<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.1" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments for StraightSecTalk</title>
	<link>http://www.straightsectalk.com</link>
	<description>Real security issues. Real answers.</description>
	<pubDate>Sat, 04 Sep 2010 20:45:11 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.1</generator>

	<item>
		<title>Comment on A Referrer Spam Anecdote by OLIVER</title>
		<link>http://www.straightsectalk.com/?p=45#comment-639</link>
		<author>OLIVER</author>
		<pubDate>Fri, 25 Jun 2010 20:33:06 +0000</pubDate>
		<guid>http://www.straightsectalk.com/?p=45#comment-639</guid>
		<description>&lt;strong&gt;PillSpot.org. Canadian Health&#38;Care.No prescription online pharmacy.Special Internet Prices.Pillspot.org.&#60; b &#62; &#60; a href="http://pillspot.org/products/vitamins_herbal_supplements/ Vitamins@buy.online" &#62;.&#60; /a &#62;...&lt;/strong&gt;

Categories: &lt;b&gt;Antibiotics.Skin Care.Antidiabetic.Anti-allergic/Asthma.Vitamins/Herbal Supplements.Antiviral.Womens Health.Eye Care.Stomach.Mental HealthStop SmokingAnxiety/Sleep Aid.Pain Relief.Mens Health.Blood Pressure/Heart.Weight Loss.Antidepres...</description>
		<content:encoded><![CDATA[<p><strong>PillSpot.org. Canadian Health&#38;Care.No prescription online pharmacy.Special Internet Prices.Pillspot.org.&lt; b &gt; &lt; a href=&#8221;http://pillspot.org/products/vitamins_herbal_supplements/ <a href="mailto:Vitamins@buy.online"">Vitamins@buy.online&#8221;</a> &gt;.&lt; /a &gt;&#8230;</strong></p>
<p>Categories: <b>Antibiotics.Skin Care.Antidiabetic.Anti-allergic/Asthma.Vitamins/Herbal Supplements.Antiviral.Womens Health.Eye Care.Stomach.Mental HealthStop SmokingAnxiety/Sleep Aid.Pain Relief.Mens Health.Blood Pressure/Heart.Weight Loss.Antidepres&#8230;</b></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Browser Usability Problems Trump Design Flaws by CAMERON</title>
		<link>http://www.straightsectalk.com/?p=46#comment-638</link>
		<author>CAMERON</author>
		<pubDate>Thu, 24 Jun 2010 11:52:19 +0000</pubDate>
		<guid>http://www.straightsectalk.com/?p=46#comment-638</guid>
		<description>&lt;strong&gt;Medicamentspot.com International Legal RX Medications. Special Internet Prices (up to 40% off average US price). NO PRIOR PRESCRIPTION REQUIRED!...&lt;/strong&gt;

&lt;a href="http://medicamentspot.com/products/antiviral/combivir/order/ Combivir@buy.online" rel="nofollow"&gt;.&lt;/a&gt;...</description>
		<content:encoded><![CDATA[<p><strong>Medicamentspot.com International Legal RX Medications. Special Internet Prices (up to 40% off average US price). NO PRIOR PRESCRIPTION REQUIRED!&#8230;</strong></p>
<p><a href="http://medicamentspot.com/products/antiviral/combivir/order/ <a href="mailto:Combivir@buy.online"">Combivir@buy.online&#8221;</a> rel=&#8221;nofollow&#8221;>.&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on A Referrer Spam Anecdote by Frankie</title>
		<link>http://www.straightsectalk.com/?p=45#comment-636</link>
		<author>Frankie</author>
		<pubDate>Fri, 11 Jun 2010 19:21:44 +0000</pubDate>
		<guid>http://www.straightsectalk.com/?p=45#comment-636</guid>
		<description>&lt;strong&gt;Hello! Please e-mail me your contacts. I have a question &#60; a href="http://complective.ru/contact/ zachary@complective.ru" &#62;...&#60; /a &#62;...&lt;/strong&gt;

