<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for plip blog</title>
	<atom:link href="http://plip.com/blog/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://plip.com/blog</link>
	<description>A blog on plip!</description>
	<lastBuildDate>Thu, 02 Sep 2010 17:21:16 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>Comment on Lifehacker on Passwords by mrjones</title>
		<link>http://plip.com/blog/lifehacker-on-passwords/comment-page-1/#comment-1574</link>
		<dc:creator>mrjones</dc:creator>
		<pubDate>Thu, 02 Sep 2010 17:21:16 +0000</pubDate>
		<guid isPermaLink="false">http://plip.com/blog/?p=676#comment-1574</guid>
		<description>Wangston - Excellent point!  My hackles may have been prematurely raised when I read the article.  Indeed, the &lt;a href=&quot;http://en.wikipedia.org/wiki/Cross-site_scripting&quot; rel=&quot;nofollow&quot;&gt;XSS scenario&lt;/a&gt; you describe is exactly how the &lt;a href=&quot;https://blogs.apache.org/infra/entry/apache_org_04_09_2010&quot; rel=&quot;nofollow&quot;&gt;Jira/Apache hack&lt;/a&gt; was executed.  However, I still feel there&#039;s a level of sophistication for a good XSS hack that&#039;s different then a &lt;a href=&quot;http://en.wikipedia.org/wiki/Script_kiddie&quot; rel=&quot;nofollow&quot;&gt;script kiddie&lt;/a&gt; brute force.</description>
		<content:encoded><![CDATA[<p>Wangston &#8211; Excellent point!  My hackles may have been prematurely raised when I read the article.  Indeed, the <a href="http://en.wikipedia.org/wiki/Cross-site_scripting" rel="nofollow">XSS scenario</a> you describe is exactly how the <a href="https://blogs.apache.org/infra/entry/apache_org_04_09_2010" rel="nofollow">Jira/Apache hack</a> was executed.  However, I still feel there&#039;s a level of sophistication for a good XSS hack that&#039;s different then a <a href="http://en.wikipedia.org/wiki/Script_kiddie" rel="nofollow">script kiddie</a> brute force.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Lifehacker on Passwords by wangston</title>
		<link>http://plip.com/blog/lifehacker-on-passwords/comment-page-1/#comment-1571</link>
		<dc:creator>wangston</dc:creator>
		<pubDate>Thu, 02 Sep 2010 16:16:28 +0000</pubDate>
		<guid isPermaLink="false">http://plip.com/blog/?p=676#comment-1571</guid>
		<description>you don&#039;t need local access to steal cookies. many/most XSS attacks allow the attacker to steal cookies remotely. there are also a lot of MITM attacks you can use to steal cookies (if i control your DNS, then you send me your cookies!)</description>
		<content:encoded><![CDATA[<p>you don&#039;t need local access to steal cookies. many/most XSS attacks allow the attacker to steal cookies remotely. there are also a lot of MITM attacks you can use to steal cookies (if i control your DNS, then you send me your cookies!)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Thermodynamics (video) by Hans</title>
		<link>http://plip.com/blog/thermodynamics-video/comment-page-1/#comment-1525</link>
		<dc:creator>Hans</dc:creator>
		<pubDate>Thu, 19 Aug 2010 02:07:59 +0000</pubDate>
		<guid isPermaLink="false">http://plip.com/blog/?p=657#comment-1525</guid>
		<description>But it is very smooth...  The thermodynamic substance that is :&#039;)</description>
		<content:encoded><![CDATA[<p>But it is very smooth&#8230;  The thermodynamic substance that is :&#039;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Baby Spider Pictures by Hairy Dog</title>
		<link>http://plip.com/blog/baby-spider-pictures/comment-page-1/#comment-1259</link>
		<dc:creator>Hairy Dog</dc:creator>
		<pubDate>Wed, 30 Jun 2010 17:03:39 +0000</pubDate>
		<guid isPermaLink="false">http://plip.com/blog/?p=627#comment-1259</guid>
		<description>Very nice.  Lucky to find both the mother and the babies.

