<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: mitigating attacks with content security policy</title>
	<atom:link href="http://hacks.mozilla.org/2009/10/content-security-policy/feed/" rel="self" type="application/rss+xml" />
	<link>http://hacks.mozilla.org/2009/10/content-security-policy/</link>
	<description>hacks.mozilla.org</description>
	<lastBuildDate>Fri, 10 Feb 2012 00:05:32 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: 谋智社区 &#187; Blog Archives &#187; 火狐五周岁──记录互联网变化的五年</title>
		<link>http://hacks.mozilla.org/2009/10/content-security-policy/comment-page-1/#comment-35562</link>
		<dc:creator>谋智社区 &#187; Blog Archives &#187; 火狐五周岁──记录互联网变化的五年</dc:creator>
		<pubDate>Mon, 09 Nov 2009 11:32:07 +0000</pubDate>
		<guid isPermaLink="false">http://hacks.mozilla.org/?p=1796#comment-35562</guid>
		<description>[...] 在过去五年中很明显改变的一件事情是在众多现代浏览器──Firefox、Safari、Opera和Chrome──同世界最流行浏览器──IE之间各个方面产生的巨大差异。现代浏览器是为了未来那些互联网应用构建──超级快速的JavaScript，现代CSS，HTML5，支持多样的互联网应用标准，支持可下载字体，支持离线应用，通过canvas 和 WebGL支持原生图像处理，原生视频支持，高级XHR支持兼具高级安全工具和网络能力。 [...]</description>
		<content:encoded><![CDATA[<p>[...] 在过去五年中很明显改变的一件事情是在众多现代浏览器──Firefox、Safari、Opera和Chrome──同世界最流行浏览器──IE之间各个方面产生的巨大差异。现代浏览器是为了未来那些互联网应用构建──超级快速的JavaScript，现代CSS，HTML5，支持多样的互联网应用标准，支持可下载字体，支持离线应用，通过canvas 和 WebGL支持原生图像处理，原生视频支持，高级XHR支持兼具高级安全工具和网络能力。 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 5 years of Firefox at hacks.mozilla.org</title>
		<link>http://hacks.mozilla.org/2009/10/content-security-policy/comment-page-1/#comment-35490</link>
		<dc:creator>5 years of Firefox at hacks.mozilla.org</dc:creator>
		<pubDate>Mon, 09 Nov 2009 04:51:12 +0000</pubDate>
		<guid isPermaLink="false">http://hacks.mozilla.org/?p=1796#comment-35490</guid>
		<description>[...] raw graphics through canvas and WebGL, native video, advanced XHR capabilities  mixed with new security tools and network [...]</description>
		<content:encoded><![CDATA[<p>[...] raw graphics through canvas and WebGL, native video, advanced XHR capabilities  mixed with new security tools and network [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rayj</title>
		<link>http://hacks.mozilla.org/2009/10/content-security-policy/comment-page-1/#comment-28006</link>
		<dc:creator>Rayj</dc:creator>
		<pubDate>Thu, 08 Oct 2009 23:40:05 +0000</pubDate>
		<guid isPermaLink="false">http://hacks.mozilla.org/?p=1796#comment-28006</guid>
		<description>I just dont fucking understand why I block this damn pop up from mozilla and it still keeps coming up with crap i will never buy. i would apprecitate it if you guys drop this crap !!!!!!!!!!i am so pissed off about these damn pop up for shit that no one wants just to make you guys more money.</description>
		<content:encoded><![CDATA[<p>I just dont fucking understand why I block this damn pop up from mozilla and it still keeps coming up with crap i will never buy. i would apprecitate it if you guys drop this crap !!!!!!!!!!i am so pissed off about these damn pop up for shit that no one wants just to make you guys more money.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jaredzusmc</title>
		<link>http://hacks.mozilla.org/2009/10/content-security-policy/comment-page-1/#comment-26437</link>
		<dc:creator>jaredzusmc</dc:creator>
		<pubDate>Tue, 06 Oct 2009 21:53:07 +0000</pubDate>
		<guid isPermaLink="false">http://hacks.mozilla.org/?p=1796#comment-26437</guid>
		<description>EXCELLENT... the simple Google URL worked but the embedded javascript obviously did not.

I&#039;m sure this is just an escape mechanism and not the actual CSP.

J.</description>
		<content:encoded><![CDATA[<p>EXCELLENT&#8230; the simple Google URL worked but the embedded javascript obviously did not.</p>
<p>I&#8217;m sure this is just an escape mechanism and not the actual CSP.</p>
<p>J.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jaredzusmc</title>
		<link>http://hacks.mozilla.org/2009/10/content-security-policy/comment-page-1/#comment-26436</link>
		<dc:creator>jaredzusmc</dc:creator>
		<pubDate>Tue, 06 Oct 2009 21:51:26 +0000</pubDate>
		<guid isPermaLink="false">http://hacks.mozilla.org/?p=1796#comment-26436</guid>
		<description>Thanks for this info. Really like the definitions of basic attacks. I&#039;m used to the terms, but not all people are. 
Not trying to &quot;attack&quot; just wanting to see the escape parameters here: 
&lt;a&gt;Google&lt;/a&gt;
&lt;a href=&quot;http://www.google.com&quot; rel=&quot;nofollow&quot;&gt;Google&lt;/a&gt;


Thanks again for the inside scoop, 

J.</description>
		<content:encoded><![CDATA[<p>Thanks for this info. Really like the definitions of basic attacks. I&#8217;m used to the terms, but not all people are.<br />
Not trying to &#8220;attack&#8221; just wanting to see the escape parameters here:<br />
<a>Google</a><br />
<a href="http://www.google.com" rel="nofollow">Google</a></p>
<p>Thanks again for the inside scoop, </p>
<p>J.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

