<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Talking to co-workers about browser security</title>
	<atom:link href="http://www.psychocats.net/ubuntucat/talking-to-co-workers-about-browser-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.psychocats.net/ubuntucat/talking-to-co-workers-about-browser-security/</link>
	<description>Random musings from the radical feminist Christian antiracist left - some having to do with Ubuntu</description>
	<lastBuildDate>Sat, 11 Feb 2012 06:53:56 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Rillip</title>
		<link>http://www.psychocats.net/ubuntucat/talking-to-co-workers-about-browser-security/comment-page-1/#comment-334</link>
		<dc:creator>Rillip</dc:creator>
		<pubDate>Mon, 23 Jul 2007 08:37:50 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntucat.wordpress.com/2007/07/11/talking-to-co-workers-about-browser-security/#comment-334</guid>
		<description>I use Opera myself, but I&#039;m not worried about security overmuch, to be honest.  I don&#039;t htink I&#039;ve ever seen a security/bugfix for Opera.  It hasa  more regular release cycle than IE, but not as updated as FF I think.

Personally I feel I.E. is less safe.  Even patched, in Windows XP and before, it is too integrated into the system; an I.E. exploied == OS Exploit.</description>
		<content:encoded><![CDATA[<p>I use Opera myself, but I&#8217;m not worried about security overmuch, to be honest.  I don&#8217;t htink I&#8217;ve ever seen a security/bugfix for Opera.  It hasa  more regular release cycle than IE, but not as updated as FF I think.</p>
<p>Personally I feel I.E. is less safe.  Even patched, in Windows XP and before, it is too integrated into the system; an I.E. exploied == OS Exploit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ubuntucat</title>
		<link>http://www.psychocats.net/ubuntucat/talking-to-co-workers-about-browser-security/comment-page-1/#comment-343</link>
		<dc:creator>ubuntucat</dc:creator>
		<pubDate>Wed, 18 Jul 2007 17:22:00 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntucat.wordpress.com/2007/07/11/talking-to-co-workers-about-browser-security/#comment-343</guid>
		<description>Just as an update, it&#039;s a week later, and Firefox has finally been patched for this flaw:

Fixed in Firefox 2.0.0.5
MFSA 2007-25 XPCNativeWrapper pollution
MFSA 2007-24 Unauthorized access to wyciwyg:// documents
MFSA 2007-23 Remote code execution by launching Firefox from Internet Explorer
MFSA 2007-22 File type confusion due to %00 in name
MFSA 2007-21 Privilege escalation using an event handler attached to an element not in the document
MFSA 2007-20 Frame spoofing while window is loading
MFSA 2007-19 XSS using addEventListener and setTimeout
MFSA 2007-18 Crashes with evidence of memory corruption

