<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Almost Hopeless Challenge Of Web Security</title>
	<atom:link href="http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/</link>
	<description>TechCrunching the Enterprise</description>
	<lastBuildDate>Sat, 13 Mar 2010 19:53:11 -0800</lastBuildDate>
	
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: sfdghsdfd</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-13418</link>
		<dc:creator>sfdghsdfd</dc:creator>
		<pubDate>Mon, 28 Sep 2009 02:57:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-13418</guid>
		<description>http://www.voguemalls.com
HOT SELL: Ed hardy/ lacoste/ polo/ ca/ A&amp;F  Tshirt :$12
         coach/ gucci/ lv/ ed hardy/ D&amp;G/ Fendi  handbag :$35
         nike jordan(1-24)/ jordan ring/ nike shox/ air max/ af1/ Dunk :$32
         lv/ ed hardy/ gucci/ coach/ lacoste/ timbland :$35
         gucci/ ed hardy/ coogi/ evisu/ prada jeans:$30
         New era/ gucci/ ed hardy cap:$13
         Okely/ gucci/ D&amp;G/ fendi/ coach/ armani sunglass:$15

nike shoes: 32 $, des jeans: 30 $, ed hardy, t-shirts: 12 $, NLF: 20 $, un entra?neur à main: 35 $, bottes UGG: 50 $</description>
		<content:encoded><![CDATA[<p><a href="http://www.voguemalls.com" rel="nofollow">http://www.voguemalls.com</a><br />
HOT SELL: Ed hardy/ lacoste/ polo/ ca/ A&amp;F  Tshirt :$12<br />
         coach/ gucci/ lv/ ed hardy/ D&amp;G/ Fendi  handbag :$35<br />
         nike jordan(1-24)/ jordan ring/ nike shox/ air max/ af1/ Dunk :$32<br />
         lv/ ed hardy/ gucci/ coach/ lacoste/ timbland :$35<br />
         gucci/ ed hardy/ coogi/ evisu/ prada jeans:$30<br />
         New era/ gucci/ ed hardy cap:$13<br />
         Okely/ gucci/ D&amp;G/ fendi/ coach/ armani sunglass:$15</p>
<p>nike shoes: 32 $, des jeans: 30 $, ed hardy, t-shirts: 12 $, NLF: 20 $, un entra?neur à main: 35 $, bottes UGG: 50 $</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RubyOnRails XSS Vulnerability Claims Twitter, Basecamp And My Confidence &#124; Submitter</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12934</link>
		<dc:creator>RubyOnRails XSS Vulnerability Claims Twitter, Basecamp And My Confidence &#124; Submitter</dc:creator>
		<pubDate>Tue, 08 Sep 2009 14:35:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12934</guid>
		<description>[...] was only three days ago that I wrote about the almost hopeless challenge of web security, specifically around new vectors [...]</description>
		<content:encoded><![CDATA[<p>[...] was only three days ago that I wrote about the almost hopeless challenge of web security, specifically around new vectors [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RubyOnRails XSS Vulnerability Claims Twitter, Basecamp And My Confidence &#124; Codedstyle</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12881</link>
		<dc:creator>RubyOnRails XSS Vulnerability Claims Twitter, Basecamp And My Confidence &#124; Codedstyle</dc:creator>
		<pubDate>Sat, 05 Sep 2009 12:01:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12881</guid>
		<description>[...] was only three days ago that I wrote about the almost hopeless challenge of web security, specifically around new vectors [...]</description>
		<content:encoded><![CDATA[<p>[...] was only three days ago that I wrote about the almost hopeless challenge of web security, specifically around new vectors [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BlogBuzz September 5, 2009</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12880</link>
		<dc:creator>BlogBuzz September 5, 2009</dc:creator>
		<pubDate>Sat, 05 Sep 2009 10:24:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12880</guid>
		<description>[...] The Almost Hopeless Challenge Of Web Security [...]</description>
		<content:encoded><![CDATA[<p>[...] The Almost Hopeless Challenge Of Web Security [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RubyOnRails XSS Vulnerability Claims Twitter, Basecamp And My Confidence &#124; Technology</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12872</link>
		<dc:creator>RubyOnRails XSS Vulnerability Claims Twitter, Basecamp And My Confidence &#124; Technology</dc:creator>
		<pubDate>Sat, 05 Sep 2009 01:01:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12872</guid>
		<description>[...] was only three days ago that I wrote about the almost hopeless challenge of web security, specifically around new vectors [...]</description>
		<content:encoded><![CDATA[<p>[...] was only three days ago that I wrote about the almost hopeless challenge of web security, specifically around new vectors [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Techcrunch &#187; Blog Archive &#187; RubyOnRails XSS Vulnerability Claims Twitter, Basecamp And My Confidence</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12867</link>
		<dc:creator>Techcrunch &#187; Blog Archive &#187; RubyOnRails XSS Vulnerability Claims Twitter, Basecamp And My Confidence</dc:creator>
		<pubDate>Fri, 04 Sep 2009 22:15:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12867</guid>
		<description>[...] was only three days ago that I wrote about the almost hopeless challenge of web security, specifically around new vectors [...]</description>
		<content:encoded><![CDATA[<p>[...] was only three days ago that I wrote about the almost hopeless challenge of web security, specifically around new vectors [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rick Lebherz</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12866</link>
		<dc:creator>Rick Lebherz</dc:creator>
		<pubDate>Fri, 04 Sep 2009 19:14:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12866</guid>
		<description>Good article.

