<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: al_9x Was Right, My Router Is Safe</title>
	<link>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Wed, 16 May 2012 22:10:24 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: شات صوتي</title>
		<link>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-24108</link>
		<dc:creator>شات صوتي</dc:creator>
		<pubDate>Thu, 28 Oct 2010 20:47:57 +0000</pubDate>
		<guid>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-24108</guid>
		<description>&#62; my own home router had been vulnerable as well</description>
		<content:encoded><![CDATA[<p>&gt; my own home router had been vulnerable as well</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23882</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Sat, 04 Sep 2010 23:56:33 +0000</pubDate>
		<guid>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23882</guid>
		<description>I'm glad I ran across this post - the original exploit had me worried. Glad, first, to find that I'm not the only one who took this seriously, and second, to find that there is a counter to it.</description>
		<content:encoded><![CDATA[<p>I&#8217;m glad I ran across this post - the original exploit had me worried. Glad, first, to find that I&#8217;m not the only one who took this seriously, and second, to find that there is a counter to it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter</title>
		<link>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23470</link>
		<dc:creator>Peter</dc:creator>
		<pubDate>Tue, 10 Aug 2010 20:52:08 +0000</pubDate>
		<guid>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23470</guid>
		<description>@ Keith G

Maybe you’re having a wrong/bad router :-) My router only support’s Windows or Linux with Firefox incl. noscript and nothing else ;-)</description>
		<content:encoded><![CDATA[<p>@ Keith G</p>
<p>Maybe you’re having a wrong/bad router :-) My router only support’s Windows or Linux with Firefox incl. noscript and nothing else ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23397</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Fri, 06 Aug 2010 19:55:48 +0000</pubDate>
		<guid>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23397</guid>
		<description>@&lt;a href="http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23395" rel="nofollow"&gt;Keith G&lt;/a&gt;:
In fact, I never said that NoScript "fixes" your router.
I just said that MY router is safe, since I browse the web only with Firefox + NoScript :)</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23395" rel="nofollow">Keith G</a>:<br />
In fact, I never said that NoScript &#8220;fixes&#8221; your router.<br />
I just said that MY router is safe, since I browse the web only with Firefox + NoScript :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Keith G</title>
		<link>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23395</link>
		<dc:creator>Keith G</dc:creator>
		<pubDate>Fri, 06 Aug 2010 16:47:22 +0000</pubDate>
		<guid>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23395</guid>
		<description>@Giorgio:
@Hänsel Würstchen makes a valid point that the security vulnerability existing in the router is NOT fixed by NoScript.  NoScript is only able to prevent your browser exploiting the vulnerability.  But when your mother-in-law comes to stay and plugs her laptop running IE into your network, the routers vulnerability becomes a problem again, and there's nothing you can do about it.</description>
		<content:encoded><![CDATA[<p>@Giorgio:<br />
@Hänsel Würstchen makes a valid point that the security vulnerability existing in the router is NOT fixed by NoScript.  NoScript is only able to prevent your browser exploiting the vulnerability.  But when your mother-in-law comes to stay and plugs her laptop running IE into your network, the routers vulnerability becomes a problem again, and there&#8217;s nothing you can do about it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23334</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Mon, 02 Aug 2010 21:53:12 +0000</pubDate>
		<guid>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23334</guid>
		<description>@&lt;a href="http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23331" rel="nofollow"&gt;Hänsel Würstchen&lt;/a&gt;:
Let me disagree. The issue at hand (which may be rectified by a firmware upgrade or, in some cases, specific firewall rules) is not a vulnerability per se, but it does become a vulnerability as soon as my web browser acts as a "proxy" between the internet and my LAN.
Therefore if I browse the web only with Firefox + NoScript my router is safe, as the title says.
This doesn't mean that as soon as a firmware upgrade is available I will refuse to install it ;)</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23331" rel="nofollow">Hänsel Würstchen</a>:<br />
Let me disagree. The issue at hand (which may be rectified by a firmware upgrade or, in some cases, specific firewall rules) is not a vulnerability per se, but it does become a vulnerability as soon as my web browser acts as a &#8220;proxy&#8221; between the internet and my LAN.<br />
Therefore if I browse the web only with Firefox + NoScript my router is safe, as the title says.<br />
This doesn&#8217;t mean that as soon as a firmware upgrade is available I will refuse to install it ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hänsel Würstchen</title>
		<link>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23331</link>
		<dc:creator>Hänsel Würstchen</dc:creator>
		<pubDate>Mon, 02 Aug 2010 18:01:22 +0000</pubDate>
		<guid>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23331</guid>
		<description>&#62; my own home router had been vulnerable as well

