<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.4" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Google Fixes Contact List Flaw</title>
	<link>http://browserden.co.uk/blog/2007/01/02/google-fixes-contact-list-flaw/</link>
	<description>Browser news, reviews and opinions</description>
	<pubDate>Tue, 06 Jan 2009 08:28:28 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.4</generator>

	<item>
		<title>by: More Gmail Drama at FreshBlogger</title>
		<link>http://browserden.co.uk/blog/2007/01/02/google-fixes-contact-list-flaw/#comment-4515</link>
		<pubDate>Tue, 02 Jan 2007 19:15:56 +0000</pubDate>
		<guid>http://browserden.co.uk/blog/2007/01/02/google-fixes-contact-list-flaw/#comment-4515</guid>
					<description>[...] Some are reporting that Google has already responded with a fix to this issue. It sounds like they&#8217;ve reacted pretty quickly and put in a simple fix that will prevent most of the damage. Others have pointed out that there are still vulnerabilities in GMail that can be exploited by malicious hacks. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Some are reporting that Google has already responded with a fix to this issue. It sounds like they&#8217;ve reacted pretty quickly and put in a simple fix that will prevent most of the damage. Others have pointed out that there are still vulnerabilities in GMail that can be exploited by malicious hacks. [&#8230;]
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Andrew</title>
		<link>http://browserden.co.uk/blog/2007/01/02/google-fixes-contact-list-flaw/#comment-4502</link>
		<pubDate>Tue, 02 Jan 2007 15:15:23 +0000</pubDate>
		<guid>http://browserden.co.uk/blog/2007/01/02/google-fixes-contact-list-flaw/#comment-4502</guid>
					<description>Why hasn't this security flaw received more press coverage? Surf the net while logged in to Google and give your entire contact list to every web site (and its advertisers!) you visit. It's appalling.

How many other web services have this problem? Are Yahoo Mail users vulnerable to a similar attack?

Will Google let anyone know when they have put in place a REAL fix for this problem? I went through their help pages yesterday and submitted a request that they announce when they've fixed the problem. I doubt anyone will ever hear from them. Their arrogance is extraordinary and may ultimately bring them down.</description>
		<content:encoded><![CDATA[<p>Why hasn&#8217;t this security flaw received more press coverage? Surf the net while logged in to Google and give your entire contact list to every web site (and its advertisers!) you visit. It&#8217;s appalling.</p>
<p>How many other web services have this problem? Are Yahoo Mail users vulnerable to a similar attack?</p>
<p>Will Google let anyone know when they have put in place a REAL fix for this problem? I went through their help pages yesterday and submitted a request that they announce when they&#8217;ve fixed the problem. I doubt anyone will ever hear from them. Their arrogance is extraordinary and may ultimately bring them down.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Bob</title>
		<link>http://browserden.co.uk/blog/2007/01/02/google-fixes-contact-list-flaw/#comment-4492</link>
		<pubDate>Tue, 02 Jan 2007 14:24:50 +0000</pubDate>
		<guid>http://browserden.co.uk/blog/2007/01/02/google-fixes-contact-list-flaw/#comment-4492</guid>
					<description>It seems fairly incompetent of Google to only partially fix this. The URL that generates this XML is the same as the one that did generate that JavaScript but with different parameters passed to it. This seems so unlike Google who usually hire some of the best engineering talent.</description>
		<content:encoded><![CDATA[<p>It seems fairly incompetent of Google to only partially fix this. The URL that generates this XML is the same as the one that did generate that JavaScript but with different parameters passed to it. This seems so unlike Google who usually hire some of the best engineering talent.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