Not sure how long the Internet Explorer patch will take, though.</description>
		<content:encoded><![CDATA[<p>Just as an update, it&#8217;s a week later, and Firefox has finally been patched for this flaw:</p>
<p>Fixed in Firefox 2.0.0.5<br />
MFSA 2007-25 XPCNativeWrapper pollution<br />
MFSA 2007-24 Unauthorized access to wyciwyg:// documents<br />
MFSA 2007-23 Remote code execution by launching Firefox from Internet Explorer<br />
MFSA 2007-22 File type confusion due to %00 in name<br />
MFSA 2007-21 Privilege escalation using an event handler attached to an element not in the document<br />
MFSA 2007-20 Frame spoofing while window is loading<br />
MFSA 2007-19 XSS using addEventListener and setTimeout<br />
MFSA 2007-18 Crashes with evidence of memory corruption</p>
<p>Not sure how long the Internet Explorer patch will take, though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frak</title>
		<link>http://www.psychocats.net/ubuntucat/talking-to-co-workers-about-browser-security/comment-page-1/#comment-342</link>
		<dc:creator>Frak</dc:creator>
		<pubDate>Mon, 16 Jul 2007 23:35:17 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntucat.wordpress.com/2007/07/11/talking-to-co-workers-about-browser-security/#comment-342</guid>
		<description>Patched or no, switch to linux, such as Ubuntu, because the Linux kernel restricts remote code execution. Windows doesn&#039;t care as long as it ends with a .cab or .exe.</description>
		<content:encoded><![CDATA[<p>Patched or no, switch to linux, such as Ubuntu, because the Linux kernel restricts remote code execution. Windows doesn&#8217;t care as long as it ends with a .cab or .exe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Edmund</title>
		<link>http://www.psychocats.net/ubuntucat/talking-to-co-workers-about-browser-security/comment-page-1/#comment-336</link>
		<dc:creator>Edmund</dc:creator>
		<pubDate>Thu, 12 Jul 2007 18:55:28 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntucat.wordpress.com/2007/07/11/talking-to-co-workers-about-browser-security/#comment-336</guid>
		<description>Patched or no, there is no accounting for stupidity. Firefox is inherently more secure, inherently more well-made than IE. Given a dumb user, FF makes for a better choice.</description>
		<content:encoded><![CDATA[<p>Patched or no, there is no accounting for stupidity. Firefox is inherently more secure, inherently more well-made than IE. Given a dumb user, FF makes for a better choice.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alejandro</title>
		<link>http://www.psychocats.net/ubuntucat/talking-to-co-workers-about-browser-security/comment-page-1/#comment-335</link>
		<dc:creator>Alejandro</dc:creator>
		<pubDate>Wed, 11 Jul 2007 21:41:15 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntucat.wordpress.com/2007/07/11/talking-to-co-workers-about-browser-security/#comment-335</guid>
		<description>It&#039;s not just the browser. It&#039;s the spirit. I find it rude and technically sloppy for a site to require a browser. Thus, I&#039;ll penalize them by depriving them of my traffic. They&#039;ll probably get an email from me, too.</description>
		<content:encoded><![CDATA[<p>It&#8217;s not just the browser. It&#8217;s the spirit. I find it rude and technically sloppy for a site to require a browser. Thus, I&#8217;ll penalize them by depriving them of my traffic. They&#8217;ll probably get an email from me, too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ubuntucat</title>
		<link>http://www.psychocats.net/ubuntucat/talking-to-co-workers-about-browser-security/comment-page-1/#comment-339</link>
		<dc:creator>ubuntucat</dc:creator>
		<pubDate>Wed, 11 Jul 2007 20:20:20 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntucat.wordpress.com/2007/07/11/talking-to-co-workers-about-browser-security/#comment-339</guid>
		<description>Certainly I&#039;d recommend Firefox if someone asked for a browser recommendation, but I think if you run IE7 with a fully patched Windows and a fully patched IE, it shouldn&#039;t be too terrible.</description>
		<content:encoded><![CDATA[<p>Certainly I&#8217;d recommend Firefox if someone asked for a browser recommendation, but I think if you run IE7 with a fully patched Windows and a fully patched IE, it shouldn&#8217;t be too terrible.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alejandro</title>
		<link>http://www.psychocats.net/ubuntucat/talking-to-co-workers-about-browser-security/comment-page-1/#comment-338</link>
		<dc:creator>Alejandro</dc:creator>
		<pubDate>Wed, 11 Jul 2007 19:58:18 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntucat.wordpress.com/2007/07/11/talking-to-co-workers-about-browser-security/#comment-338</guid>
		<description>Edmundo: If it were up to me, I&#039;d visit another site before using IE...</description>
		<content:encoded><![CDATA[<p>Edmundo: If it were up to me, I&#8217;d visit another site before using IE&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alejandro</title>
		<link>http://www.psychocats.net/ubuntucat/talking-to-co-workers-about-browser-security/comment-page-1/#comment-337</link>
		<dc:creator>Alejandro</dc:creator>
		<pubDate>Wed, 11 Jul 2007 19:48:23 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntucat.wordpress.com/2007/07/11/talking-to-co-workers-about-browser-security/#comment-337</guid>
		<description>Firefox is the more secure browser of the two, by far. However, its security might have been oversold: Firefox (like Linux) acquired a reputation for being invulnerable, and no software is invulnerable. That&#039;s probably part of the reason why Firefox bugs make the headlines more often.

Again, part of the reason.</description>
		<content:encoded><![CDATA[<p>Firefox is the more secure browser of the two, by far. However, its security might have been oversold: Firefox (like Linux) acquired a reputation for being invulnerable, and no software is invulnerable. That&#8217;s probably part of the reason why Firefox bugs make the headlines more often.</p>
<p>Again, part of the reason.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Edmundo</title>
		<link>http://www.psychocats.net/ubuntucat/talking-to-co-workers-about-browser-security/comment-page-1/#comment-340</link>
		<dc:creator>Edmundo</dc:creator>
		<pubDate>Wed, 11 Jul 2007 19:48:19 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntucat.wordpress.com/2007/07/11/talking-to-co-workers-about-browser-security/#comment-340</guid>
		<description>Don&#039;t use IE! There are many, many more security &quot;flaws&quot; and vulnerabilities in IE than Firefox, and it is a security risk to use IE (regardless of platform). Unless a site absolutely, positively require it (like your mother&#039;s MLS issue), never ever use IE. Ever.</description>
		<content:encoded><![CDATA[<p>Don&#8217;t use IE! There are many, many more security &#8220;flaws&#8221; and vulnerabilities in IE than Firefox, and it is a security risk to use IE (regardless of platform). Unless a site absolutely, positively require it (like your mother&#8217;s MLS issue), never ever use IE. Ever.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anurag Panda</title>
		<link>http://www.psychocats.net/ubuntucat/talking-to-co-workers-about-browser-security/comment-page-1/#comment-341</link>
		<dc:creator>Anurag Panda</dc:creator>
		<pubDate>Wed, 11 Jul 2007 17:09:17 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntucat.wordpress.com/2007/07/11/talking-to-co-workers-about-browser-security/#comment-341</guid>
		<description>Are not most Firefox as well as Opera vulnerabilities related to the Windows platform? I am not bashing Windows in this way but this is fact.</description>
		<content:encoded><![CDATA[<p>Are not most Firefox as well as Opera vulnerabilities related to the Windows platform? I am not bashing Windows in this way but this is fact.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

