<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Automated detection of CSRF</title>
	<atom:link href="http://www.greebo.net/2007/05/09/automated-detection-of-csrf/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.greebo.net/2007/05/09/automated-detection-of-csrf/</link>
	<description>mostly useless crap from me</description>
	<lastBuildDate>Mon, 23 Jan 2012 12:46:05 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: Martijn Loth</title>
		<link>http://www.greebo.net/2007/05/09/automated-detection-of-csrf/comment-page-1/#comment-8785</link>
		<dc:creator>Martijn Loth</dc:creator>
		<pubDate>Mon, 14 May 2007 20:03:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.greebo.net/?p=413#comment-8785</guid>
		<description>Interesting blog-topics here, Andrew!  

I&#039;m going to have to go with the &quot;mass-positive&quot; over the &quot;mass-negative&quot;; successful CSRF attacks are difficult enough to detect program-wise, informing the masses of these possibilities should be our front line of defense.

The way I see it: we&#039;ve stood at this crossroad before.
At a certain point in history the security-scene stood before the same decision regarding things like sql-injections: &quot;should we risk exposing our vulnerable sides to people who could possibly have malicious intentions?&quot;.
While such knowledge is still not as widespread as I had hoped, we are finally bringing the topic of security to the lovable, but ignorant public. We should not stop now.

[optimism]Besides, the more people know about these vectors, the more people will be able to pitch in useful ideas.[/optimism]</description>
		<content:encoded><![CDATA[<p>Interesting blog-topics here, Andrew!  </p>
<p>I&#8217;m going to have to go with the &#8220;mass-positive&#8221; over the &#8220;mass-negative&#8221;; successful CSRF attacks are difficult enough to detect program-wise, informing the masses of these possibilities should be our front line of defense.</p>
<p>The way I see it: we&#8217;ve stood at this crossroad before.<br />
At a certain point in history the security-scene stood before the same decision regarding things like sql-injections: &#8220;should we risk exposing our vulnerable sides to people who could possibly have malicious intentions?&#8221;.<br />
While such knowledge is still not as widespread as I had hoped, we are finally bringing the topic of security to the lovable, but ignorant public. We should not stop now.</p>
<p>[optimism]Besides, the more people know about these vectors, the more people will be able to pitch in useful ideas.[/optimism]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

