<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ★ SuperGenPass is not that secure</title>
	<atom:link href="http://akibjorklund.com/2009/supergenpass-is-not-that-secure/feed" rel="self" type="application/rss+xml" />
	<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure</link>
	<description>web generalist</description>
	<lastBuildDate>Tue, 21 Jun 2011 07:03:10 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: lankycoder &#187; Blog Archive &#187; A Fruitless Search for a Password Bookmarklet</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-20943</link>
		<dc:creator>lankycoder &#187; Blog Archive &#187; A Fruitless Search for a Password Bookmarklet</dc:creator>
		<pubDate>Wed, 15 Jun 2011 07:41:07 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-20943</guid>
		<description>[...] alas, SuperGenPass (and any other simple bookmarklet) is not secure in the face of a malicious website that contains JavaScript designed to sniff entry of the master [...]</description>
		<content:encoded><![CDATA[<p>[...] alas, SuperGenPass (and any other simple bookmarklet) is not secure in the face of a malicious website that contains JavaScript designed to sniff entry of the master [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-20650</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Mon, 31 Jan 2011 20:25:20 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-20650</guid>
		<description>Just a note to say that the use of a JavaScript filter like &lt;a href=&quot;http://noscript.net/&quot; rel=&quot;nofollow&quot;&gt;NoScript&lt;/a&gt; will prevent this kind of attack on untrusted websites. SuperGenPass, as a bookmarklet, is implicitly trusted while the malicious code is blocked. However, this protection is limited since tyour determination of which sites are &quot;trusted&quot; might be flawed.</description>
		<content:encoded><![CDATA[<p>Just a note to say that the use of a JavaScript filter like <a href="http://noscript.net/">NoScript</a> will prevent this kind of attack on untrusted websites. SuperGenPass, as a bookmarklet, is implicitly trusted while the malicious code is blocked. However, this protection is limited since tyour determination of which sites are &#8220;trusted&#8221; might be flawed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karolis Pocius &#187; Slaptažodžių valdymas: SuperGenPass vs LastPass</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-20315</link>
		<dc:creator>Karolis Pocius &#187; Slaptažodžių valdymas: SuperGenPass vs LastPass</dc:creator>
		<pubDate>Tue, 11 Jan 2011 15:31:40 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-20315</guid>
		<description>[...] anksčiau skaitytą straipsnį apie galimą SGP saugumo spragą, tačiau ta saugumo spraga manęs neįtikino, juolab, kad jos galima nesunkiai išvengti naudojant [...]</description>
		<content:encoded><![CDATA[<p>[...] anksčiau skaitytą straipsnį apie galimą SGP saugumo spragą, tačiau ta saugumo spraga manęs neįtikino, juolab, kad jos galima nesunkiai išvengti naudojant [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Using a shell version of supergenpass from vimperator/pentadactyl &#171; ChMD</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-19990</link>
		<dc:creator>Using a shell version of supergenpass from vimperator/pentadactyl &#171; ChMD</dc:creator>
		<pubDate>Mon, 20 Dec 2010 17:37:55 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-19990</guid>
		<description>[...] supergenpass is not that secure. Any script executed in the page you are executing supergenpass into is able to see your master [...]</description>
		<content:encoded><![CDATA[<p>[...] supergenpass is not that secure. Any script executed in the page you are executing supergenpass into is able to see your master [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: geeknik</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-18591</link>
		<dc:creator>geeknik</dc:creator>
		<pubDate>Tue, 21 Sep 2010 04:15:21 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-18591</guid>
		<description>Your demo doesn&#039;t work with the latest version of SuperGenPass and Firefox 4.0b7pre.</description>
		<content:encoded><![CDATA[<p>Your demo doesn&#8217;t work with the latest version of SuperGenPass and Firefox 4.0b7pre.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Anderson</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-18477</link>
		<dc:creator>Tim Anderson</dc:creator>
		<pubDate>Tue, 14 Sep 2010 06:07:11 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-18477</guid>
		<description>steve lewis: in order to open the page in an iframe, some DOM manipulation procedures need to be called. These procedures can be overwritten to steal your password by changing the &#039;local&#039; page to one on a remote server. Even if it did work, the portion of the iframe isolated from the evil stuff on the page would be isolated from SGP.</description>
		<content:encoded><![CDATA[<p>steve lewis: in order to open the page in an iframe, some DOM manipulation procedures need to be called. These procedures can be overwritten to steal your password by changing the &#8216;local&#8217; page to one on a remote server. Even if it did work, the portion of the iframe isolated from the evil stuff on the page would be isolated from SGP.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve lewis</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-18462</link>
		<dc:creator>steve lewis</dc:creator>
		<pubDate>Mon, 13 Sep 2010 17:08:41 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-18462</guid>
		<description>If SGP was changed to open a HTML file in an Iframe saved on the computer containing the application, that portion of the DOM might be isolated from the suspect page. The bookmarklet could possibly pass the domain as a parameter to the HTML file. Would this work as sort of a &quot;secure&quot; version of SGP?</description>
		<content:encoded><![CDATA[<p>If SGP was changed to open a HTML file in an Iframe saved on the computer containing the application, that portion of the DOM might be isolated from the suspect page. The bookmarklet could possibly pass the domain as a parameter to the HTML file. Would this work as sort of a &#8220;secure&#8221; version of SGP?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aki Björklund</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-18403</link>
		<dc:creator>Aki Björklund</dc:creator>
		<pubDate>Thu, 09 Sep 2010 04:39:43 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-18403</guid>
		<description>Yes, it will.</description>
		<content:encoded><![CDATA[<p>Yes, it will.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: c</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-18402</link>
		<dc:creator>c</dc:creator>
		<pubDate>Wed, 08 Sep 2010 22:44:23 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-18402</guid>
		<description>If I use the applet in a blank tab and then paste in the password, will  it be secure?</description>
		<content:encoded><![CDATA[<p>If I use the applet in a blank tab and then paste in the password, will  it be secure?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Anderson</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-17236</link>
		<dc:creator>Tim Anderson</dc:creator>
		<pubDate>Wed, 14 Apr 2010 10:16:18 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-17236</guid>
		<description>@Andres Riofrio That doesn&#039;t work in firefox 3.5.6</description>
		<content:encoded><![CDATA[<p>@Andres Riofrio That doesn&#8217;t work in firefox 3.5.6</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Served from: akibjorklund.com @ 2012-05-30 09:37:26 -->
