<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Even Forced SSL is broken for Facebook Google Twitter</title>
	<atom:link href="http://www.digitalsociety.org/2010/10/even-forced-ssl-is-broken-for-facebook-google-twitter/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.digitalsociety.org/2010/10/even-forced-ssl-is-broken-for-facebook-google-twitter/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=even-forced-ssl-is-broken-for-facebook-google-twitter</link>
	<description>Pro-Culture, Pro-Commerce</description>
	<lastBuildDate>Mon, 14 Jan 2013 10:54:13 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: בשעה טובה Facebook over SSL. &#124; הבלוג של iTK98</title>
		<link>http://www.digitalsociety.org/2010/10/even-forced-ssl-is-broken-for-facebook-google-twitter/comment-page-1/#comment-20034</link>
		<dc:creator>בשעה טובה Facebook over SSL. &#124; הבלוג של iTK98</dc:creator>
		<pubDate>Wed, 26 Jan 2011 21:02:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitalsociety.org/?p=7566#comment-20034</guid>
		<description><![CDATA[[...] Society: 1 [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Society: 1 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Online services security report card &#171; Rogerio Aristides</title>
		<link>http://www.digitalsociety.org/2010/10/even-forced-ssl-is-broken-for-facebook-google-twitter/comment-page-1/#comment-17259</link>
		<dc:creator>Online services security report card &#171; Rogerio Aristides</dc:creator>
		<pubDate>Sun, 07 Nov 2010 14:10:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitalsociety.org/?p=7566#comment-17259</guid>
		<description><![CDATA[[...] been offering incorrect advice to just use force the website to run SSL, but my testing shows that sidejacking is still possible even when the site runs SSL.&#160; Some people have suggested tools that go as far as rewriting the website’s javascript but [...]]]></description>
		<content:encoded><![CDATA[<p>[...] been offering incorrect advice to just use force the website to run SSL, but my testing shows that sidejacking is still possible even when the site runs SSL.&#160; Some people have suggested tools that go as far as rewriting the website’s javascript but [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SiliconANGLE &#8212; Blog &#8212; Microsoft promises fix to Hotmail security this month</title>
		<link>http://www.digitalsociety.org/2010/10/even-forced-ssl-is-broken-for-facebook-google-twitter/comment-page-1/#comment-17176</link>
		<dc:creator>SiliconANGLE &#8212; Blog &#8212; Microsoft promises fix to Hotmail security this month</dc:creator>
		<pubDate>Thu, 04 Nov 2010 19:41:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitalsociety.org/?p=7566#comment-17176</guid>
		<description><![CDATA[[...] Sites like Facebook that allow you to manually force an SSL connection for everything are still susceptible to cookie theft while sites like Ebay which doesn’t support full time SSL browsing aren’t susceptible.&#160; [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Sites like Facebook that allow you to manually force an SSL connection for everything are still susceptible to cookie theft while sites like Ebay which doesn’t support full time SSL browsing aren’t susceptible.&#160; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Digital Society &#187; Blog Archive &#187; Microsoft promises fix to Hotmail security this month</title>
		<link>http://www.digitalsociety.org/2010/10/even-forced-ssl-is-broken-for-facebook-google-twitter/comment-page-1/#comment-17142</link>
		<dc:creator>Digital Society &#187; Blog Archive &#187; Microsoft promises fix to Hotmail security this month</dc:creator>
		<pubDate>Wed, 03 Nov 2010 23:13:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitalsociety.org/?p=7566#comment-17142</guid>
		<description><![CDATA[[...]  [...]]]></description>
		<content:encoded><![CDATA[<p>[...]  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SiliconANGLE &#8212; Blog &#8212; Online services security report card</title>
		<link>http://www.digitalsociety.org/2010/10/even-forced-ssl-is-broken-for-facebook-google-twitter/comment-page-1/#comment-17099</link>
		<dc:creator>SiliconANGLE &#8212; Blog &#8212; Online services security report card</dc:creator>
		<pubDate>Tue, 02 Nov 2010 15:01:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitalsociety.org/?p=7566#comment-17099</guid>
		<description><![CDATA[[...] been offering incorrect advice to just use force the website to run SSL, but my testing shows that sidejacking is still possible even when the site runs SSL.&#160; Some people have suggested tools that go as far as rewriting the website’s javascript but [...]]]></description>
		<content:encoded><![CDATA[<p>[...] been offering incorrect advice to just use force the website to run SSL, but my testing shows that sidejacking is still possible even when the site runs SSL.&#160; Some people have suggested tools that go as far as rewriting the website’s javascript but [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Digital Society &#187; Blog Archive &#187; Online services security report card</title>