I think the nature of the challenge isnt just with in IT and the Tech world. It comes down to human nature and pushing the limits of what is possible. 

As long as someone creates something of value, someone else will be there trying to pick it a part and poke holes in it.  Hopefully the intention is to improve and alert the community and not leverage this for personal gain.  But many people are selfish creatures. All you can do is try and stay ahead of the curve. 

Also along the same lines in case you missed it, OpSource is improving Cloud Security and performance to meet enterprise expectations and requirements. A multitiered architecture, firewalls and load balancing standard (not an option), dedicated private VLANs, Encryptions, SAS 70...yada yada yada...check it out

http://www.techcrunchit.com/2009/08/27/opsource-unveils-hybrid-cloud-solution-for-the-enterprise/</description>
		<content:encoded><![CDATA[<p>Good article.</p>
<p>I think the nature of the challenge isnt just with in IT and the Tech world. It comes down to human nature and pushing the limits of what is possible. </p>
<p>As long as someone creates something of value, someone else will be there trying to pick it a part and poke holes in it.  Hopefully the intention is to improve and alert the community and not leverage this for personal gain.  But many people are selfish creatures. All you can do is try and stay ahead of the curve. </p>
<p>Also along the same lines in case you missed it, OpSource is improving Cloud Security and performance to meet enterprise expectations and requirements. A multitiered architecture, firewalls and load balancing standard (not an option), dedicated private VLANs, Encryptions, SAS 70&#8230;yada yada yada&#8230;check it out</p>
<p><a href="http://www.techcrunchit.com/2009/08/27/opsource-unveils-hybrid-cloud-solution-for-the-enterprise/" rel="nofollow">http://www.techcrunchit.com/2009/08/27/opsource-unveils-hybrid-cloud-solution-for-the-enterprise/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RubyOnRails XSS Vulnerability Claims Twitter, Basecamp And My Confidence</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12818</link>
		<dc:creator>RubyOnRails XSS Vulnerability Claims Twitter, Basecamp And My Confidence</dc:creator>
		<pubDate>Fri, 04 Sep 2009 06:59:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12818</guid>
		<description>[...] was only three days ago that I wrote about the almost hopeless challenge of web security, specifically around new vectors [...]</description>
		<content:encoded><![CDATA[<p>[...] was only three days ago that I wrote about the almost hopeless challenge of web security, specifically around new vectors [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SpaceMan</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12811</link>
		<dc:creator>SpaceMan</dc:creator>
		<pubDate>Fri, 04 Sep 2009 02:34:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12811</guid>
		<description>If PHP is the center of Web technology... PHP will stand for Pretty Hopeless PHP</description>
		<content:encoded><![CDATA[<p>If PHP is the center of Web technology&#8230; PHP will stand for Pretty Hopeless PHP</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Today Free Tips</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12748</link>
		<dc:creator>Today Free Tips</dc:creator>
		<pubDate>Wed, 02 Sep 2009 16:19:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12748</guid>
		<description>[...] has dropped over the years as our trust in our favorite services grows Yet all the while the... read more or search more on challenge hopeless web &#187;  Other posts in Marketing&quot;TheTime is Now&quot; For [...]</description>
		<content:encoded><![CDATA[<p>[...] has dropped over the years as our trust in our favorite services grows Yet all the while the&#8230; read more or search more on challenge hopeless web &raquo;  Other posts in Marketing&#8221;TheTime is Now&#8221; For [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Almost Hopeless Challenge Of Web Security &#171; Jared Rimer&#8217;s Technology blog and podcast</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12709</link>
		<dc:creator>The Almost Hopeless Challenge Of Web Security &#171; Jared Rimer&#8217;s Technology blog and podcast</dc:creator>
		<pubDate>Wed, 02 Sep 2009 05:51:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12709</guid>
		<description>[...] The Almost Hopeless Challenge Of Web Security. [...]</description>
		<content:encoded><![CDATA[<p>[...] The Almost Hopeless Challenge Of Web Security. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Koretz</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12692</link>
		<dc:creator>David Koretz</dc:creator>
		<pubDate>Wed, 02 Sep 2009 03:14:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12692</guid>
		<description>There are a lot of smart people working on this problem such as White Hat Security, Mykonos Software, Fortify, and others.

