<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Verisign FAIL &#8211; We are all doomed</title>
	<atom:link href="http://www.sslfail.com/2009/01/verisign-fail-we-are-all-doomed/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sslfail.com/2009/01/verisign-fail-we-are-all-doomed/</link>
	<description>1.2.840.113549.1.1</description>
	<lastBuildDate>Thu, 01 Jul 2010 03:13:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Michael Coates</title>
		<link>http://www.sslfail.com/2009/01/verisign-fail-we-are-all-doomed/comment-page-1/#comment-16</link>
		<dc:creator>Michael Coates</dc:creator>
		<pubDate>Sat, 17 Jan 2009 14:12:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=125#comment-16</guid>
		<description>The reason this is a fail is because the user was presented with an error message at all. Michael J is correct,  the two A records point to the same IP address and its not a big deal.

However, by presenting an error message at all we are training the public users to ignore the error message and continue browsing. If they see any other error messages in the future, they&#039;ll be tempted to ignore those as well (and those ssl error messages could be much worse).

If you are using SSL for a site, then there should never be any SSL error warnings presented to the user. &gt; 0 = fail

-Michael Coates</description>
		<content:encoded><![CDATA[<p>The reason this is a fail is because the user was presented with an error message at all. Michael J is correct,  the two A records point to the same IP address and its not a big deal.</p>
<p>However, by presenting an error message at all we are training the public users to ignore the error message and continue browsing. If they see any other error messages in the future, they&#8217;ll be tempted to ignore those as well (and those ssl error messages could be much worse).</p>
<p>If you are using SSL for a site, then there should never be any SSL error warnings presented to the user. &gt; 0 = fail</p>
<p>-Michael Coates</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Janke</title>
		<link>http://www.sslfail.com/2009/01/verisign-fail-we-are-all-doomed/comment-page-1/#comment-9</link>
		<dc:creator>Michael Janke</dc:creator>
		<pubDate>Wed, 14 Jan 2009 04:20:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=125#comment-9</guid>
		<description>How is this a fail? It&#039;s obviously just a case where two A records point to the same IP address.

No big deal, really.</description>
		<content:encoded><![CDATA[<p>How is this a fail? It&#8217;s obviously just a case where two A records point to the same IP address.</p>
<p>No big deal, really.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
