<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Microsoft Recommends NoScript</title>
	<link>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Wed, 08 Feb 2012 12:03:15 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Dauns Wurst</title>
		<link>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22937</link>
		<dc:creator>Dauns Wurst</dc:creator>
		<pubDate>Mon, 26 Apr 2010 23:17:02 +0000</pubDate>
		<guid>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22937</guid>
		<description>Forget what I wrote, I was in a hurry.</description>
		<content:encoded><![CDATA[<p>Forget what I wrote, I was in a hurry.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dauns Wurst</title>
		<link>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22936</link>
		<dc:creator>Dauns Wurst</dc:creator>
		<pubDate>Mon, 26 Apr 2010 23:16:40 +0000</pubDate>
		<guid>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22936</guid>
		<description>Forgot what I wrote, I was in a hurry.</description>
		<content:encoded><![CDATA[<p>Forgot what I wrote, I was in a hurry.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dauns Wurst</title>
		<link>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22935</link>
		<dc:creator>Dauns Wurst</dc:creator>
		<pubDate>Mon, 26 Apr 2010 22:49:35 +0000</pubDate>
		<guid>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22935</guid>
		<description>So according to this chart NoScripts XSS is bypassable, but in what sense? Generally or just in special cases, because latter was and probably always will be the case.</description>
		<content:encoded><![CDATA[<p>So according to this chart NoScripts XSS is bypassable, but in what sense? Generally or just in special cases, because latter was and probably always will be the case.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sirdarckcat</title>
		<link>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22925</link>
		<dc:creator>sirdarckcat</dc:creator>
		<pubDate>Thu, 22 Apr 2010 15:10:49 +0000</pubDate>
		<guid>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22925</guid>
		<description>Hey!

So, yeah.. NoScript is safer, because it stops requests from happening in the first place, however that makes it have a bigger false positive ratio.

In terms of which one is harder to bypass, the winner is IE8, followed by NoScript, followed by Chrome.. considering that it takes days to bypass IE8, as opposed to chrome/noscript.

Greetings!!</description>
		<content:encoded><![CDATA[<p>Hey!</p>
<p>So, yeah.. NoScript is safer, because it stops requests from happening in the first place, however that makes it have a bigger false positive ratio.</p>
<p>In terms of which one is harder to bypass, the winner is IE8, followed by NoScript, followed by Chrome.. considering that it takes days to bypass IE8, as opposed to chrome/noscript.</p>
<p>Greetings!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22924</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Thu, 22 Apr 2010 06:40:48 +0000</pubDate>
		<guid>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22924</guid>
		<description>@&lt;a href="http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22923" rel="nofollow"&gt;David Lindsay&lt;/a&gt;:
OK, apologizes accepted. Please accept mine regarding the "big players bias" allegation, I just had that feeling looking at the table and combining that with the preamble.

Like &lt;a href="https://twitter.com/thornmaker/status/12614231216" rel="nofollow"&gt;you said&lt;/a&gt;, no hard feelings.</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22923" rel="nofollow">David Lindsay</a>:<br />
OK, apologizes accepted. Please accept mine regarding the &#8220;big players bias&#8221; allegation, I just had that feeling looking at the table and combining that with the preamble.</p>
<p>Like <a href="https://twitter.com/thornmaker/status/12614231216" rel="nofollow">you said</a>, no hard feelings.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Lindsay</title>
		<link>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22923</link>
		<dc:creator>David Lindsay</dc:creator>
		<pubDate>Wed, 21 Apr 2010 20:44:09 +0000</pubDate>
		<guid>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22923</guid>
		<description>The wording in the whitepaper preamble was completely mine, so yes, you can blame me.  When I said IE8's filters were &#34;somewhat novel&#34;, I was referring to to the fact that they were not the first to develop thorough client-side XSS filters, clearly NoScript had been doing this for quite some time, however they were the first *browser* to have such filters built in by default.  

It was not my intent to slight NoScript in any way.  In hindsight, I can clearly see your point of view and I apologize for not properly acknowledging NoScript's pioneering role in terms of client-side filters.  

That being said, I make no apologies for the content of the comparison slide in our presentation.  Although Eduardo and I had a lot of back-and-forth discussion regarding how to compare things on that slide, the final contents accurately reflect the average of our opinions (which were never that far apart to begin with).  And I take offense to any accusations of bias towards &#34;big players&#34;; if anything, the opposite is true.</description>
		<content:encoded><![CDATA[<p>The wording in the whitepaper preamble was completely mine, so yes, you can blame me.  When I said IE8&#8217;s filters were &quot;somewhat novel&quot;, I was referring to to the fact that they were not the first to develop thorough client-side XSS filters, clearly NoScript had been doing this for quite some time, however they were the first *browser* to have such filters built in by default.  </p>
<p>It was not my intent to slight NoScript in any way.  In hindsight, I can clearly see your point of view and I apologize for not properly acknowledging NoScript&#8217;s pioneering role in terms of client-side filters.  </p>
<p>That being said, I make no apologies for the content of the comparison slide in our presentation.  Although Eduardo and I had a lot of back-and-forth discussion regarding how to compare things on that slide, the final contents accurately reflect the average of our opinions (which were never that far apart to begin with).  And I take offense to any accusations of bias towards &quot;big players&quot;; if anything, the opposite is true.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Morgan Storey</title>
		<link>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22904</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Wed, 21 Apr 2010 11:26:12 +0000</pubDate>
		<guid>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22904</guid>
		<description>A bit of spurious reasoning, not that I don't use noscript. I think they were trying to spruik IE8 still. But maybe you could help them along and port noscript to IE, and then they would at least have something to crow about, once they offer you an obscene amount of money and put it into the code natively.
I am surprised you didn't mention the recent network solutions attack and its injection of malicious javascript, if something like noscript was globally used this breach may have been found sooner with less collateral damage, if I saw javascript on my page I would know as there is very little and it isn't whitelisted.</description>
		<content:encoded><![CDATA[<p>A bit of spurious reasoning, not that I don&#8217;t use noscript. I think they were trying to spruik IE8 still. But maybe you could help them along and port noscript to IE, and then they would at least have something to crow about, once they offer you an obscene amount of money and put it into the code natively.<br />
I am surprised you didn&#8217;t mention the recent network solutions attack and its injection of malicious javascript, if something like noscript was globally used this breach may have been found sooner with less collateral damage, if I saw javascript on my page I would know as there is very little and it isn&#8217;t whitelisted.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: uberVU - social comments</title>
		<link>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22900</link>
		<dc:creator>uberVU - social comments</dc:creator>
		<pubDate>Wed, 21 Apr 2010 10:36:50 +0000</pubDate>
		<guid>http://hackademix.net/2010/04/21/microsoft-recommends-noscript/#comment-22900</guid>
		<description>&lt;strong&gt;Social comments and analytics for this post&lt;/strong&gt;

This post was mentioned on Twitter by ma1: Microsoft endorses Firefox+NoScript :) http://snipurl.com/ms4ns</description>
		<content:encoded><![CDATA[<p><strong>Social comments and analytics for this post</strong></p>
<p>This post was mentioned on Twitter by ma1: Microsoft endorses Firefox+NoScript :) <a href="http://snipurl.com/ms4ns" rel="nofollow">http://snipurl.com/ms4ns</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