The end result is going to be a strategy that attacks multiple layers via code scanning, code-level protection, intrusion detection, etc.

It&#039;s no different than physical security: you lock your doors, and buy an alarm system.

The real problem is that the average developer is not trained on application security, and under the pressure of corporate deadlines builds features, not security.</description>
		<content:encoded><![CDATA[<p>There are a lot of smart people working on this problem such as White Hat Security, Mykonos Software, Fortify, and others.</p>
<p>The end result is going to be a strategy that attacks multiple layers via code scanning, code-level protection, intrusion detection, etc.</p>
<p>It&#8217;s no different than physical security: you lock your doors, and buy an alarm system.</p>
<p>The real problem is that the average developer is not trained on application security, and under the pressure of corporate deadlines builds features, not security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sh</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12684</link>
		<dc:creator>sh</dc:creator>
		<pubDate>Tue, 01 Sep 2009 21:23:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12684</guid>
		<description>Federal Authority Over the Internet? The Cybersecurity Act of 2009

http://www.eff.org/deeplinks/2009/04/cybersecurity-act</description>
		<content:encoded><![CDATA[<p>Federal Authority Over the Internet? The Cybersecurity Act of 2009</p>
<p><a href="http://www.eff.org/deeplinks/2009/04/cybersecurity-act" rel="nofollow">http://www.eff.org/deeplinks/2009/04/cybersecurity-act</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sh</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12683</link>
		<dc:creator>sh</dc:creator>
		<pubDate>Tue, 01 Sep 2009 21:20:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12683</guid>
		<description>Read this about another security issue:

http://www.eff.org/deeplinks/2009/04/cybersecurity-act

Federal Authority Over the Internet? The Cybersecurity Act of 2009</description>
		<content:encoded><![CDATA[<p>Read this about another security issue:</p>
<p><a href="http://www.eff.org/deeplinks/2009/04/cybersecurity-act" rel="nofollow">http://www.eff.org/deeplinks/2009/04/cybersecurity-act</a></p>
<p>Federal Authority Over the Internet? The Cybersecurity Act of 2009</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hristo Bojinov</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12681</link>
		<dc:creator>Hristo Bojinov</dc:creator>
		<pubDate>Tue, 01 Sep 2009 19:22:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12681</guid>
		<description>To add to the problem, many devices now feature multiple interfaces that can be used as alternative injection points into the browser. We call this cross-channel scripting (XCS) in a recent talk:

http://bojinov.org/professional/BH09_EMI.pdf
http://seclab.stanford.edu/websec/embedded/</description>
		<content:encoded><![CDATA[<p>To add to the problem, many devices now feature multiple interfaces that can be used as alternative injection points into the browser. We call this cross-channel scripting (XCS) in a recent talk:</p>
<p><a href="http://bojinov.org/professional/BH09_EMI.pdf" rel="nofollow">http://bojinov.org/professional/BH09_EMI.pdf</a><br />
<a href="http://seclab.stanford.edu/websec/embedded/" rel="nofollow">http://seclab.stanford.edu/websec/embedded/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ambert ho</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12678</link>
		<dc:creator>ambert ho</dc:creator>
		<pubDate>Tue, 01 Sep 2009 17:48:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12678</guid>
		<description>&quot;browser manufacturers themselves do not completely understand the issues involved, and in some cases are moving backwards (ie. the new IE8 is now allowing XmlHttpRequest across-ports)&quot;


Curious, what&#039;s the big deal with allowing XHRs to any port?

