<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Security in an AJAX World</title>
	<atom:link href="http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/</link>
	<description>Philip Jacob's web page</description>
	<lastBuildDate>Tue, 13 Sep 2011 08:59:30 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Slung</title>
		<link>http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/comment-page-1/#comment-189248</link>
		<dc:creator>Slung</dc:creator>
		<pubDate>Mon, 14 Jun 2010 19:49:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/#comment-189248</guid>
		<description>If the token is part of an associative array, as in the request is contained in 
an iteration of an array, the serial or id of the object would not only be hard to guess
but easy to reference given multiple runs or sends.
I believe it is easier to grab a hard coded token as well, especially if it happens to have
some sort of &quot;x&quot; or &quot;y&quot; thing going on...
Just as storing data in most major AJAX lines of coding techniques promote healthy
security, storing the request with a random or new iteration (associative) then destroying it allows for the browser to clean up after itself.</description>
		<content:encoded><![CDATA[<p>If the token is part of an associative array, as in the request is contained in<br />
an iteration of an array, the serial or id of the object would not only be hard to guess<br />
but easy to reference given multiple runs or sends.<br />
I believe it is easier to grab a hard coded token as well, especially if it happens to have<br />
some sort of &#8220;x&#8221; or &#8220;y&#8221; thing going on&#8230;<br />
Just as storing data in most major AJAX lines of coding techniques promote healthy<br />
security, storing the request with a random or new iteration (associative) then destroying it allows for the browser to clean up after itself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Max Kiesler - Designer &#187; Blog Archive &#187; What You Should Know About AJAX Security: 24 Tutorials</title>
		<link>http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/comment-page-1/#comment-145788</link>
		<dc:creator>Max Kiesler - Designer &#187; Blog Archive &#187; What You Should Know About AJAX Security: 24 Tutorials</dc:creator>
		<pubDate>Tue, 02 Jun 2009 08:48:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/#comment-145788</guid>
		<description>[...] Security in an AJAX World If data is more openly available as XML over HTTP, it’s going to be pretty damn easy for a smart hacker to get access to that data to make applications like this impressive example… which is great, but undoubtedly someone eventually will feel like their data is being “stolen” or “misused”. [...]</description>
		<content:encoded><![CDATA[<p>[...] Security in an AJAX World If data is more openly available as XML over HTTP, it’s going to be pretty damn easy for a smart hacker to get access to that data to make applications like this impressive example… which is great, but undoubtedly someone eventually will feel like their data is being “stolen” or “misused”. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sebastian Bauer (IT-Blog) &#187; Aufgepasst im Web2.0</title>
		<link>http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/comment-page-1/#comment-56428</link>
		<dc:creator>Sebastian Bauer (IT-Blog) &#187; Aufgepasst im Web2.0</dc:creator>
		<pubDate>Thu, 24 Jan 2008 16:15:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/#comment-56428</guid>
		<description>[...] Links zu dem Thema: ar.kadi.us, Whirlycott, Mayflower     komfortabler Datei-Upload mit [...]</description>
		<content:encoded><![CDATA[<p>[...] Links zu dem Thema: ar.kadi.us, Whirlycott, Mayflower     komfortabler Datei-Upload mit [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ajax Security on HubPages</title>
		<link>http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/comment-page-1/#comment-6032</link>
		<dc:creator>Ajax Security on HubPages</dc:creator>
		<pubDate>Fri, 13 Oct 2006 21:12:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/#comment-6032</guid>
		<description>[...] json xmlhttprequest javascript webdevelopment What are tags?email this pagedigg this pagereddit!bookmark this pagelink to this pageWhat do thesedo? [...]</description>
		<content:encoded><![CDATA[<p>[...] json xmlhttprequest javascript webdevelopment What are tags?email this pagedigg this pagereddit!bookmark this pagelink to this pageWhat do thesedo? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BiZwiKi - 喧闹 PK 噪音 &#187; Blog Archive &#187; Ajax Security</title>
		<link>http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/comment-page-1/#comment-1841</link>
		<dc:creator>BiZwiKi - 喧闹 PK 噪音 &#187; Blog Archive &#187; Ajax Security</dc:creator>
		<pubDate>Tue, 09 May 2006 21:47:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/#comment-1841</guid>
		<description></description>
		<content:encoded><![CDATA[<p>[...] AJAX 世界里?的安全（Security in an AJAX World） [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lockergnome's Web Developers</title>
		<link>http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/comment-page-1/#comment-1582</link>
		<dc:creator>Lockergnome's Web Developers</dc:creator>
		<pubDate>Fri, 17 Mar 2006 06:25:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/#comment-1582</guid>
		<description>&lt;strong&gt;Security in an AJAX World...&lt;/strong&gt;

Don&#039;t get me wrong here, I think that AJAX is as cool as everyone else out there. Cool effects and time saving abilities. But is it also a cause for security concerns, too. It appears that for some, it could......</description>
		<content:encoded><![CDATA[<p><strong>Security in an AJAX World&#8230;</strong></p>
<p>Don&#8217;t get me wrong here, I think that AJAX is as cool as everyone else out there. Cool effects and time saving abilities. But is it also a cause for security concerns, too. It appears that for some, it could&#8230;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 木头工作室 &#187; Ajax Security (1)</title>
		<link>http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/comment-page-1/#comment-1530</link>
		<dc:creator>木头工作室 &#187; Ajax Security (1)</dc:creator>
		<pubDate>Fri, 17 Feb 2006 02:31:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/#comment-1530</guid>
		<description></description>
		<content:encoded><![CDATA[<p>[...] 下?的内容?考自：http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/ [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 빛? 담고 세? 넓히기 &#187; AJAX 개발?용 ?료(3) - 보안</title>
		<link>http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/comment-page-1/#comment-1511</link>
		<dc:creator>빛? 담고 세? 넓히기 &#187; AJAX 개발?용 ?료(3) - 보안</dc:creator>
		<pubDate>Thu, 12 Jan 2006 02:18:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/#comment-1511</guid>
		<description></description>
		<content:encoded><![CDATA[<p>[...] 1. token 사용 : UUID와 같? 토?? 사용함으로? 유효한 사용?? 요청?만 ?답할 수 있다. session? 키를 저장한 후 ??서버로 ?정한 시간안? XMLHttpRequest 요청? 들어오는 경우만 ?답? 하는 방?으로 유효성? 체?할 수 있다. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: joe</title>
		<link>http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/comment-page-1/#comment-1468</link>
		<dc:creator>joe</dc:creator>
		<pubDate>Fri, 28 Oct 2005 03:28:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/#comment-1468</guid>
		<description>can&#039;t this data be mooched from a website anyway?  splogs have been taking bits of real blog posts to add a pinch of real to them .</description>
		<content:encoded><![CDATA[<p>can&#8217;t this data be mooched from a website anyway?  splogs have been taking bits of real blog posts to add a pinch of real to them .</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gregor J. Rothfuss</title>
		<link>http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/comment-page-1/#comment-614</link>
		<dc:creator>Gregor J. Rothfuss</dc:creator>
		<pubDate>Wed, 20 Apr 2005 19:44:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.whirlycott.com/phil/2005/04/15/security-in-an-ajax-world/#comment-614</guid>
		<description>also,

http://www.intertwingly.net/blog/2005/04/01/Sajax-Still-UnSafe</description>
		<content:encoded><![CDATA[<p>also,</p>
<p><a href="http://www.intertwingly.net/blog/2005/04/01/Sajax-Still-UnSafe" rel="nofollow">http://www.intertwingly.net/blog/2005/04/01/Sajax-Still-UnSafe</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

