<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: MozillaZine fixes information leak</title>
	<atom:link href="http://www.squarefree.com/2004/02/11/mozillazine-fixes-information-leak/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.squarefree.com/2004/02/11/mozillazine-fixes-information-leak/</link>
	<description>Jesse Ruderman on Firefox, security, and more</description>
	<lastBuildDate>Fri, 09 Sep 2011 05:56:55 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: b</title>
		<link>http://www.squarefree.com/2004/02/11/mozillazine-fixes-information-leak/comment-page-1/#comment-282</link>
		<dc:creator>b</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/test/wp15/wordpress/?p=101#comment-282</guid>
		<description>It&#039;s good that the hole has been fixed. MozillaZine rarely gets information in advance (they only knew of the name because Kerz came up with it), but it could be damaging if any info they did have got out early.

That said, if Jesus_X knew about this hole so long ago, why didn&#039;t he inform anyone? So he could spy on MozillaZine, I guess.</description>
		<content:encoded><![CDATA[<p>It&#8217;s good that the hole has been fixed. MozillaZine rarely gets information in advance (they only knew of the name because Kerz came up with it), but it could be damaging if any info they did have got out early.</p>
<p>That said, if Jesus_X knew about this hole so long ago, why didn&#8217;t he inform anyone? So he could spy on MozillaZine, I guess.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jesse Ruderman</title>
		<link>http://www.squarefree.com/2004/02/11/mozillazine-fixes-information-leak/comment-page-1/#comment-283</link>
		<dc:creator>Jesse Ruderman</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/test/wp15/wordpress/?p=101#comment-283</guid>
		<description>I don&#039;t think jesus_X knew about the title leak until I told him about it.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t think jesus_X knew about the title leak until I told him about it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alanjstr</title>
		<link>http://www.squarefree.com/2004/02/11/mozillazine-fixes-information-leak/comment-page-1/#comment-284</link>
		<dc:creator>alanjstr</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/test/wp15/wordpress/?p=101#comment-284</guid>
		<description>I&#039;m sure they were notified in advance enough to change the forum names, just like djst was notified so he could update his website before it was slashdotted.</description>
		<content:encoded><![CDATA[<p>I&#8217;m sure they were notified in advance enough to change the forum names, just like djst was notified so he could update his website before it was slashdotted.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex Bishop</title>
		<link>http://www.squarefree.com/2004/02/11/mozillazine-fixes-information-leak/comment-page-1/#comment-285</link>
		<dc:creator>Alex Bishop</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/test/wp15/wordpress/?p=101#comment-285</guid>
		<description>Question: You&#039;ve found a security hole in a website. What do you do?

A. Tell the maintainers of the site.
B. Tell their nearest competitor, allowing them to steal news.

I knew that reading the headlines of unpublished articles was possible under certain circumstances but thought that no-one else knew about it. In any case, most of the future article headlines are hardly top secret. I did take precautions with some sensitive articles though. I thought Kerz knew about the hole. Seems he didn&#039;t.

This is the first I&#039;ve ever heard of full articles being visible before publication.

We were told in advance about the name change, as well as the release dates and times. Similar to when we were told about the new end user services launch or last year&#039;s major Roadmap update. Completely dissimilar to when we weren&#039;t told about the creation of the Mozilla Foundation. They&#039;re quite good about supplying prerelease news now.</description>
		<content:encoded><![CDATA[<p>Question: You&#8217;ve found a security hole in a website. What do you do?</p>
<p>A. Tell the maintainers of the site.<br />
B. Tell their nearest competitor, allowing them to steal news.</p>
<p>I knew that reading the headlines of unpublished articles was possible under certain circumstances but thought that no-one else knew about it. In any case, most of the future article headlines are hardly top secret. I did take precautions with some sensitive articles though. I thought Kerz knew about the hole. Seems he didn&#8217;t.</p>
<p>This is the first I&#8217;ve ever heard of full articles being visible before publication.</p>
<p>We were told in advance about the name change, as well as the release dates and times. Similar to when we were told about the new end user services launch or last year&#8217;s major Roadmap update. Completely dissimilar to when we weren&#8217;t told about the creation of the Mozilla Foundation. They&#8217;re quite good about supplying prerelease news now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jesus X</title>
		<link>http://www.squarefree.com/2004/02/11/mozillazine-fixes-information-leak/comment-page-1/#comment-286</link>
		<dc:creator>jesus X</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/test/wp15/wordpress/?p=101#comment-286</guid>
		<description>To &quot;b&quot;: As Jesse said in a reply, I didn&#039;t know about the headline-in-titlebar hole until he told me, as I don&#039;t have the same security-hole detection abilities as Jesse does. He finds them everywhere, with amazing speed. It&#039;s one his his many talents. As for not notifying anyone, as Jesse said, this was LONG ago that there was a hole I knew of, and it had long since been fixed.  I have no such interest in spying on MoZine, flat out. Please keep those kinds of guesses to yourself.

To Alex: I don&#039;t need to &quot;steal&quot; your news, nor did I. If you have problems with me, take it up with me, not in someone else&#039;s blog comments. Jesse just happened to ask if I knew anything about the name change. He didn&#039;t run to tell me of the bug. You only make yourself look bad when you try to insult myself and Jesse. You owe Jesse an apology.</description>
		<content:encoded><![CDATA[<p>To &#8220;b&#8221;: As Jesse said in a reply, I didn&#8217;t know about the headline-in-titlebar hole until he told me, as I don&#8217;t have the same security-hole detection abilities as Jesse does. He finds them everywhere, with amazing speed. It&#8217;s one his his many talents. As for not notifying anyone, as Jesse said, this was LONG ago that there was a hole I knew of, and it had long since been fixed.  I have no such interest in spying on MoZine, flat out. Please keep those kinds of guesses to yourself.</p>
<p>To Alex: I don&#8217;t need to &#8220;steal&#8221; your news, nor did I. If you have problems with me, take it up with me, not in someone else&#8217;s blog comments. Jesse just happened to ask if I knew anything about the name change. He didn&#8217;t run to tell me of the bug. You only make yourself look bad when you try to insult myself and Jesse. You owe Jesse an apology.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex Bishop</title>
		<link>http://www.squarefree.com/2004/02/11/mozillazine-fixes-information-leak/comment-page-1/#comment-287</link>
		<dc:creator>Alex Bishop</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/test/wp15/wordpress/?p=101#comment-287</guid>
		<description>jesus_X: I wasn&#039;t trying to insult anyone, just expressing my surprise that a member of the Mozilla security group&#039;s first thought on finding a bug in a popular Mozilla news site was not to tell the site&#039;s maintainers but to discuss the issue with a maintainer of a rival site.

Maybe you don&#039;t need to steal news. However, the fact remains that the Mozilla Foundation decided not to tell you about the name change for whatever reason, yet you still had an article ready in time for the midnight launch.</description>
		<content:encoded><![CDATA[<p>jesus_X: I wasn&#8217;t trying to insult anyone, just expressing my surprise that a member of the Mozilla security group&#8217;s first thought on finding a bug in a popular Mozilla news site was not to tell the site&#8217;s maintainers but to discuss the issue with a maintainer of a rival site.</p>
<p>Maybe you don&#8217;t need to steal news. However, the fact remains that the Mozilla Foundation decided not to tell you about the name change for whatever reason, yet you still had an article ready in time for the midnight launch.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