The API only allows you to initialize the xhr to make HTTP requests with HTTP headers (so it&#039;s not like I can open an FTP request, or start arbitrarily talking SQL to port 3306) and even with the IE8 change it&#039;s not like you can open connections to other servers - Same-Origin-Policy is still enforced, just not to the same port.

So I don&#039;t really see how this makes the browser less secure - seems like it was just a feature added to better support SOAP, REST, etc. since some people are going to have their web services listening on nonstandard ports.</description>
		<content:encoded><![CDATA[<p>&#8220;browser manufacturers themselves do not completely understand the issues involved, and in some cases are moving backwards (ie. the new IE8 is now allowing XmlHttpRequest across-ports)&#8221;</p>
<p>Curious, what&#8217;s the big deal with allowing XHRs to any port?</p>
<p>The API only allows you to initialize the xhr to make HTTP requests with HTTP headers (so it&#8217;s not like I can open an FTP request, or start arbitrarily talking SQL to port 3306) and even with the IE8 change it&#8217;s not like you can open connections to other servers &#8211; Same-Origin-Policy is still enforced, just not to the same port.</p>
<p>So I don&#8217;t really see how this makes the browser less secure &#8211; seems like it was just a feature added to better support SOAP, REST, etc. since some people are going to have their web services listening on nonstandard ports.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: <fb:name linked="false" useyou="false" uid="507212615">Angela Hayden</fb:name></title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12677</link>
		<dc:creator><fb:name linked="false" useyou="false" uid="507212615">Angela Hayden</fb:name></dc:creator>
		<pubDate>Tue, 01 Sep 2009 17:44:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12677</guid>
		<description>I&#039;m just a simple graphic designer trying to start an online audio tour business and it has been HELL! I can&#039;t express in words how much I hate Dreamweaver, Notepad++, CSS, PHP, etc. I&#039;m a starving artist so I have to do everything myself and I also wanted to host everything myself. Instead I&#039;m having to pay E-Junkie to host my mp3 files. My hosting company can&#039;t even send me instructions on how to stop someone from sending emails from my business account. My head is spinning from all the e-cart solutions. 

AnyHoo, thanks for listening. I have to go produce 100 images in photoshop for another project. Oh yea, my shitty site is http://www.hereandthereaudiotours.com I&#039;m editing the page now with a set-up css template using notepad++. I have much work to do.

Okay, now I&#039;m crying. Damn it. And another thing, in the last year and a half I&#039;ve lost data on 3 external hard drives. I&#039;m going to bomb my office. I really have to go now.</description>
		<content:encoded><![CDATA[<p>I&#8217;m just a simple graphic designer trying to start an online audio tour business and it has been HELL! I can&#8217;t express in words how much I hate Dreamweaver, Notepad++, CSS, PHP, etc. I&#8217;m a starving artist so I have to do everything myself and I also wanted to host everything myself. Instead I&#8217;m having to pay E-Junkie to host my mp3 files. My hosting company can&#8217;t even send me instructions on how to stop someone from sending emails from my business account. My head is spinning from all the e-cart solutions. </p>
<p>AnyHoo, thanks for listening. I have to go produce 100 images in photoshop for another project. Oh yea, my shitty site is <a href="http://www.hereandthereaudiotours.com" rel="nofollow">http://www.hereandthereaudiotours.com</a> I&#8217;m editing the page now with a set-up css template using notepad++. I have much work to do.</p>
<p>Okay, now I&#8217;m crying. Damn it. And another thing, in the last year and a half I&#8217;ve lost data on 3 external hard drives. I&#8217;m going to bomb my office. I really have to go now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Almost Hopeless Challenge Of Web Security &#124; BIT Blog</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12667</link>
		<dc:creator>The Almost Hopeless Challenge Of Web Security &#124; BIT Blog</dc:creator>
		<pubDate>Tue, 01 Sep 2009 14:19:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12667</guid>
		<description>[...] at &#8216;cross-site scripting&#8217; one of the latest &#8216;online security can-of-worms&#8217;. Click here to read the original [...]</description>
		<content:encoded><![CDATA[<p>[...] at &#8216;cross-site scripting&#8217; one of the latest &#8216;online security can-of-worms&#8217;. Click here to read the original [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ScriptBasic</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12665</link>
		<dc:creator>ScriptBasic</dc:creator>
		<pubDate>Tue, 01 Sep 2009 12:00:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12665</guid>
		<description>It is when you use something BCX Basic to C or BaCon Basic to C to produce fast, small CGI (compiled) scripts.</description>
		<content:encoded><![CDATA[<p>It is when you use something BCX Basic to C or BaCon Basic to C to produce fast, small CGI (compiled) scripts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12664</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Tue, 01 Sep 2009 11:57:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12664</guid>
		<description>C is not a scripting solution.</description>
		<content:encoded><![CDATA[<p>C is not a scripting solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ScriptBasic</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12663</link>
		<dc:creator>ScriptBasic</dc:creator>
		<pubDate>Tue, 01 Sep 2009 11:19:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12663</guid>
		<description>Or use a non-html parsing scripting solution. I remember when php would parse fake gif files and execute embed code skipping the binary headers.

