<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-6487569807197140119.post5482201385467949913..comments</id><updated>2009-01-05T09:29:36.100+01:00</updated><title type='text'>Comments on christian's weblog: One more reason why CSRF sucks hard</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://christ1an.blogspot.com/feeds/5482201385467949913/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6487569807197140119/5482201385467949913/comments/default'/><link rel='alternate' type='text/html' href='http://christ1an.blogspot.com/2007/09/one-more-reason-why-csrf-sucks-hard.html'/><author><name>Christian Matthies</name><uri>http://www.blogger.com/profile/18000193340630874188</uri><email>ch0012@gmail.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6487569807197140119.post-8172027295085428481</id><published>2007-10-04T23:15:00.000+02:00</published><updated>2007-10-04T23:15:00.000+02:00</updated><title type='text'>My audience just says nothing. They just don't car...</title><content type='html'>My audience just says nothing. They just don't care about it.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6487569807197140119/5482201385467949913/comments/default/8172027295085428481'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6487569807197140119/5482201385467949913/comments/default/8172027295085428481'/><link rel='alternate' type='text/html' href='http://christ1an.blogspot.com/2007/09/one-more-reason-why-csrf-sucks-hard.html?showComment=1191532500000#c8172027295085428481' title=''/><author><name>Alex</name><uri>http://www.bitsploit.de</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://christ1an.blogspot.com/2007/09/one-more-reason-why-csrf-sucks-hard.html' ref='tag:blogger.com,1999:blog-6487569807197140119.post-5482201385467949913' source='http://www.blogger.com/feeds/6487569807197140119/posts/default/5482201385467949913' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-6487569807197140119.post-7043149943563012516</id><published>2007-09-27T03:53:00.000+02:00</published><updated>2007-09-27T03:53:00.000+02:00</updated><title type='text'>When I explain CSRF to folks they either say that ...</title><content type='html'>When I explain CSRF to folks they either say that web browsers "shouldn't do that" or they get very scared.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6487569807197140119/5482201385467949913/comments/default/7043149943563012516'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6487569807197140119/5482201385467949913/comments/default/7043149943563012516'/><link rel='alternate' type='text/html' href='http://christ1an.blogspot.com/2007/09/one-more-reason-why-csrf-sucks-hard.html?showComment=1190857980000#c7043149943563012516' title=''/><author><name>Ian McKellar</name><uri>http://www.blogger.com/profile/15959494545366543766</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://christ1an.blogspot.com/2007/09/one-more-reason-why-csrf-sucks-hard.html' ref='tag:blogger.com,1999:blog-6487569807197140119.post-5482201385467949913' source='http://www.blogger.com/feeds/6487569807197140119/posts/default/5482201385467949913' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-6487569807197140119.post-3167250714062461818</id><published>2007-09-26T19:48:00.000+02:00</published><updated>2007-09-26T19:48:00.000+02:00</updated><title type='text'>You go home at night and open your front door usin...</title><content type='html'>You go home at night and open your front door using your jingly-jangly keys. Sadly, when you walked in, you forgot to take the keys out of the lock as you picked up the bag of groceries you had to set down to open the door. Someone walks by, see the keys already in the lock, and uses them to walk on into your house. Or they could just walk away with your keys and knowledge of what door they open.&lt;BR/&gt;&lt;BR/&gt;Is that maybe helpful? :)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6487569807197140119/5482201385467949913/comments/default/3167250714062461818'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6487569807197140119/5482201385467949913/comments/default/3167250714062461818'/><link rel='alternate' type='text/html' href='http://christ1an.blogspot.com/2007/09/one-more-reason-why-csrf-sucks-hard.html?showComment=1190828880000#c3167250714062461818' title=''/><author><name>LonerVamp</name><uri>http://www.blogger.com/profile/15357840241031190415</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://christ1an.blogspot.com/2007/09/one-more-reason-why-csrf-sucks-hard.html' ref='tag:blogger.com,1999:blog-6487569807197140119.post-5482201385467949913' source='http://www.blogger.com/feeds/6487569807197140119/posts/default/5482201385467949913' type='text/html'/></entry></feed>