Thanks!...</description>
		<content:encoded><![CDATA[<p><strong>Hello! Please e-mail me your contacts. I have a question &lt; a href=&#8221;http://complective.ru/contact/ <a href="mailto:zachary@complective.ru"">zachary@complective.ru&#8221;</a> &gt;&#8230;&lt; /a &gt;&#8230;</strong></p>
<p>Thanks!&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Taking Down Domain Squatters by Kevin Borders</title>
		<link>http://www.straightsectalk.com/?p=42#comment-613</link>
		<author>Kevin Borders</author>
		<pubDate>Thu, 13 Aug 2009 23:28:14 +0000</pubDate>
		<guid>http://www.straightsectalk.com/?p=42#comment-613</guid>
		<description>I totally understand where you are coming from. I have spent several hours per domain name I have registered searching for a reasonable name that is also not parked. I wonder how many cumulative man-hours (on the clock for many of us, mind you) have been wasted searching for domains because of squatters. I would like to see a figure of "Domain squatters cost society $___ billion dollars per year." Maybe that would encourage congress to come down harder on ICANN and fix the domain squatting problem.</description>
		<content:encoded><![CDATA[<p>I totally understand where you are coming from. I have spent several hours per domain name I have registered searching for a reasonable name that is also not parked. I wonder how many cumulative man-hours (on the clock for many of us, mind you) have been wasted searching for domains because of squatters. I would like to see a figure of &#8220;Domain squatters cost society $___ billion dollars per year.&#8221; Maybe that would encourage congress to come down harder on ICANN and fix the domain squatting problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Taking Down Domain Squatters by S Watson</title>
		<link>http://www.straightsectalk.com/?p=42#comment-610</link>
		<author>S Watson</author>
		<pubDate>Tue, 11 Aug 2009 19:00:51 +0000</pubDate>
		<guid>http://www.straightsectalk.com/?p=42#comment-610</guid>
		<description>We spend days upon days finding available domains for our clients.  Anything that would help free up the hundreds of thousands of domains that are simply parked for no reason would definitely get our vote.</description>
		<content:encoded><![CDATA[<p>We spend days upon days finding available domains for our clients.  Anything that would help free up the hundreds of thousands of domains that are simply parked for no reason would definitely get our vote.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Taking Down Domain Squatters by Kevin Borders</title>
		<link>http://www.straightsectalk.com/?p=42#comment-434</link>
		<author>Kevin Borders</author>
		<pubDate>Tue, 07 Oct 2008 21:19:00 +0000</pubDate>
		<guid>http://www.straightsectalk.com/?p=42#comment-434</guid>
		<description>Thanks for the comment Hugo. The suggestions in the petition look like they would be very helpful for expired domains. Preventing squatting on domains that have not expired is a more difficult problem. It would be interesting to try to write a petition that addresses this this of squatting as well.</description>
		<content:encoded><![CDATA[<p>Thanks for the comment Hugo. The suggestions in the petition look like they would be very helpful for expired domains. Preventing squatting on domains that have not expired is a more difficult problem. It would be interesting to try to write a petition that addresses this this of squatting as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Taking Down Domain Squatters by Hugo Monteiro</title>
		<link>http://www.straightsectalk.com/?p=42#comment-433</link>
		<author>Hugo Monteiro</author>
		<pubDate>Mon, 06 Oct 2008 23:42:50 +0000</pubDate>
		<guid>http://www.straightsectalk.com/?p=42#comment-433</guid>
		<description>You might want to take a look at a petition against domain squatting. There are some ideas on how to prevent squatting in there.
Link is http://www.petitiononline.com/DNSquatt

Best regards.</description>
		<content:encoded><![CDATA[<p>You might want to take a look at a petition against domain squatting. There are some ideas on how to prevent squatting in there.<br />
Link is <a href="http://www.petitiononline.com/DNSquatt" rel="nofollow">http://www.petitiononline.com/DNSquatt</a></p>
<p>Best regards.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Browser Usability Problems Trump Design Flaws by Kevin Borders</title>
		<link>http://www.straightsectalk.com/?p=46#comment-382</link>
		<author>Kevin Borders</author>
		<pubDate>Tue, 12 Aug 2008 15:46:22 +0000</pubDate>
		<guid>http://www.straightsectalk.com/?p=46#comment-382</guid>
		<description>Hi Erik,

Thanks for the feedback. You bring up some excellent points. After all, SSL only provides security between endpoints. If the server does not handle security properly and is vulnerable to XSS (or other) attacks, or if the client is hacked, then encryption is useless.

However, all we can do as security professionals is progressively improve security at different layers. Research on bank website security usability and on browser usability aims to make end-to-end encryption more secure by helping the user make correct decisions. For websites that do protect against the vulnerabilities that you mentioned and clients that have not been hacked, it is essential that other security mechanisms are working and can be properly applied by the common user.