Your much safer using something like C, Python, Perl or my favorite ScriptBasic. These scripting solutions are real programs that do what they are intended to do instead of parsing /executing whatever is passed their way.</description>
		<content:encoded><![CDATA[<p>Or use a non-html parsing scripting solution. I remember when php would parse fake gif files and execute embed code skipping the binary headers.</p>
<p>Your much safer using something like C, Python, Perl or my favorite ScriptBasic. These scripting solutions are real programs that do what they are intended to do instead of parsing /executing whatever is passed their way.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James Grinter</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12662</link>
		<dc:creator>James Grinter</dc:creator>
		<pubDate>Tue, 01 Sep 2009 10:08:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12662</guid>
		<description>Even if you don&#039;t &quot;trust the web&quot;, someone else probably is on your behalf. Or, someone else you&#039;ve had contact with will do something stupid that has an impact upon you. That&#039;s the power of computer networks.

(Cross-site scripting attacks are, of course, merely attacks of the defensive programming stratagem &quot;sanitise your input&quot;. Just rather a sneaky one, where some thought they could safely sanitise all HTML.)</description>
		<content:encoded><![CDATA[<p>Even if you don&#8217;t &#8220;trust the web&#8221;, someone else probably is on your behalf. Or, someone else you&#8217;ve had contact with will do something stupid that has an impact upon you. That&#8217;s the power of computer networks.</p>
<p>(Cross-site scripting attacks are, of course, merely attacks of the defensive programming stratagem &#8220;sanitise your input&#8221;. Just rather a sneaky one, where some thought they could safely sanitise all HTML.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12659</link>
		<dc:creator>Jonathan</dc:creator>
		<pubDate>Tue, 01 Sep 2009 09:25:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12659</guid>
		<description>I also do not.</description>
		<content:encoded><![CDATA[<p>I also do not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: @Nope</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12658</link>
		<dc:creator>@Nope</dc:creator>
		<pubDate>Tue, 01 Sep 2009 09:25:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12658</guid>
		<description>This problem is not about you or me Nope. It&#039;s about the safety of the majority. Cloud computing is THE solution for it makes problems the size that can&#039;t be ignored ;-)
Asking individuals to accepts responsibility is a losing strategy at this point. We need collective solutions so developers &amp; start-ups can start using cloud based services that are safe.</description>
		<content:encoded><![CDATA[<p>This problem is not about you or me Nope. It&#8217;s about the safety of the majority. Cloud computing is THE solution for it makes problems the size that can&#8217;t be ignored ;-)<br />
Asking individuals to accepts responsibility is a losing strategy at this point. We need collective solutions so developers &amp; start-ups can start using cloud based services that are safe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dog Training Issues &#8211; Refusing to Come When Called Pets</title>
		<link>http://www.techcrunchit.com/2009/08/31/the-almost-hopeless-challenge-of-web-security/comment-page-1/#comment-12656</link>
		<dc:creator>Dog Training Issues &#8211; Refusing to Come When Called Pets</dc:creator>
		<pubDate>Tue, 01 Sep 2009 05:32:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunchit.com/?p=3459#comment-12656</guid>
		<description>[...] Today we are trusting the web with our most personal and important data, from private photos and social graphs to finances and key work documents. Our hesitation to share such information has dropped over the years as our trust in our favorite services grows. Yet all the while, the web is actually growing less secure, as sites are left open to new attacks that can spread easily and leave users&#8230;Read more &#187; [...]</description>
		<content:encoded><![CDATA[<p>[...] Today we are trusting the web with our most personal and important data, from private photos and social graphs to finances and key work documents. Our hesitation to share such information has dropped over the years as our trust in our favorite services grows. Yet all the while, the web is actually growing less secure, as sites are left open to new attacks that can spread easily and leave users&#8230;Read more &raquo; [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
