 3 years old article? :P</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2009/05/08/start-panicking/#comment-13159" rel="nofollow">rvdh</a>:<br />
Did you notice the OP starts with &#8220;Nothing new&#8221; linked to a&#8230; what? &#8230; 3 years old article? :P</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rvdh</title>
		<link>http://hackademix.net/2009/05/08/start-panicking/#comment-13159</link>
		<dc:creator>rvdh</dc:creator>
		<pubDate>Sat, 06 Jun 2009 10:26:13 +0000</pubDate>
		<guid>http://hackademix.net/2009/05/08/start-panicking/#comment-13159</guid>
		<description>fuck this is ..what.. 3 years old news? am I the only one without amnesia or what?</description>
		<content:encoded><![CDATA[<p>fuck this is ..what.. 3 years old news? am I the only one without amnesia or what?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2009/05/08/start-panicking/#comment-12664</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Wed, 13 May 2009 17:21:39 +0000</pubDate>
		<guid>http://hackademix.net/2009/05/08/start-panicking/#comment-12664</guid>
		<description>@&lt;a href="http://hackademix.net/2009/05/08/start-panicking/#comment-12659" rel="nofollow"&gt;Nilesh&lt;/a&gt;:
&lt;blockquote&gt;The bug lifts information about visited website from the history. Isn’t it?&lt;/blockquote&gt;
Yes. More precisely, attackers can tell if a certain URL is present in your history or not (they're using a list of 100,000 to be impressive).

&lt;blockquote&gt;Is IE also susceptible?&lt;/blockquote&gt;
Of course it is. Every modern browser susceptible.

&lt;blockquote&gt;My IE 7.0 gets hanged whenever I visit startpnaic.com and click Check. Why?&lt;/blockquote&gt;
Because its JavaScript interpreter sucks?</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2009/05/08/start-panicking/#comment-12659" rel="nofollow">Nilesh</a>:</p>
<blockquote><p>The bug lifts information about visited website from the history. Isn’t it?</p></blockquote>
<p>Yes. More precisely, attackers can tell if a certain URL is present in your history or not (they&#8217;re using a list of 100,000 to be impressive).</p>
<blockquote><p>Is IE also susceptible?</p></blockquote>
<p>Of course it is. Every modern browser susceptible.</p>
<blockquote><p>My IE 7.0 gets hanged whenever I visit startpnaic.com and click Check. Why?</p></blockquote>
<p>Because its JavaScript interpreter sucks?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nilesh</title>
		<link>http://hackademix.net/2009/05/08/start-panicking/#comment-12659</link>
		<dc:creator>Nilesh</dc:creator>
		<pubDate>Wed, 13 May 2009 05:38:21 +0000</pubDate>
		<guid>http://hackademix.net/2009/05/08/start-panicking/#comment-12659</guid>
		<description>Hi Giorgio,

    When I cleared the history of Mozilla FF, visiting on startpanic.com didn't yield any result. The bug lifts information about visited website from the history. Isn't it? Is IE also susceptible? My IE 7.0 gets hanged whenever I visit startpnaic.com and click Check. Why?</description>
		<content:encoded><![CDATA[<p>Hi Giorgio,</p>
<p>    When I cleared the history of Mozilla FF, visiting on startpanic.com didn&#8217;t yield any result. The bug lifts information about visited website from the history. Isn&#8217;t it? Is IE also susceptible? My IE 7.0 gets hanged whenever I visit startpnaic.com and click Check. Why?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: A bug in Firefox can detect which sites you have visited - profirefox.org</title>
		<link>http://hackademix.net/2009/05/08/start-panicking/#comment-12627</link>
		<dc:creator>A bug in Firefox can detect which sites you have visited - profirefox.org</dc:creator>
		<pubDate>Mon, 11 May 2009 12:31:21 +0000</pubDate>
		<guid>http://hackademix.net/2009/05/08/start-panicking/#comment-12627</guid>
		<description>[...] Mozilla is already working on this bug. [via Giorgio Maone's blog] [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Mozilla is already working on this bug. [via Giorgio Maone&#8217;s blog] [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2009/05/08/start-panicking/#comment-12609</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Sun, 10 May 2009 12:21:27 +0000</pubDate>
		<guid>http://hackademix.net/2009/05/08/start-panicking/#comment-12609</guid>
		<description>@&lt;a href="http://hackademix.net/2009/05/08/start-panicking/#comment-12566" rel="nofollow"&gt;AndreH&lt;/a&gt;:
&lt;pre&gt;
curl http://startpanic.com/db/db_en.txt &#124; wc -l
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100 1386k  100 1386k    0     0   117k      0  0:00:11  0:00:11 --:--:--  133k
100000
&lt;/pre&gt;
As you can see there are 100,000 domains in that list, for more than 1MB file size, which you're proposing to turn in server-side generated styled links to be downloaded.
Consider also that a scriptless approach requires one separate HTTP request (and database write) for each single domains found in history, while with JavaScript you can coalesce the logging in one single request/write. 
So I can hardly imagine an attacker preferring the scriptless way over the JavaScript one in a real world scenario, aside very motivated targeted attacks against a specific NoScript user.

