<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Google Chrome Options</title>
	<atom:link href="http://www.gnucitizen.org/blog/google-chrome-options/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/google-chrome-options/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Tue, 06 Jan 2009 09:11:24 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: media buff</title>
		<link>http://www.gnucitizen.org/blog/google-chrome-options/comment-page-1/#comment-123806</link>
		<dc:creator>media buff</dc:creator>
		<pubDate>Sat, 20 Sep 2008 21:48:19 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1318#comment-123806</guid>
		<description>it's funny, the more i use Chrome, the more unstable it seems to get... crashes a lot more, can't handle sites with flash, hangs every time i close a tab... all that to say, i'm switching back to Firefox</description>
		<content:encoded><![CDATA[<p>it&#8217;s funny, the more i use Chrome, the more unstable it seems to get&#8230; crashes a lot more, can&#8217;t handle sites with flash, hangs every time i close a tab&#8230; all that to say, i&#8217;m switching back to Firefox</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: meathive</title>
		<link>http://www.gnucitizen.org/blog/google-chrome-options/comment-page-1/#comment-123790</link>
		<dc:creator>meathive</dc:creator>
		<pubDate>Fri, 19 Sep 2008 14:36:42 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1318#comment-123790</guid>
		<description>I'm inclined to believe that Google is simply testing the waters by releasing Chrome; I also think something truly deceptive is going on in releasing it that I can't quite grasp.

https://kinqpinz.info/lib/2008/sep/#d5ab0fdf</description>
		<content:encoded><![CDATA[<p>I&#8217;m inclined to believe that Google is simply testing the waters by releasing Chrome; I also think something truly deceptive is going on in releasing it that I can&#8217;t quite grasp.</p>
<p><a href="https://kinqpinz.info/lib/2008/sep/#d5ab0fdf" rel="nofollow">https://kinqpinz.info/lib/2008/sep/#d5ab0fdf</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: est</title>
		<link>http://www.gnucitizen.org/blog/google-chrome-options/comment-page-1/#comment-123789</link>
		<dc:creator>est</dc:creator>
		<pubDate>Fri, 19 Sep 2008 14:09:10 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1318#comment-123789</guid>
		<description>what's the difference between %s %l and %* ?</description>
		<content:encoded><![CDATA[<p>what&#8217;s the difference between %s %l and %* ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/google-chrome-options/comment-page-1/#comment-123786</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 19 Sep 2008 09:34:16 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1318#comment-123786</guid>
		<description>10x, Chris. Keep up the good work!</description>
		<content:encoded><![CDATA[<p>10x, Chris. Keep up the good work!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ronald</title>
		<link>http://www.gnucitizen.org/blog/google-chrome-options/comment-page-1/#comment-123783</link>
		<dc:creator>ronald</dc:creator>
		<pubDate>Fri, 19 Sep 2008 00:33:19 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1318#comment-123783</guid>
		<description>I'm highly dissapointed by Chrome. Google had the manpower to create something new and epic, but they failed. I mean what are they doing? copying Webkit and tweaking it a bit? 

It's sad dudes, I'm really dissapointed that no-one in this Universe seems to create a secure browser. For real, it's that bad!

It's depressing at most.</description>
		<content:encoded><![CDATA[<p>I&#8217;m highly dissapointed by Chrome. Google had the manpower to create something new and epic, but they failed. I mean what are they doing? copying Webkit and tweaking it a bit? </p>
<p>It&#8217;s sad dudes, I&#8217;m really dissapointed that no-one in this Universe seems to create a secure browser. For real, it&#8217;s that bad!</p>
<p>It&#8217;s depressing at most.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Evans</title>
		<link>http://www.gnucitizen.org/blog/google-chrome-options/comment-page-1/#comment-123776</link>
		<dc:creator>Chris Evans</dc:creator>
		<pubDate>Thu, 18 Sep 2008 21:59:50 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1318#comment-123776</guid>
		<description>Yes, it's a reasonable defense in depth measure so I'll make it happen.</description>
		<content:encoded><![CDATA[<p>Yes, it&#8217;s a reasonable defense in depth measure so I&#8217;ll make it happen.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Brooks</title>
		<link>http://www.gnucitizen.org/blog/google-chrome-options/comment-page-1/#comment-123773</link>
		<dc:creator>Michael Brooks</dc:creator>
		<pubDate>Thu, 18 Sep 2008 19:40:14 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1318#comment-123773</guid>
		<description>You totally found this file (http://src.chromium.org/svn/trunk/src/chrome/common/chrome_switches.cc) by doing a "find in files" for "file://"!  I like your file:// hack for quicktime,  how did you know it was a flaw?</description>
		<content:encoded><![CDATA[<p>You totally found this file (http://src.chromium.org/svn/trunk/src/chrome/common/chrome_switches.cc) by doing a &#8220;find in files&#8221; for &#8220;file://&#8221;!  I like your <a href='file://' rel='nofollow'>file://</a> hack for quicktime,  how did you know it was a flaw?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/google-chrome-options/comment-page-1/#comment-123770</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 18 Sep 2008 16:02:11 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1318#comment-123770</guid>
		<description>Ryan, yes, this is what &lt;a href="http://www.scary.beasts.org/security/" rel="nofollow"&gt;Chris Evans&lt;/a&gt; suggested as well.</description>
		<content:encoded><![CDATA[<p>Ryan, yes, this is what <a href="http://www.scary.beasts.org/security/" rel="nofollow">Chris Evans</a> suggested as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Julian Rodriguez</title>
		<link>http://www.gnucitizen.org/blog/google-chrome-options/comment-page-1/#comment-123769</link>
		<dc:creator>Julian Rodriguez</dc:creator>
		<pubDate>Thu, 18 Sep 2008 15:55:39 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1318#comment-123769</guid>
		<description>hahaha nice, very nice post.</description>
		<content:encoded><![CDATA[<p>hahaha nice, very nice post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan Patterson</title>
		<link>http://www.gnucitizen.org/blog/google-chrome-options/comment-page-1/#comment-123768</link>
		<dc:creator>Ryan Patterson</dc:creator>
		<pubDate>Thu, 18 Sep 2008 15:18:50 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1318#comment-123768</guid>
		<description>This is a good point. I think the best way to fix it is not to remove those options, though, but instead to change the shell open command to c:\path\to\chrome.exe -- "%s". Traditionally, -- as an argument means "end of options", specifying that only input files follow. However, an equally effective measure might be c:\path\to\chrome.exe "--url=%s".

This removes the vulnerability from the shell's open URL command, but still leaves the flexibility provided by allowing command-line arguments.</description>
		<content:encoded><![CDATA[<p>This is a good point. I think the best way to fix it is not to remove those options, though, but instead to change the shell open command to c:\path\to\chrome.exe &#8212; &#8220;%s&#8221;. Traditionally, &#8212; as an argument means &#8220;end of options&#8221;, specifying that only input files follow. However, an equally effective measure might be c:\path\to\chrome.exe &#8220;&#8211;url=%s&#8221;.</p>
<p>This removes the vulnerability from the shell&#8217;s open URL command, but still leaves the flexibility provided by allowing command-line arguments.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
