<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Google Browser Sync</title>
	<atom:link href="http://dcortesi.com/2006/12/11/google-browser-sync/feed/" rel="self" type="application/rss+xml" />
	<link>http://dcortesi.com/2006/12/11/google-browser-sync/</link>
	<description>Coding, Security, and maybe a little bit about Damon Cortesi</description>
	<pubDate>Wed, 20 Aug 2008 17:18:28 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Damon</title>
		<link>http://dcortesi.com/2006/12/11/google-browser-sync/#comment-13569</link>
		<dc:creator>Damon</dc:creator>
		<pubDate>Sat, 16 Dec 2006 19:32:18 +0000</pubDate>
		<guid isPermaLink="false">http://dcortesi.com/2006/12/11/google-browser-sync/#comment-13569</guid>
		<description>Well it seems to happen whenever I leave Seattle!  So I guess that means I should stay in town more often.</description>
		<content:encoded><![CDATA[<p>Well it seems to happen whenever I leave Seattle!  So I guess that means I should stay in town more often.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lauriannjane</title>
		<link>http://dcortesi.com/2006/12/11/google-browser-sync/#comment-13564</link>
		<dc:creator>lauriannjane</dc:creator>
		<pubDate>Sat, 16 Dec 2006 15:05:23 +0000</pubDate>
		<guid isPermaLink="false">http://dcortesi.com/2006/12/11/google-browser-sync/#comment-13564</guid>
		<description>Hey Damon, ever since you moved out there I've read one article after another on big storms, monsoons, etc.  You windstorm of yesterday made front page news on our Pittsburgh Post Gazette.  Does this have anything to do with your arrival there??</description>
		<content:encoded><![CDATA[<p>Hey Damon, ever since you moved out there I&#8217;ve read one article after another on big storms, monsoons, etc.  You windstorm of yesterday made front page news on our Pittsburgh Post Gazette.  Does this have anything to do with your arrival there??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ha.ckers.org web application security lab - Archive &#187; Firefox Allows Any Site To Inject XPI Via XSS Via Delegation</title>
		<link>http://dcortesi.com/2006/12/11/google-browser-sync/#comment-13458</link>
		<dc:creator>ha.ckers.org web application security lab - Archive &#187; Firefox Allows Any Site To Inject XPI Via XSS Via Delegation</dc:creator>
		<pubDate>Wed, 13 Dec 2006 19:49:19 +0000</pubDate>
		<guid isPermaLink="false">http://dcortesi.com/2006/12/11/google-browser-sync/#comment-13458</guid>
		<description>[...] Apparently this is true, although I can&#8217;t for the life of me figure out why this should be allowed. I ran across an article at DCortesi&#8217;s site talking about how Firefox has delegated their security to Google for installation of the Google Sync XPI. Pretty scary actually. What this means is that if an XSS hole were ever found in any whitelisted domain (including XSS in their server, MITM through your proxy server etc&#8230;) Firefox will happily allow you to download xpi files. I&#8217;ve talked with a few people about this off and on in a different context of loading an xpi file into a data: directive on the whitelisted domain. Yah, that&#8217;s scary. This is worse. [...]</description>
		<content:encoded><![CDATA[<p>[...] Apparently this is true, although I can&#8217;t for the life of me figure out why this should be allowed. I ran across an article at DCortesi&#8217;s site talking about how Firefox has delegated their security to Google for installation of the Google Sync XPI. Pretty scary actually. What this means is that if an XSS hole were ever found in any whitelisted domain (including XSS in their server, MITM through your proxy server etc&#8230;) Firefox will happily allow you to download xpi files. I&#8217;ve talked with a few people about this off and on in a different context of loading an xpi file into a data: directive on the whitelisted domain. Yah, that&#8217;s scary. This is worse. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ziru Zhu</title>
		<link>http://dcortesi.com/2006/12/11/google-browser-sync/#comment-13418</link>
		<dc:creator>Ziru Zhu</dc:creator>
		<pubDate>Tue, 12 Dec 2006 06:53:21 +0000</pubDate>
		<guid isPermaLink="false">http://dcortesi.com/2006/12/11/google-browser-sync/#comment-13418</guid>
		<description>I would blame Mozilla more on this.</description>
		<content:encoded><![CDATA[<p>I would blame Mozilla more on this.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

