<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: New Security Update</title>
	<atom:link href="http://twitbin.com/blog/new-security-update/feed/" rel="self" type="application/rss+xml" />
	<link>http://twitbin.com/blog/new-security-update/</link>
	<description>News and developments from twitbin.com</description>
	<pubDate>Sat, 06 Sep 2008 01:29:20 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
		<item>
		<title>By: Dan</title>
		<link>http://twitbin.com/blog/new-security-update/#comment-211</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Fri, 26 Oct 2007 21:37:52 +0000</pubDate>
		<guid isPermaLink="false">http://twitbin.com/blog/new-security-update/#comment-211</guid>
		<description>Brian - Thanks for the quick fix and the great tool that is twitbin. Note, however, that the security issue with plaintext passwords in cookies extends to sending those plaintext passwords in HTTP requests, too -- compromise of the user's computer is not the only concern. So if those usernames and passwords are being decrypted and then sent via HTTP and not HTTPS, credentials are still going over the wire (or air) in plaintext.</description>
		<content:encoded><![CDATA[<p>Brian - Thanks for the quick fix and the great tool that is twitbin. Note, however, that the security issue with plaintext passwords in cookies extends to sending those plaintext passwords in HTTP requests, too &#8212; compromise of the user&#8217;s computer is not the only concern. So if those usernames and passwords are being decrypted and then sent via HTTP and not HTTPS, credentials are still going over the wire (or air) in plaintext.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://twitbin.com/blog/new-security-update/#comment-210</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Wed, 24 Oct 2007 19:51:17 +0000</pubDate>
		<guid isPermaLink="false">http://twitbin.com/blog/new-security-update/#comment-210</guid>
		<description>Thanks for making Twitbin and thanks for the security update.</description>
		<content:encoded><![CDATA[<p>Thanks for making Twitbin and thanks for the security update.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