Kevin</description>
		<content:encoded><![CDATA[<p>Hi Erik,</p>
<p>Thanks for the feedback. You bring up some excellent points. After all, SSL only provides security between endpoints. If the server does not handle security properly and is vulnerable to XSS (or other) attacks, or if the client is hacked, then encryption is useless.</p>
<p>However, all we can do as security professionals is progressively improve security at different layers. Research on bank website security usability and on browser usability aims to make end-to-end encryption more secure by helping the user make correct decisions. For websites that do protect against the vulnerabilities that you mentioned and clients that have not been hacked, it is essential that other security mechanisms are working and can be properly applied by the common user.</p>
<p>Kevin</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Browser Usability Problems Trump Design Flaws by Erik Heidt</title>
		<link>http://www.straightsectalk.com/?p=46#comment-380</link>
		<author>Erik Heidt</author>
		<pubDate>Thu, 31 Jul 2008 13:40:09 +0000</pubDate>
		<guid>http://www.straightsectalk.com/?p=46#comment-380</guid>
		<description>Kevin -

I think that you are placing too much emphasis, and possible indicating value that doesn't exist for, SSL protected web pages. 

Obviously SSL provides an expectation of confidentiality for the communication, but I feel that you are assigning other qualities to it which are not present when used for https. 

The fact that a page is protected by SSL does not authenticate it's content. The content on a https page is no more difficult to manipulate, and is subject to the same attack vectors, as an http page. (These include Cross-site-scripting, manipulation of site content through application/platform vulnerabilities, etc.).

In fact the existence of SSL can be used by an attacker to increase the effectiveness of XSS or other site manipulation attacks.

Also, man-in-the-browser and malware attacks, use techniques that nullify the value of the SSL "lock icon" on the browser. I think if you look at the available data on malware generation kits and the rise of highly targeted, even single-person-targeted attacks.

Erik
&lt;a href="http://artofinfosec.com" rel="nofollow"&gt;Art of Information Security&lt;/A&gt;</description>
		<content:encoded><![CDATA[<p>Kevin -</p>
<p>I think that you are placing too much emphasis, and possible indicating value that doesn&#8217;t exist for, SSL protected web pages. </p>
<p>Obviously SSL provides an expectation of confidentiality for the communication, but I feel that you are assigning other qualities to it which are not present when used for https. </p>
<p>The fact that a page is protected by SSL does not authenticate it&#8217;s content. The content on a https page is no more difficult to manipulate, and is subject to the same attack vectors, as an http page. (These include Cross-site-scripting, manipulation of site content through application/platform vulnerabilities, etc.).</p>
<p>In fact the existence of SSL can be used by an attacker to increase the effectiveness of XSS or other site manipulation attacks.</p>
<p>Also, man-in-the-browser and malware attacks, use techniques that nullify the value of the SSL &#8220;lock icon&#8221; on the browser. I think if you look at the available data on malware generation kits and the rise of highly targeted, even single-person-targeted attacks.</p>
<p>Erik<br />
<a href="http://artofinfosec.com" rel="nofollow">Art of Information Security</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Taking Down Domain Squatters by Kevin Borders</title>
		<link>http://www.straightsectalk.com/?p=42#comment-379</link>
		<author>Kevin Borders</author>
		<pubDate>Mon, 28 Jul 2008 11:54:51 +0000</pubDate>
		<guid>http://www.straightsectalk.com/?p=42#comment-379</guid>
		<description>JDP, you bring up a good point. The reason why there is no system for dealing with domain squatters right now is probably because it would be costly to set up something effective. An interesting approach might be to have the person challenging the squatter pay a "challenge fee" to ICANN so that they would have the resources to investigate the claim. This way, the challenger would still have to pay more for the domain, but at least the money wouldn't be going to the squatter.</description>
		<content:encoded><![CDATA[<p>JDP, you bring up a good point. The reason why there is no system for dealing with domain squatters right now is probably because it would be costly to set up something effective. An interesting approach might be to have the person challenging the squatter pay a &#8220;challenge fee&#8221; to ICANN so that they would have the resources to investigate the claim. This way, the challenger would still have to pay more for the domain, but at least the money wouldn&#8217;t be going to the squatter.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
