<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Firefox hack can expose your Google account</title>
	<atom:link href="http://tech.blorge.com/Structure:%20/2007/11/18/firefox-hack-can-expose-your-google-account/feed/" rel="self" type="application/rss+xml" />
	<link>http://tech.blorge.com/Structure: /2007/11/18/firefox-hack-can-expose-your-google-account/</link>
	<description>Technology news</description>
	<lastBuildDate>Sun, 22 Nov 2009 16:15:02 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Giorgio Maone</title>
		<link>http://tech.blorge.com/Structure:/2007/11/18/firefox-hack-can-expose-your-google-account/comment-page-1/#comment-49978</link>
		<dc:creator>Giorgio Maone</dc:creator>
		<pubDate>Sun, 18 Nov 2007 21:51:44 +0000</pubDate>
		<guid isPermaLink="false">http://tech.blorge.com/Structure: /2007/11/18/firefox-hack-can-expose-your-google-account/#comment-49978</guid>
		<description>&quot;There is an easy fix if you install the NoScript Firefox extension, but this means that you’ll be running absolutely no scripts, making for a far more boring web browsing experience.&quot;

This is incorrect and misleading, because NoScript protection against this bug is independent from JavaScript blocking, i.e. you can keep JavaScript enabled on sites where you need it and still be protected by NoScript against jar: attacks and other XSS exploits.

See &lt;a href=&quot;http://hackademix.net/2007/11/13/a-jar-of-misleading-advices/&quot; rel=&quot;nofollow&quot;&gt;A Jar of Misleading Advices&lt;/a&gt; for more details.</description>
		<content:encoded><![CDATA[<p>&#8220;There is an easy fix if you install the NoScript Firefox extension, but this means that you’ll be running absolutely no scripts, making for a far more boring web browsing experience.&#8221;</p>
<p>This is incorrect and misleading, because NoScript protection against this bug is independent from JavaScript blocking, i.e. you can keep JavaScript enabled on sites where you need it and still be protected by NoScript against jar: attacks and other XSS exploits.</p>
<p>See <a href="http://hackademix.net/2007/11/13/a-jar-of-misleading-advices/" rel="nofollow">A Jar of Misleading Advices</a> for more details.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
