<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: SSLFail.com == SSL FAIL?</title>
	<atom:link href="http://www.sslfail.com/2009/01/sslfailcom-ssl-fail/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sslfail.com/2009/01/sslfailcom-ssl-fail/</link>
	<description>1.2.840.113549.1.1</description>
	<lastBuildDate>Thu, 01 Jul 2010 03:13:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Tyler</title>
		<link>http://www.sslfail.com/2009/01/sslfailcom-ssl-fail/comment-page-1/#comment-87</link>
		<dc:creator>Tyler</dc:creator>
		<pubDate>Fri, 27 Feb 2009 11:52:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=225#comment-87</guid>
		<description>Michael, 

I agree... the assumption I made on people wanting SSL or complaining about the lack of SSL was that they wanted to bypass some basic content filter and were worried about the content of the site. 

In that case, the encryption is needed but not the trust, hence the self-signed certificate. 

Tyler.</description>
		<content:encoded><![CDATA[<p>Michael, </p>
<p>I agree&#8230; the assumption I made on people wanting SSL or complaining about the lack of SSL was that they wanted to bypass some basic content filter and were worried about the content of the site. </p>
<p>In that case, the encryption is needed but not the trust, hence the self-signed certificate. </p>
<p>Tyler.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Coates</title>
		<link>http://www.sslfail.com/2009/01/sslfailcom-ssl-fail/comment-page-1/#comment-83</link>
		<dc:creator>Michael Coates</dc:creator>
		<pubDate>Thu, 26 Feb 2009 16:20:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=225#comment-83</guid>
		<description>Agree, SSL is not needed for viewers of this site.  I don&#039;t provide you any sensitive data, nor do you have any sensitive data of mine.  The worse case is a MitM injects false content. 

Yes, a MitM could inject a malicious script, but they could do that for any other page I browse to just as easily.

-Michael</description>
		<content:encoded><![CDATA[<p>Agree, SSL is not needed for viewers of this site.  I don&#8217;t provide you any sensitive data, nor do you have any sensitive data of mine.  The worse case is a MitM injects false content. </p>
<p>Yes, a MitM could inject a malicious script, but they could do that for any other page I browse to just as easily.</p>
<p>-Michael</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick</title>
		<link>http://www.sslfail.com/2009/01/sslfailcom-ssl-fail/comment-page-1/#comment-54</link>
		<dc:creator>Patrick</dc:creator>
		<pubDate>Mon, 09 Feb 2009 20:33:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=225#comment-54</guid>
		<description>https://www.register.com/titan/promo/ssl_essential_1.rcmx

$12.67 per year for three years.</description>
		<content:encoded><![CDATA[<p><a href="https://www.register.com/titan/promo/ssl_essential_1.rcmx" rel="nofollow">https://www.register.com/titan/promo/ssl_essential_1.rcmx</a></p>
<p>$12.67 per year for three years.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Dickey</title>
		<link>http://www.sslfail.com/2009/01/sslfailcom-ssl-fail/comment-page-1/#comment-27</link>
		<dc:creator>Michael Dickey</dc:creator>
		<pubDate>Wed, 28 Jan 2009 21:33:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=225#comment-27</guid>
		<description>You MUST have SSL or else someone can inject!!

(No, I&#039;m with you, I think it is an arguable thing...unless you want to support encrypting everything on the web, which I wouldn&#039;t mind, but I&#039;m sure pretty much every government would mind.)

I&#039;ve already sniffed Marcin&#039;s password to the site...nicely enough, he uses it for other things too!</description>
		<content:encoded><![CDATA[<p>You MUST have SSL or else someone can inject!!</p>
<p>(No, I&#8217;m with you, I think it is an arguable thing&#8230;unless you want to support encrypting everything on the web, which I wouldn&#8217;t mind, but I&#8217;m sure pretty much every government would mind.)</p>
<p>I&#8217;ve already sniffed Marcin&#8217;s password to the site&#8230;nicely enough, he uses it for other things too!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marcin</title>
		<link>http://www.sslfail.com/2009/01/sslfailcom-ssl-fail/comment-page-1/#comment-26</link>
		<dc:creator>Marcin</dc:creator>
		<pubDate>Tue, 27 Jan 2009 18:06:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=225#comment-26</guid>
		<description>Oh no!  What on earth could we do?  Wait, I have an idea!

How about we SSH to the server, and then write posts using SQL INSERT statements.  Yah!</description>
		<content:encoded><![CDATA[<p>Oh no!  What on earth could we do?  Wait, I have an idea!</p>
<p>How about we SSH to the server, and then write posts using SQL INSERT statements.  Yah!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