Please excuse my smartarseness, but I would argue that your home router is still vulnerable and you are now merely protected against attacks against your router utilising your Firefox installation.
I value NoScript and I am happy about this feature but protecting silly home routers is nothing NoScript will ever be able to reliably achieve. Therefore you should make clear that this is only some sort of workaround for an issue which in most cases can only be fixed with a firmware upgrade.
Thank you.</description>
		<content:encoded><![CDATA[<p>&gt; my own home router had been vulnerable as well</p>
<p>Please excuse my smartarseness, but I would argue that your home router is still vulnerable and you are now merely protected against attacks against your router utilising your Firefox installation.<br />
I value NoScript and I am happy about this feature but protecting silly home routers is nothing NoScript will ever be able to reliably achieve. Therefore you should make clear that this is only some sort of workaround for an issue which in most cases can only be fixed with a firmware upgrade.<br />
Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: FirefoxFan</title>
		<link>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23325</link>
		<dc:creator>FirefoxFan</dc:creator>
		<pubDate>Mon, 02 Aug 2010 09:56:39 +0000</pubDate>
		<guid>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23325</guid>
		<description>@frank goossens
Best and least disruptive protection would be if Firefox shipped with these additional features as default prefs, with the more user-troublesome ones exposed in the Firefox gui and the more dangerous ones kept under the hood.
But that would mean Mozilla committing actual funds and staff to handing back a lot more control of the browser to the user than the Web wants them to..because the Web wants the lazy path to get at people's money and wants users to remain nice and ignorant about just how many holes most Web pages contain.
http://hackademix.net/2008/01/12/malware-20-is-now/

Just saying :-) I'm pleased that Mozilla remain committed to the anarchy of Firefox overall. It could have been so much worse when they went corporate.</description>
		<content:encoded><![CDATA[<p>@frank goossens<br />
Best and least disruptive protection would be if Firefox shipped with these additional features as default prefs, with the more user-troublesome ones exposed in the Firefox gui and the more dangerous ones kept under the hood.<br />
But that would mean Mozilla committing actual funds and staff to handing back a lot more control of the browser to the user than the Web wants them to..because the Web wants the lazy path to get at people&#8217;s money and wants users to remain nice and ignorant about just how many holes most Web pages contain.<br />
<a href="http://hackademix.net/2008/01/12/malware-20-is-now/" rel="nofollow">http://hackademix.net/2008/01/12/malware-20-is-now/</a></p>
<p>Just saying :-) I&#8217;m pleased that Mozilla remain committed to the anarchy of Firefox overall. It could have been so much worse when they went corporate.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: frank goossens</title>
		<link>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23323</link>
		<dc:creator>frank goossens</dc:creator>
		<pubDate>Mon, 02 Aug 2010 08:07:25 +0000</pubDate>
		<guid>http://hackademix.net/2010/08/01/al_9x-was-right-my-router-is-safe/#comment-23323</guid>
		<description>Noscript with &#34;Allow script globally (dangerous)&#34; indeed offers great non-disruptive protection, &lt;a href="http://blog.futtta.be/2010/02/22/browser-choice-vacuming-security-for-father-in-laws/" rel="nofollow"&gt;I have it installed on my wife's and father-in-law's PC's that way&lt;/a&gt;.

So wouldn't it be great if there was alternative version of noscript that came with a minimal UI and non-script-blocking out of the box, aimed at non-techie users? call it &#34;Secure browsing&#34; &#38; start protecting the non-geeky masses (even if not as thorough as in blocking mode)? :)</description>
		<content:encoded><![CDATA[<p>Noscript with &quot;Allow script globally (dangerous)&quot; indeed offers great non-disruptive protection, <a href="http://blog.futtta.be/2010/02/22/browser-choice-vacuming-security-for-father-in-laws/" rel="nofollow">I have it installed on my wife&#8217;s and father-in-law&#8217;s PC&#8217;s that way</a>.</p>
<p>So wouldn&#8217;t it be great if there was alternative version of noscript that came with a minimal UI and non-script-blocking out of the box, aimed at non-techie users? call it &quot;Secure browsing&quot; &amp; start protecting the non-geeky masses (even if not as thorough as in blocking mode)? :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

