<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>An Information Security Place &#187; Firefox</title>
	<atom:link href="http://infosecplace.com/blog/category/firefox/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecplace.com/blog</link>
	<description>Commentary on the State of Information Security</description>
	<lastBuildDate>Wed, 23 Jun 2010 11:19:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>A Flaw in NoScript Firefox Plugin!!!</title>
		<link>http://infosecplace.com/blog/2008/08/11/a-flaw-in-noscript-firefox-plugin/</link>
		<comments>http://infosecplace.com/blog/2008/08/11/a-flaw-in-noscript-firefox-plugin/#comments</comments>
		<pubDate>Mon, 11 Aug 2008 19:31:52 +0000</pubDate>
		<dc:creator>Michael Farnum</dc:creator>
				<category><![CDATA[Firefox]]></category>
		<category><![CDATA[NoScript]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/2008/08/11/a-flaw-in-noscript-firefox-plugin/</guid>
		<description><![CDATA[There&#8217;s not really a flaw (that I know of), so sorry for the theatrics.&#160; Just thought that would be a good draw.&#160;  
But really, there is a human problem from which NoScript cannot protect you.&#160; What if you have setup a website as trusted through NoScript, then that site gets compromised?&#160; If there is [...]]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s not really a flaw (that I know of), so sorry for the theatrics.&#160; Just thought that would be a good draw.&#160; <img src='http://infosecplace.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>But really, there is a human problem from which <a href="http://noscript.net/">NoScript</a> cannot protect you.&#160; What if you have setup a website as trusted through NoScript, then that site gets compromised?&#160; If there is malware in the compromised site, it is possible that your trusted relationship will allow that code to run and infect you.&#160; Yes, there are extra protections built into NoScript to protect against even trusted sites (see screenshots below), but this is still a problem if you have a site in the whitelist and it gets compromised.</p>
<p>This seems obvious now that I see it, but I never thought about it until <a href="http://www.mckeay.net/2008/08/11/ssaaty-site-compromised-sunday/">Alan&#8217;s blog got compromised.</a>&#160; My advice would be to whitelist as little as possible and to use the temporary allow feature for everything that doesn&#8217;t cause you severe headaches.</p>
<p><strong>NoScript Advance options:</strong></p>
<p><a href="http://infosecplace.com/blog/wp-content/uploads/2008/08/image.png"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="286" alt="image" src="http://infosecplace.com/blog/wp-content/uploads/2008/08/image-thumb.png" width="328" border="0" /></a> </p>
<p><a href="http://infosecplace.com/blog/wp-content/uploads/2008/08/image1.png"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="281" alt="image" src="http://infosecplace.com/blog/wp-content/uploads/2008/08/image-thumb1.png" width="320" border="0" /></a> </p>
<p><a href="http://infosecplace.com/blog/wp-content/uploads/2008/08/image2.png"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="280" alt="image" src="http://infosecplace.com/blog/wp-content/uploads/2008/08/image-thumb2.png" width="323" border="0" /></a> </p>
<p>Vet</p>
]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2008/08/11/a-flaw-in-noscript-firefox-plugin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>trying out Safari for Windows</title>
		<link>http://infosecplace.com/blog/2008/03/31/trying-out-safari-for-windows/</link>
		<comments>http://infosecplace.com/blog/2008/03/31/trying-out-safari-for-windows/#comments</comments>
		<pubDate>Mon, 31 Mar 2008 20:42:30 +0000</pubDate>
		<dc:creator>Michael Farnum</dc:creator>
				<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Safari]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/2008/03/31/trying-out-safari-for-windows/</guid>
		<description><![CDATA[I have heard some good things about Safari for Windows, so I am going to try it out.&#160; And since they are pushing it with the new version of iTunes (not quite as heavy handed as the push out to Mac users &#8211; I had a choice to decline it), I figured what the heck.
The [...]]]></description>
			<content:encoded><![CDATA[<p>I have heard some good things about Safari for Windows, so I am going to try it out.&#160; And since they are pushing it with the new version of iTunes (not quite as heavy handed as the push out to Mac users &#8211; I had a choice to decline it), I figured what the heck.</p>
<p>The first load was pretty slow, but that is to be expected the first time it comes up on a new system.&#160; It loaded much quicker the second time around.&#160; I&#8217;ll play around and let you know what I think later on.</p>
<p>Update.&#160; I said later, but here are a couple of thoughts / impressions right now:</p>
<ul>
<li>The load status of webpages is in the address bar, which is different for me (maybe that is standard for Mac users).&#160; </li>
<li>Intense Debate (the new blog comment system that I am beta testing) seems to work fine with it.&#160; Intense Debate also works great with Firefox on my system, but IE seems to choke on it quite a bit. </li>
<li>The fonts seem to be a tad hazy.&#160; Not as crisp maybe </li>
<li>iGoogle looks pretty good on it </li>
<li>The redlines under suspected misspelled words is much more noticeable </li>
<li>I still like IE7&#8217;s new tab feature rather than needing to hit CTRL-T </li>
<li>I don&#8217;t like that there is not a history arrow in the address field.&#160; Instead you have to click the history menu.&#160; Maybe that is just because I am used to it, but I like that feature on IE and Firefox </li>
</ul>
<p>Maybe some more later.</p>
<p>OK, more:&#160; Where is the area that gives you a preview of the link you are about to click on?&#160; I can&#8217;t see where I am going!!&#160; Oops&#8230; OK, found it.&#160; You have to choose View &gt; Show Status Bar.&#160; This is becoming more like a twit post than a blog post. <img src='http://infosecplace.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Vet</p>
]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2008/03/31/trying-out-safari-for-windows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