@&lt;a href="http://hackademix.net/2009/05/08/start-panicking/#comment-12595" rel="nofollow"&gt;Dom&lt;/a&gt;:
&lt;blockquote&gt;Will the Firefox fix have the same functionality as SafeHistory?&lt;/blockquote&gt;
Nope. If you look at the bug report, you'll find I repeatedly suggested that was the right approach, however the current &#34;solution&#34; breaks the :visited functionality entirely and therefore is obviously disabled by default.

@&lt;a href="http://hackademix.net/2009/05/08/start-panicking/#comment-12598" rel="nofollow"&gt;Basti&lt;/a&gt;:
I heard of a compatible beta, but I can't find it right now.
There's no alternative, I'm afraid.</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2009/05/08/start-panicking/#comment-12566" rel="nofollow">AndreH</a>:</p>
<pre>
curl <a href="http://startpanic.com/db/db_en.txt" rel="nofollow">http://startpanic.com/db/db_en.txt</a> | wc -l
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100 1386k  100 1386k    0     0   117k      0  0:00:11  0:00:11 &#8211;:&#8211;:&#8211;  133k
100000
</pre>
<p>As you can see there are 100,000 domains in that list, for more than 1MB file size, which you&#8217;re proposing to turn in server-side generated styled links to be downloaded.<br />
Consider also that a scriptless approach requires one separate HTTP request (and database write) for each single domains found in history, while with JavaScript you can coalesce the logging in one single request/write.<br />
So I can hardly imagine an attacker preferring the scriptless way over the JavaScript one in a real world scenario, aside very motivated targeted attacks against a specific NoScript user.</p>
<p>@<a href="http://hackademix.net/2009/05/08/start-panicking/#comment-12595" rel="nofollow">Dom</a>:</p>
<blockquote><p>Will the Firefox fix have the same functionality as SafeHistory?</p></blockquote>
<p>Nope. If you look at the bug report, you&#8217;ll find I repeatedly suggested that was the right approach, however the current &quot;solution&quot; breaks the :visited functionality entirely and therefore is obviously disabled by default.</p>
<p>@<a href="http://hackademix.net/2009/05/08/start-panicking/#comment-12598" rel="nofollow">Basti</a>:<br />
I heard of a compatible beta, but I can&#8217;t find it right now.<br />
There&#8217;s no alternative, I&#8217;m afraid.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Basti</title>
		<link>http://hackademix.net/2009/05/08/start-panicking/#comment-12598</link>
		<dc:creator>Basti</dc:creator>
		<pubDate>Sun, 10 May 2009 07:07:46 +0000</pubDate>
		<guid>http://hackademix.net/2009/05/08/start-panicking/#comment-12598</guid>
		<description>I used SafeHistory before, but it's not compatible with Firefox 3. I know how to patch it, but I don't think it's a good idea. Does any one know an alternative?</description>
		<content:encoded><![CDATA[<p>I used SafeHistory before, but it&#8217;s not compatible with Firefox 3. I know how to patch it, but I don&#8217;t think it&#8217;s a good idea. Does any one know an alternative?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sirdarckcat</title>
		<link>http://hackademix.net/2009/05/08/start-panicking/#comment-12597</link>
		<dc:creator>sirdarckcat</dc:creator>
		<pubDate>Sun, 10 May 2009 06:38:11 +0000</pubDate>
		<guid>http://hackademix.net/2009/05/08/start-panicking/#comment-12597</guid>
		<description>I like CSSH more.. haha we can crawl which links you entered in each website.

http://eaea.sirdarckcat.net/cssh-mon/cssh-mon.php

Greetz!!</description>
		<content:encoded><![CDATA[<p>I like CSSH more.. haha we can crawl which links you entered in each website.</p>
<p><a href="http://eaea.sirdarckcat.net/cssh-mon/cssh-mon.php" rel="nofollow">http://eaea.sirdarckcat.net/cssh-mon/cssh-mon.php</a></p>
<p>Greetz!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dom</title>
		<link>http://hackademix.net/2009/05/08/start-panicking/#comment-12595</link>
		<dc:creator>Dom</dc:creator>
		<pubDate>Sun, 10 May 2009 02:39:47 +0000</pubDate>
		<guid>http://hackademix.net/2009/05/08/start-panicking/#comment-12595</guid>
		<description>Will the Firefox fix have the same functionality as SafeHistory?</description>
		<content:encoded><![CDATA[<p>Will the Firefox fix have the same functionality as SafeHistory?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GµårÐïåñ</title>
		<link>http://hackademix.net/2009/05/08/start-panicking/#comment-12589</link>
		<dc:creator>GµårÐïåñ</dc:creator>
		<pubDate>Sat, 09 May 2009 21:30:28 +0000</pubDate>
		<guid>http://hackademix.net/2009/05/08/start-panicking/#comment-12589</guid>
		<description>Giorgio, I love SafeHistory but the problem is that it has not been updated for a long while and it causes some issues in Fx 3 but for me NoScript seems to be pretty effective and the fact that I don't maintain a history at all.</description>
		<content:encoded><![CDATA[<p>Giorgio, I love SafeHistory but the problem is that it has not been updated for a long while and it causes some issues in Fx 3 but for me NoScript seems to be pretty effective and the fact that I don&#8217;t maintain a history at all.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

