<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Improving Google Chrome</title>
	<atom:link href="http://www.gnucitizen.org/blog/improving-google-chrome/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/improving-google-chrome/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Tue, 06 Jan 2009 04:06:47 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: radi</title>
		<link>http://www.gnucitizen.org/blog/improving-google-chrome/comment-page-1/#comment-123732</link>
		<dc:creator>radi</dc:creator>
		<pubDate>Tue, 16 Sep 2008 11:55:58 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1250#comment-123732</guid>
		<description>"Let’s have another Chrome Mode which is called Encrypted Mode -&#62; New encrypted window Ctrl + Shift + E. Once inside this window, HTTPS is forced on all requests. No exceptions!"

Can you elaborate a bit more, please? Would this mean that use of HTTPS would be mandated by the browser as opposed to by the web app?</description>
		<content:encoded><![CDATA[<p>&#8220;Let’s have another Chrome Mode which is called Encrypted Mode -&gt; New encrypted window Ctrl + Shift + E. Once inside this window, HTTPS is forced on all requests. No exceptions!&#8221;</p>
<p>Can you elaborate a bit more, please? Would this mean that use of HTTPS would be mandated by the browser as opposed to by the web app?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hubert</title>
		<link>http://www.gnucitizen.org/blog/improving-google-chrome/comment-page-1/#comment-123694</link>
		<dc:creator>Hubert</dc:creator>
		<pubDate>Fri, 12 Sep 2008 12:37:38 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1250#comment-123694</guid>
		<description>Reasonable idea but I doubt they would ever implement it since it will break many (most) websites.</description>
		<content:encoded><![CDATA[<p>Reasonable idea but I doubt they would ever implement it since it will break many (most) websites.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: FilipM</title>
		<link>http://www.gnucitizen.org/blog/improving-google-chrome/comment-page-1/#comment-123673</link>
		<dc:creator>FilipM</dc:creator>
		<pubDate>Thu, 11 Sep 2008 12:51:56 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1250#comment-123673</guid>
		<description>@ Erlend:
I understand your concern, but if session cookies (and sessions in general) aren't shared between tabs, there would be no possibility for child-sessions or childprocesses communicating with the parent. Although I'm not fund of the use of childprocesses, somethimes they come in handy. Lots of webapps would have to be rewritten, even the encrypted onces.</description>
		<content:encoded><![CDATA[<p>@ Erlend:<br />
I understand your concern, but if session cookies (and sessions in general) aren&#8217;t shared between tabs, there would be no possibility for child-sessions or childprocesses communicating with the parent. Although I&#8217;m not fund of the use of childprocesses, somethimes they come in handy. Lots of webapps would have to be rewritten, even the encrypted onces.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Erlend</title>
		<link>http://www.gnucitizen.org/blog/improving-google-chrome/comment-page-1/#comment-123669</link>
		<dc:creator>Erlend</dc:creator>
		<pubDate>Thu, 11 Sep 2008 07:39:06 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1250#comment-123669</guid>
		<description>I like the idea of having an encrypted mode. One of the things that puzzles me about Chrome, is that even though the tabs run as different processes, session cookies are still shared between the tabs. If they were not shared, that might make XSRF harder, because the sessions were not available when visiting a malicious site in another tab.</description>
		<content:encoded><![CDATA[<p>I like the idea of having an encrypted mode. One of the things that puzzles me about Chrome, is that even though the tabs run as different processes, session cookies are still shared between the tabs. If they were not shared, that might make XSRF harder, because the sessions were not available when visiting a malicious site in another tab.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NurBo</title>
		<link>http://www.gnucitizen.org/blog/improving-google-chrome/comment-page-1/#comment-123667</link>
		<dc:creator>NurBo</dc:creator>
		<pubDate>Thu, 11 Sep 2008 03:59:36 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1250#comment-123667</guid>
		<description>Yeah the Google Chrome browser is a great piece of work but they still have a few big bugs to fix. And I also don't like how the browser itself doesn't support flash games and videos that we'll. But its the beta version :)</description>
		<content:encoded><![CDATA[<p>Yeah the Google Chrome browser is a great piece of work but they still have a few big bugs to fix. And I also don&#8217;t like how the browser itself doesn&#8217;t support flash games and videos that we&#8217;ll. But its the beta version :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clefty</title>
		<link>http://www.gnucitizen.org/blog/improving-google-chrome/comment-page-1/#comment-123665</link>
		<dc:creator>Clefty</dc:creator>
		<pubDate>Thu, 11 Sep 2008 01:38:03 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1250#comment-123665</guid>
		<description>I think privacy is very important.  I didn't realize there was that problem with leaking session identifiers.  Do you think google will be fixing this soon (especially since you say it's a quick and easy fix)?  That's one thing I'd like fixed before I fully commit to google chrome.</description>
		<content:encoded><![CDATA[<p>I think privacy is very important.  I didn&#8217;t realize there was that problem with leaking session identifiers.  Do you think google will be fixing this soon (especially since you say it&#8217;s a quick and easy fix)?  That&#8217;s one thing I&#8217;d like fixed before I fully commit to google chrome.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Julian A. Rodriguez</title>
		<link>http://www.gnucitizen.org/blog/improving-google-chrome/comment-page-1/#comment-123663</link>
		<dc:creator>Julian A. Rodriguez</dc:creator>
		<pubDate>Wed, 10 Sep 2008 23:48:39 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1250#comment-123663</guid>
		<description>yeah it's a very nice idea but the browser honestly sucks, they need first fix all the simple bugs and bofs in the software; your idea it's a good begin, btw "big company, bad software" I don't want to say that about google but something it's wrong here</description>
		<content:encoded><![CDATA[<p>yeah it&#8217;s a very nice idea but the browser honestly sucks, they need first fix all the simple bugs and bofs in the software; your idea it&#8217;s a good begin, btw &#8220;big company, bad software&#8221; I don&#8217;t want to say that about google but something it&#8217;s wrong here</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/improving-google-chrome/comment-page-1/#comment-123657</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 10 Sep 2008 16:32:46 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1250#comment-123657</guid>
		<description>yep, correct. the anti XSS and CSRF features should be global to all browser modes.</description>
		<content:encoded><![CDATA[<p>yep, correct. the anti XSS and CSRF features should be global to all browser modes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan Patterson</title>
		<link>http://www.gnucitizen.org/blog/improving-google-chrome/comment-page-1/#comment-123656</link>
		<dc:creator>Ryan Patterson</dc:creator>
		<pubDate>Wed, 10 Sep 2008 16:21:57 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1250#comment-123656</guid>
		<description>Sure, it is a great idea, and it'd be easy to do in Firefox via an extension. But it doesn't protect you from either XSS attacks or CSRFs.</description>
		<content:encoded><![CDATA[<p>Sure, it is a great idea, and it&#8217;d be easy to do in Firefox via an extension. But it doesn&#8217;t protect you from either XSS attacks or CSRFs.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
