<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New security features in IE8</title>
	<atom:link href="http://www.squarefree.com/2008/07/04/new-security-features-in-ie8/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.squarefree.com/2008/07/04/new-security-features-in-ie8/</link>
	<description>Jesse Ruderman on Firefox, security, and more</description>
	<lastBuildDate>Fri, 09 Sep 2011 05:56:55 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Gerv</title>
		<link>http://www.squarefree.com/2008/07/04/new-security-features-in-ie8/comment-page-1/#comment-4179</link>
		<dc:creator>Gerv</dc:creator>
		<pubDate>Mon, 07 Jul 2008 08:35:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/?p=398#comment-4179</guid>
		<description>From a usability point of view, lack of whitelisting JS execution is not about &quot;developer politics&quot;, it&#039;s about the fact that websites stop working by default, and people don&#039;t like that.</description>
		<content:encoded><![CDATA[<p>From a usability point of view, lack of whitelisting JS execution is not about &#8220;developer politics&#8221;, it&#8217;s about the fact that websites stop working by default, and people don&#8217;t like that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ant</title>
		<link>http://www.squarefree.com/2008/07/04/new-security-features-in-ie8/comment-page-1/#comment-4175</link>
		<dc:creator>ant</dc:creator>
		<pubDate>Fri, 04 Jul 2008 23:38:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/?p=398#comment-4175</guid>
		<description>The XSS thing is something NoScript already protects against.

I&#039;d expect such a simple thing (whitelist JS execution) to be built into the browser by now since it&#039;s been getting requested for X years, but as usual developer politics seem to be killing progress...</description>
		<content:encoded><![CDATA[<p>The XSS thing is something NoScript already protects against.</p>
<p>I&#8217;d expect such a simple thing (whitelist JS execution) to be built into the browser by now since it&#8217;s been getting requested for X years, but as usual developer politics seem to be killing progress&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lee</title>
		<link>http://www.squarefree.com/2008/07/04/new-security-features-in-ie8/comment-page-1/#comment-4174</link>
		<dc:creator>Lee</dc:creator>
		<pubDate>Fri, 04 Jul 2008 22:24:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/?p=398#comment-4174</guid>
		<description>I see their address bar now highlights the domain, making the rest of the URL grey. I seem to recall reading that this was removed from firefox nightlies because people found it annoying/harder to read, so I&#039;m interested to see what happens with it in IE.

I do quite like the idea of isolated mode, though - it&#039;s nice that different tabs can be loaded with different privileges according to the native OS, and that crashes are less of an annoyance. Conceivably this could help with reclaiming lost memory, such as when a plugin leaks memory, too.</description>
		<content:encoded><![CDATA[<p>I see their address bar now highlights the domain, making the rest of the URL grey. I seem to recall reading that this was removed from firefox nightlies because people found it annoying/harder to read, so I&#8217;m interested to see what happens with it in IE.</p>
<p>I do quite like the idea of isolated mode, though &#8211; it&#8217;s nice that different tabs can be loaded with different privileges according to the native OS, and that crashes are less of an annoyance. Conceivably this could help with reclaiming lost memory, such as when a plugin leaks memory, too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mardeg</title>
		<link>http://www.squarefree.com/2008/07/04/new-security-features-in-ie8/comment-page-1/#comment-4173</link>
		<dc:creator>Mardeg</dc:creator>
		<pubDate>Fri, 04 Jul 2008 22:16:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/?p=398#comment-4173</guid>
		<description>&quot;IE8 prevents “upsniff” of files served with image/* content types into HTML/Script. Even if a file contains script, if the server declares that it is an image, IE will not run the embedded script.&quot;
&quot;We were able to make this change by default with minimal compatibility impact because servers rarely knowingly send HTML or script with an image/* content type.&quot;

So much for them working towards natively supporting image/svg+xml which allows javascript in SVG files (does this also break Adobe&#039;s SVG viewer?)</description>
		<content:encoded><![CDATA[<p>&#8220;IE8 prevents “upsniff” of files served with image/* content types into HTML/Script. Even if a file contains script, if the server declares that it is an image, IE will not run the embedded script.&#8221;<br />
&#8220;We were able to make this change by default with minimal compatibility impact because servers rarely knowingly send HTML or script with an image/* content type.&#8221;</p>
<p>So much for them working towards natively supporting image/svg+xml which allows javascript in SVG files (does this also break Adobe&#8217;s SVG viewer?)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

