<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: PayPal is Safer with NoScript</title>
	<link>http://hackademix.net/2009/11/07/paypal-is-safer-with-noscript/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Sat, 31 Jul 2010 04:45:39 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: uberVU - social comments</title>
		<link>http://hackademix.net/2009/11/07/paypal-is-safer-with-noscript/#comment-16228</link>
		<dc:creator>uberVU - social comments</dc:creator>
		<pubDate>Sun, 22 Nov 2009 20:54:15 +0000</pubDate>
		<guid>http://hackademix.net/2009/11/07/paypal-is-safer-with-noscript/#comment-16228</guid>
		<description>&lt;strong&gt;Social comments and analytics for this post&lt;/strong&gt;

This post was mentioned on Twitter by planetmozilla: Giorgio Maone: PayPal is Safer with NoScript: Strict Transport Security (STS) has gone live on PayPal yesterday.. http://bit.ly/3YqKe2</description>
		<content:encoded><![CDATA[<p><strong>Social comments and analytics for this post</strong></p>
<p>This post was mentioned on Twitter by planetmozilla: Giorgio Maone: PayPal is Safer with NoScript: Strict Transport Security (STS) has gone live on PayPal yesterday.. <a href="http://bit.ly/3YqKe2" rel="nofollow">http://bit.ly/3YqKe2</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PayPal is Safer with NoScript [ hackademix.net ]</title>
		<link>http://hackademix.net/2009/11/07/paypal-is-safer-with-noscript/#comment-15900</link>
		<dc:creator>PayPal is Safer with NoScript [ hackademix.net ]</dc:creator>
		<pubDate>Sat, 07 Nov 2009 23:46:26 +0000</pubDate>
		<guid>http://hackademix.net/2009/11/07/paypal-is-safer-with-noscript/#comment-15900</guid>
		<description>[...] PayPal is Safer with NoScript Found 2 hours, 14 minutes ago Strict Transport Security STS has gone live on PayPal yesterday STS is a simple yet effective system for web sites requiring high safety levels eg payment gateways or financial institutions to force HTTPS connections on every request originated by supporting browsers It is currently supported by NoScript Chrome 4 beta and Sid Stamm8217s Force TLS Together with NoScript8217s From: hackademix.net [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] PayPal is Safer with NoScript Found 2 hours, 14 minutes ago Strict Transport Security STS has gone live on PayPal yesterday STS is a simple yet effective system for web sites requiring high safety levels eg payment gateways or financial institutions to force HTTPS connections on every request originated by supporting browsers It is currently supported by NoScript Chrome 4 beta and Sid Stamm8217s Force TLS Together with NoScript8217s From: hackademix.net [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2009/11/07/paypal-is-safer-with-noscript/#comment-15899</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Sat, 07 Nov 2009 22:33:55 +0000</pubDate>
		<guid>http://hackademix.net/2009/11/07/paypal-is-safer-with-noscript/#comment-15899</guid>
		<description>@&lt;a href="http://hackademix.net/2009/11/07/paypal-is-safer-with-noscript/#comment-15892" rel="nofollow"&gt;Alan Baxter&lt;/a&gt;:
No, using the &lt;em&gt;NoScript Options&#124;Advanced&#124;HTTPS&lt;/em&gt; stuff doesn't hurt anything on STS-enabled sites.

Actually, the "normal" (user-driven) HTTPS-enforcing NoScript features can be used to customize STS: for instance, the "never force HTTPS" list does affect STS, allowing you to state user-driven exceptions to the server-driven enforcement.</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2009/11/07/paypal-is-safer-with-noscript/#comment-15892" rel="nofollow">Alan Baxter</a>:<br />
No, using the <em>NoScript Options|Advanced|HTTPS</em> stuff doesn&#8217;t hurt anything on STS-enabled sites.</p>
<p>Actually, the &#8220;normal&#8221; (user-driven) HTTPS-enforcing NoScript features can be used to customize STS: for instance, the &#8220;never force HTTPS&#8221; list does affect STS, allowing you to state user-driven exceptions to the server-driven enforcement.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GµårÐïåñ</title>
		<link>http://hackademix.net/2009/11/07/paypal-is-safer-with-noscript/#comment-15894</link>
		<dc:creator>GµårÐïåñ</dc:creator>
		<pubDate>Sat, 07 Nov 2009 20:35:33 +0000</pubDate>
		<guid>http://hackademix.net/2009/11/07/paypal-is-safer-with-noscript/#comment-15894</guid>
		<description>Well despite the fact that PayPal totally sucks and I hate having to deal with them at all, it is good news that at least with NoScript they are safer to use. I would still be interested to know about what Alan asked, is it a replacement (or redundant) to using Force HTTPS or can they be used in conjunction? If so, will they cause any issues?</description>
		<content:encoded><![CDATA[<p>Well despite the fact that PayPal totally sucks and I hate having to deal with them at all, it is good news that at least with NoScript they are safer to use. I would still be interested to know about what Alan asked, is it a replacement (or redundant) to using Force HTTPS or can they be used in conjunction? If so, will they cause any issues?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alan Baxter</title>
		<link>http://hackademix.net/2009/11/07/paypal-is-safer-with-noscript/#comment-15892</link>
		<dc:creator>Alan Baxter</dc:creator>
		<pubDate>Sat, 07 Nov 2009 17:38:02 +0000</pubDate>
		<guid>http://hackademix.net/2009/11/07/paypal-is-safer-with-noscript/#comment-15892</guid>
		<description>Does it hurt anything if I to continue to force *.paypal.com using the NoScript Force HTTPS facility while never forcing email*.paypal.com?</description>
		<content:encoded><![CDATA[<p>Does it hurt anything if I to continue to force *.paypal.com using the NoScript Force HTTPS facility while never forcing email*.paypal.com?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
