<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Google falters? Can&apos;t be!</title>
	<link>http://www.metafilter.com/36619/Google-falters-Cant-be/</link>
	<description>Comments on MetaFilter post Google falters? Can&apos;t be!</description>
	<pubDate>Fri, 29 Oct 2004 16:39:13 -0800</pubDate>
	<lastBuildDate>Fri, 29 Oct 2004 16:39:13 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Google falters? Can&apos;t be!</title>
		<link>http://www.metafilter.com/36619/Google-falters-Cant-be</link>	
		<description>&lt;a href="http://www.theregister.co.uk/2004/10/29/gmail_vuln/"&gt;GMail not-so-safe Mail.&lt;/a&gt; So apparentley GMail has a major exploit that&apos;s been discovered by an Israeli hacker. &lt;i&gt;&quot;Using a hex-encoded XSS link, the victim&apos;s cookie file can be stolen by a hacker, who can later use it to identify himself to Gmail as the original owner of an email account, regardless of whether or not the password is subsequently changed.&quot;&lt;/i&gt; And so the fun with GMail begins..</description>
		<guid isPermaLink="false">post:www.metafilter.com,2004:site.36619</guid>
		<pubDate>Fri, 29 Oct 2004 16:37:21 -0800</pubDate>
		<dc:creator>mrplab</dc:creator>		<category>Google</category>		<category>gmail</category>		<category>email</category>		<category>hacking</category>		<category>security</category>		<category>cookies</category>		<category>phishing</category>
	</item>	<item>
		<title>By: 327.ca</title>
		<link>http://www.metafilter.com/36619/Google-falters-Cant-be#758829</link>	
		<description>Good. These are the kind of things one hopes to find in beta testing. Right?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2004:site.36619-758829</guid>
		<pubDate>Fri, 29 Oct 2004 16:39:13 -0800</pubDate>
		<dc:creator>327.ca</dc:creator>
	</item>	<item>
		<title>By: mrplab</title>
		<link>http://www.metafilter.com/36619/Google-falters-Cant-be#758832</link>	
		<description>And by the way, more information &lt;a href=&quot;http://net.nana.co.il/Article/?ArticleID=155025&amp;sid=10&quot;&gt;here&lt;/a&gt; from the Israeli news source.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2004:site.36619-758832</guid>
		<pubDate>Fri, 29 Oct 2004 16:40:18 -0800</pubDate>
		<dc:creator>mrplab</dc:creator>
	</item>	<item>
		<title>By: neckro23</title>
		<link>http://www.metafilter.com/36619/Google-falters-Cant-be#758856</link>	
		<description>It sounds to me like in order to get hacked, you have to fall for a phishing-style thinger first.  Pfff.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2004:site.36619-758856</guid>
		<pubDate>Fri, 29 Oct 2004 23:20:04 -0800</pubDate>
		<dc:creator>neckro23</dc:creator>
	</item>	<item>
		<title>By: SpecialK</title>
		<link>http://www.metafilter.com/36619/Google-falters-Cant-be#758872</link>	
		<description>Yeah, but it&apos;s still bad design -- something you wouldn&apos;t expect from Google.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2004:site.36619-758872</guid>
		<pubDate>Fri, 29 Oct 2004 23:32:49 -0800</pubDate>
		<dc:creator>SpecialK</dc:creator>
	</item>	<item>
		<title>By: Keyser Soze</title>
		<link>http://www.metafilter.com/36619/Google-falters-Cant-be#758884</link>	
		<description>Yeah SpecialK me neither, but then again it was only a matter of pressure and time. Whatever man makes a person can take apart.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2004:site.36619-758884</guid>
		<pubDate>Fri, 29 Oct 2004 23:58:32 -0800</pubDate>
		<dc:creator>Keyser Soze</dc:creator>
	</item>	<item>
		<title>By: SpecialK</title>
		<link>http://www.metafilter.com/36619/Google-falters-Cant-be#758896</link>	
		<description>True, but I&apos;d expect them to have something obscure taken apart. I&apos;ve got a more secure cookie-based authentication than that running for my webapps; they&apos;re not hard to code at all.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2004:site.36619-758896</guid>
		<pubDate>Sat, 30 Oct 2004 00:46:11 -0800</pubDate>
		<dc:creator>SpecialK</dc:creator>
	</item>	<item>
		<title>By: SpecialK</title>
		<link>http://www.metafilter.com/36619/Google-falters-Cant-be#758898</link>	
		<description>(I mean, just a simple username/hash stored in a cookie that doesn&apos;t change over 2 weeks? Bad form. If you&apos;re going to keep an authentication token like that, it should change frequently, and be based on some facts that are on the server and stored on the user&apos;s machine just coincidentally. For instance, I store a serialized array with the user&apos;s login name in one field and a 60-charachter hash in the second. The hash is built off of the user&apos;s session record in the database that they&apos;re accessing; it&apos;s made up of the last time the hash was changed (about every 5 pageviews), the user&apos;s password, and some other bits of trivia. The server builds the hash, then retreives the hash from the cookie and compares the two. If they don&apos;t match, the user gets kicked back to the login screen. It&apos;s not bulletproof and unbreakable of course, but I&apos;ve had people try ... and without hacking the server, it hasn&apos;t been broken. Yet, of course.)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2004:site.36619-758898</guid>
		<pubDate>Sat, 30 Oct 2004 00:51:36 -0800</pubDate>
		<dc:creator>SpecialK</dc:creator>
	</item>	<item>
		<title>By: ac</title>
		<link>http://www.metafilter.com/36619/Google-falters-Cant-be#758977</link>	
		<description>hash browns taste good</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2004:site.36619-758977</guid>
		<pubDate>Sat, 30 Oct 2004 08:31:21 -0800</pubDate>
		<dc:creator>ac</dc:creator>
	</item>	<item>
		<title>By: hincandenza</title>
		<link>http://www.metafilter.com/36619/Google-falters-Cant-be#759157</link>	
		<description>This just goes to show that &lt;strike&gt;Microsoft&lt;/strike&gt; Google is not serious about user privacy, security or good software.  

Hey, welcome to the big-leagues, boys.  You&apos;re a bona fide target now!  :)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2004:site.36619-759157</guid>
		<pubDate>Sat, 30 Oct 2004 15:19:30 -0800</pubDate>
		<dc:creator>hincandenza</dc:creator>
	</item>
	</channel>
</rss>