The dog water bowl for a fill light is &#039;brilliant&#039; :)</description>
		<content:encoded><![CDATA[<p>Very nice.  Lucky to find both the mother and the babies.</p>
<p>The dog water bowl for a fill light is &#039;brilliant&#039; :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Simpson&#039;s For Ever by mr jones</title>
		<link>http://plip.com/blog/simpsons-for-ever/comment-page-1/#comment-187</link>
		<dc:creator>mr jones</dc:creator>
		<pubDate>Wed, 03 Mar 2010 22:28:19 +0000</pubDate>
		<guid isPermaLink="false">http://testplip.com/blog/?p=35#comment-187</guid>
		<description>cool!</description>
		<content:encoded><![CDATA[<p>cool!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Simpson&#039;s For Ever by mrjones</title>
		<link>http://plip.com/blog/simpsons-for-ever/comment-page-1/#comment-185</link>
		<dc:creator>mrjones</dc:creator>
		<pubDate>Wed, 03 Mar 2010 22:27:18 +0000</pubDate>
		<guid isPermaLink="false">http://testplip.com/blog/?p=35#comment-185</guid>
		<description>works!</description>
		<content:encoded><![CDATA[<p>works!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Simpson&#039;s For Ever by mr jones</title>
		<link>http://plip.com/blog/simpsons-for-ever/comment-page-1/#comment-184</link>
		<dc:creator>mr jones</dc:creator>
		<pubDate>Wed, 03 Mar 2010 22:26:35 +0000</pubDate>
		<guid isPermaLink="false">http://testplip.com/blog/?p=35#comment-184</guid>
		<description>testing comments</description>
		<content:encoded><![CDATA[<p>testing comments</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Keep those passwords safe by mrjones</title>
		<link>http://plip.com/blog/keep-those-passwords-safe/comment-page-1/#comment-183</link>
		<dc:creator>mrjones</dc:creator>
		<pubDate>Wed, 03 Mar 2010 22:16:47 +0000</pubDate>
		<guid isPermaLink="false">http://plip.com/blog/?p=406#comment-183</guid>
		<description>Mike - Thanks for the comment! DropBox is a known quantity, not specifically a weak link.  Let&#039;s assume they&#039;re a so-so company and their  security is only so -so (I think they&#039;re great though!).  This &quot;so-so&quot; security is totally OK because KeePass implements &lt;a href=&quot;http://keepass.info/help/base/security.html&quot; rel=&quot;nofollow&quot;&gt;real encryption&lt;/a&gt; way above and beyond what DropBox will ever provide.  For us, DropBox is less  secure storage and more a rich man&#039;s &lt;a href=&quot;http://en.wikipedia.org/wiki/Rsync&quot; rel=&quot;nofollow&quot;&gt;rsync&lt;/a&gt; between our work computer, home computer and smartphone. It even has a web interface so we can use it on a friends computer with out installing anything.  A very rich man&#039;s rsync, indeed!</description>
		<content:encoded><![CDATA[<p>Mike &#8211; Thanks for the comment! DropBox is a known quantity, not specifically a weak link.  Let&#039;s assume they&#039;re a so-so company and their  security is only so -so (I think they&#039;re great though!).  This &#034;so-so&#034; security is totally OK because KeePass implements <a href="http://keepass.info/help/base/security.html" rel="nofollow">real encryption</a> way above and beyond what DropBox will ever provide.  For us, DropBox is less  secure storage and more a rich man&#039;s <a href="http://en.wikipedia.org/wiki/Rsync" rel="nofollow">rsync</a> between our work computer, home computer and smartphone. It even has a web interface so we can use it on a friends computer with out installing anything.  A very rich man&#039;s rsync, indeed!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Keep those passwords safe by Mike Smith</title>
		<link>http://plip.com/blog/keep-those-passwords-safe/comment-page-1/#comment-182</link>
		<dc:creator>Mike Smith</dc:creator>
		<pubDate>Wed, 03 Mar 2010 15:50:13 +0000</pubDate>
		<guid isPermaLink="false">http://plip.com/blog/?p=406#comment-182</guid>
		<description>Is dropbox the weak link here? Drop box does not seem very secure to me. What would stop someone from hacking dropbox and then they have your password file?</description>
		<content:encoded><![CDATA[<p>Is dropbox the weak link here? Drop box does not seem very secure to me. What would stop someone from hacking dropbox and then they have your password file?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Another Very Poor Man&#039;s Google Analytics Post by mrjones</title>
		<link>http://plip.com/blog/another-very-poor-mans-google-analytics-post/comment-page-1/#comment-102</link>
		<dc:creator>mrjones</dc:creator>
		<pubDate>Mon, 01 Mar 2010 06:27:03 +0000</pubDate>
		<guid isPermaLink="false">http://plip.com/blog/?p=476#comment-102</guid>
		<description>Hah - no, the blog has only been up for...um...9 months?  No!  Goodness!  It&#039;s been a year almost to the day!  I imported all the old &quot;posts&quot; from the news system I wrote into wordpress.  My &lt;a href=&quot;http://plip.com/blog/new-news-old-open-source/&quot; rel=&quot;nofollow&quot;&gt;first post was Feb 24th, 2009&lt;/a&gt;.  How apropos that on the 27th I wrote about the top posts which likely span the last year.  Hah!</description>
		<content:encoded><![CDATA[<p>Hah &#8211; no, the blog has only been up for&#8230;um&#8230;9 months?  No!  Goodness!  It&#039;s been a year almost to the day!  I imported all the old &#034;posts&#034; from the news system I wrote into wordpress.  My <a href="http://plip.com/blog/new-news-old-open-source/" rel="nofollow">first post was Feb 24th, 2009</a>.  How apropos that on the 27th I wrote about the top posts which likely span the last year.  Hah!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
