<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: You Can Pry My Gmail Delete Button From My Cold, Dead Fingers</title>
	<atom:link href="http://redmonk.com/sogrady/2005/07/19/you-can-pry-my-gmail-delete-button-from-my-cold-dead-fingers/feed/" rel="self" type="application/rss+xml" />
	<link>http://redmonk.com/sogrady/2005/07/19/you-can-pry-my-gmail-delete-button-from-my-cold-dead-fingers/</link>
	<description>because technology is just another ecosystem</description>
	<pubDate>Sun, 07 Sep 2008 05:56:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: Jeremy Dunck</title>
		<link>http://redmonk.com/sogrady/2005/07/19/you-can-pry-my-gmail-delete-button-from-my-cold-dead-fingers/#comment-907</link>
		<dc:creator>Jeremy Dunck</dc:creator>
		<pubDate>Thu, 21 Jul 2005 16:35:40 +0000</pubDate>
		<guid isPermaLink="false">http://redmonk.com/sogrady/wp/?p=510#comment-907</guid>
		<description>And hey, just to illustrate how touchy this is, 
it turns out that the one I said was ok:
*mail.google.com/*
is -not- OK, because this also matches:
http://evil.com/mail.google.com/mwahaha

So, like giving condoms to kids whilst urging abstinence-- be careful out there!
</description>
		<content:encoded><![CDATA[<p>And hey, just to illustrate how touchy this is,<br />
it turns out that the one I said was ok:<br />
*mail.google.com/*<br />
is -not- OK, because this also matches:<br />
<a href="http://evil.com/mail.google.com/mwahaha" >http://evil.com/mail.google.com/mwahaha</a></p>
<p>So, like giving condoms to kids whilst urging abstinence&#8211; be careful out there!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeremy Dunck</title>
		<link>http://redmonk.com/sogrady/2005/07/19/you-can-pry-my-gmail-delete-button-from-my-cold-dead-fingers/#comment-906</link>
		<dc:creator>Jeremy Dunck</dc:creator>
		<pubDate>Wed, 20 Jul 2005 22:03:53 +0000</pubDate>
		<guid isPermaLink="false">http://redmonk.com/sogrady/wp/?p=510#comment-906</guid>
		<description>If you're going to run an unsafe version, please make sure that your scripts (even non-universal ones) have an @include that you intend.

@include *mail.google.com/* is fine.
@include *mail.google.* isn't, nor is *mail.google.com*.  They'll match mail.google.com.evil.com.  Then all someone has to do is  phish you over to mail.google.com.evil.com, and you're done.

Just an explanatory note of caution, not intended as FUD.</description>
		<content:encoded><![CDATA[<p>If you&#8217;re going to run an unsafe version, please make sure that your scripts (even non-universal ones) have an @include that you intend.</p>
<p>@include *mail.google.com/* is fine.<br />
@include *mail.google.* isn&#8217;t, nor is *mail.google.com*.  They&#8217;ll match mail.google.com.evil.com.  Then all someone has to do is  phish you over to mail.google.com.evil.com, and you&#8217;re done.</p>
<p>Just an explanatory note of caution, not intended as FUD.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