		<link>http://www.digitalsociety.org/2010/10/even-forced-ssl-is-broken-for-facebook-google-twitter/comment-page-1/#comment-17084</link>
		<dc:creator>Digital Society &#187; Blog Archive &#187; Online services security report card</dc:creator>
		<pubDate>Tue, 02 Nov 2010 02:44:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitalsociety.org/?p=7566#comment-17084</guid>
		<description><![CDATA[[...]  [...]]]></description>
		<content:encoded><![CDATA[<p>[...]  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio Maone</title>
		<link>http://www.digitalsociety.org/2010/10/even-forced-ssl-is-broken-for-facebook-google-twitter/comment-page-1/#comment-17053</link>
		<dc:creator>Giorgio Maone</dc:creator>
		<pubDate>Sun, 31 Oct 2010 14:53:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitalsociety.org/?p=7566#comment-17053</guid>
		<description><![CDATA[&lt;a href=&quot;http://hackademix.net/2010/10/27/forcing-https-with-noscript/&quot; rel=&quot;nofollow&quot;&gt;NoScript&#039;s &quot;Force HTTPS&quot; feature&lt;/a&gt; covers all the request &lt;em&gt;and the subrequests&lt;/em&gt; to the forced domains (no matter if images, scripts, stylesheets or anything else), hence you&#039;re fully covered against this kind of attacks.]]></description>
		<content:encoded><![CDATA[<p><a href="http://hackademix.net/2010/10/27/forcing-https-with-noscript/" rel="nofollow">NoScript&#8217;s &#8220;Force HTTPS&#8221; feature</a> covers all the request <em>and the subrequests</em> to the forced domains (no matter if images, scripts, stylesheets or anything else), hence you&#8217;re fully covered against this kind of attacks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firesheep och tillit &#124; Intensifier</title>
		<link>http://www.digitalsociety.org/2010/10/even-forced-ssl-is-broken-for-facebook-google-twitter/comment-page-1/#comment-17029</link>
		<dc:creator>Firesheep och tillit &#124; Intensifier</dc:creator>
		<pubDate>Sat, 30 Oct 2010 13:20:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitalsociety.org/?p=7566#comment-17029</guid>
		<description><![CDATA[[...] sida. Inte ens olika sätt att tvinga fram SSL (alltså HTTPS i det här fallet) hjälper eftersom javascript läcker okrypterad information. Min skepsis inför plugins som HTTPS everywhere inslaget i Radio Metropol besannades alltså. Det [...]]]></description>
		<content:encoded><![CDATA[<p>[...] sida. Inte ens olika sätt att tvinga fram SSL (alltså HTTPS i det här fallet) hjälper eftersom javascript läcker okrypterad information. Min skepsis inför plugins som HTTPS everywhere inslaget i Radio Metropol besannades alltså. Det [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rajandran R</title>
		<link>http://www.digitalsociety.org/2010/10/even-forced-ssl-is-broken-for-facebook-google-twitter/comment-page-1/#comment-17024</link>
		<dc:creator>Rajandran R</dc:creator>
		<pubDate>Sat, 30 Oct 2010 09:45:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitalsociety.org/?p=7566#comment-17024</guid>
		<description><![CDATA[Thanks a lot for the huge information about the Forced SSL in Chrome browser.
Its time for Browser Developers need to take a big step on this issue. Better one should stay away from Public Wi-Fi spot until we get a clearcut solution]]></description>
		<content:encoded><![CDATA[<p>Thanks a lot for the huge information about the Forced SSL in Chrome browser.<br />
Its time for Browser Developers need to take a big step on this issue. Better one should stay away from Public Wi-Fi spot until we get a clearcut solution</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nik Cubrilovic</title>
		<link>http://www.digitalsociety.org/2010/10/even-forced-ssl-is-broken-for-facebook-google-twitter/comment-page-1/#comment-17023</link>
		<dc:creator>Nik Cubrilovic</dc:creator>
		<pubDate>Sat, 30 Oct 2010 08:32:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitalsociety.org/?p=7566#comment-17023</guid>
		<description><![CDATA[George - My (recently renamed) extension Fidelio takes care of what you describe in your first paragraph. It will:

* rewrite your cookies (as they are set) so that the secure flag is on (ie. they will only ever be sent back over an https connection)

* will rewrite main requests to https 

* capture all doc loads, be it an image, javascript or xmlhttprequest, and either rewrite them to https or drop the request entirely 

between these features, your cookies will never be sent in the clear. you can get it here:

http://github.com/nikcub/fidelio]]></description>
		<content:encoded><![CDATA[<p>George &#8211; My (recently renamed) extension Fidelio takes care of what you describe in your first paragraph. It will:</p>
<p>* rewrite your cookies (as they are set) so that the secure flag is on (ie. they will only ever be sent back over an https connection)</p>
<p>* will rewrite main requests to https </p>
<p>* capture all doc loads, be it an image, javascript or xmlhttprequest, and either rewrite them to https or drop the request entirely </p>
<p>between these features, your cookies will never be sent in the clear. you can get it here:</p>
<p><a href="http://github.com/nikcub/fidelio" rel="nofollow">http://github.com/nikcub/fidelio</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
