<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Fancy Clickjacking, Tougher NoScript</title>
	<link>http://hackademix.net/2011/07/11/fancy-clickjacking-tougher-noscript/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Wed, 16 May 2012 22:32:18 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Basti</title>
		<link>http://hackademix.net/2011/07/11/fancy-clickjacking-tougher-noscript/#comment-24896</link>
		<dc:creator>Basti</dc:creator>
		<pubDate>Tue, 12 Jul 2011 17:20:55 +0000</pubDate>
		<guid>http://hackademix.net/2011/07/11/fancy-clickjacking-tougher-noscript/#comment-24896</guid>
		<description>Nice work. In case you're wondering about a &#34;clickjacking report&#34; on one of the demos kindly provided by Krzysztof Kotowicz, that was me. I loaded the page and disabled the protection. The warning came up and I clicked the button right to &#34;OK&#34; as I assumed it would be &#34;Cancel&#34;.

FF security is much greater with NoScript.</description>
		<content:encoded><![CDATA[<p>Nice work. In case you&#8217;re wondering about a &quot;clickjacking report&quot; on one of the demos kindly provided by Krzysztof Kotowicz, that was me. I loaded the page and disabled the protection. The warning came up and I clicked the button right to &quot;OK&quot; as I assumed it would be &quot;Cancel&quot;.</p>
<p>FF security is much greater with NoScript.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tommy</title>
		<link>http://hackademix.net/2011/07/11/fancy-clickjacking-tougher-noscript/#comment-24895</link>
		<dc:creator>tommy</dc:creator>
		<pubDate>Tue, 12 Jul 2011 06:31:18 +0000</pubDate>
		<guid>http://hackademix.net/2011/07/11/fancy-clickjacking-tougher-noscript/#comment-24895</guid>
		<description>Or, one could defeat #2 by avoiding obviously risky sites and protocols like Facebook, Twitter, and OAuth. But they won't. 

Otherwise, what KK said. 

btw, should I be worried that I have to allow an iFrame recaptcha to post here? And copy/paste text from it into a box? ;)</description>
		<content:encoded><![CDATA[<p>Or, one could defeat #2 by avoiding obviously risky sites and protocols like Facebook, Twitter, and OAuth. But they won&#8217;t. </p>
<p>Otherwise, what KK said. </p>
<p>btw, should I be worried that I have to allow an iFrame recaptcha to post here? And copy/paste text from it into a box? ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Krzysztof Kotowicz</title>
		<link>http://hackademix.net/2011/07/11/fancy-clickjacking-tougher-noscript/#comment-24894</link>
		<dc:creator>Krzysztof Kotowicz</dc:creator>
		<pubDate>Mon, 11 Jul 2011 14:23:49 +0000</pubDate>
		<guid>http://hackademix.net/2011/07/11/fancy-clickjacking-tougher-noscript/#comment-24894</guid>
		<description>Yay :) Congratulations on fast patches - NoScript really is a 0-day-style security tool :) If only Firefox would disallow framed view-source: in the first place...</description>
		<content:encoded><![CDATA[<p>Yay :) Congratulations on fast patches - NoScript really is a 0-day-style security tool :) If only Firefox would disallow framed view-source: in the first place&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

