<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Untrusted text in security dialogs</title>
	<atom:link href="http://www.squarefree.com/2010/07/14/untrusted-text-in-security-dialogs/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.squarefree.com/2010/07/14/untrusted-text-in-security-dialogs/</link>
	<description>Jesse Ruderman on Firefox, security, and more</description>
	<lastBuildDate>Fri, 09 Sep 2011 05:56:55 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Mook</title>
		<link>http://www.squarefree.com/2010/07/14/untrusted-text-in-security-dialogs/comment-page-1/#comment-7027</link>
		<dc:creator>Mook</dc:creator>
		<pubDate>Thu, 15 Jul 2010 05:40:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/?p=596#comment-7027</guid>
		<description>That is awesome :)

Sadly, security-related UI (i.e. PSM) is rather underowned - as far as I can tell, the current owner is Johnath, but as you mentioned he seems to be way too loaded to spend time on it :(

Please think a *lot* more from the web site&#039;s point of view (and not just the security one) before removing things like onbeforeunload; it can also be used for good for things like making sure the user is aware that she hasn&#039;t committed before closing the page.</description>
		<content:encoded><![CDATA[<p>That is awesome :)</p>
<p>Sadly, security-related UI (i.e. PSM) is rather underowned &#8211; as far as I can tell, the current owner is Johnath, but as you mentioned he seems to be way too loaded to spend time on it :(</p>
<p>Please think a *lot* more from the web site&#8217;s point of view (and not just the security one) before removing things like onbeforeunload; it can also be used for good for things like making sure the user is aware that she hasn&#8217;t committed before closing the page.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio Maone</title>
		<link>http://www.squarefree.com/2010/07/14/untrusted-text-in-security-dialogs/comment-page-1/#comment-7010</link>
		<dc:creator>Giorgio Maone</dc:creator>
		<pubDate>Wed, 14 Jul 2010 23:31:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/?p=596#comment-7010</guid>
		<description>Interesting stuff. I loved the right-to-left URL attack. 
Thanks for sharing.</description>
		<content:encoded><![CDATA[<p>Interesting stuff. I loved the right-to-left URL attack.<br />
Thanks for sharing.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

