<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments for One Shot Design</title>
	<atom:link href="http://www.1sd.org/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.1sd.org</link>
	<description>Areas of our digital life that should be left open or kept closed</description>
	<pubDate>Mon, 22 Mar 2010 04:05:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>Comment on Largest job search engine should hire a better sysadmin by E L</title>
		<link>http://www.1sd.org/2009/01/24/largest-job-search-engine-should-hire-a-better-sysadmin/#comment-8279</link>
		<dc:creator>E L</dc:creator>
		<pubDate>Mon, 02 Mar 2009 00:32:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.1sd.org/2009/01/24/largest-job-search-engine-should-hire-a-better-sysadmin/#comment-8279</guid>
		<description>Hi,
After monster.com had their
problems, I changed my 
password and found the login 
process and the password 
change process is not 
encrypted at all.

I've sent them a message 
which will certainly go 
unanswered.

It seemed like there might
be some guidelines at the
Safe Harbor web pages.  Sad
to say, there is nothing 
there indicating encryption
should be used during the
login and password changing
processes.

I used Wireshark to capture
packets during the login
process and during the
password change process.
Both were in the clear using
HTTP instead of HTTPS.

Perhaps this information can
be shared out to Monster and
other companies to fix this
issue.  And, shared to the
customers to put pressure
on these companies.

We've learned NOT to hold 
our breath for these simple,
yet effective security 
methods.  

Regards,
E L
nojunkmail4ebl@comcast.net</description>
		<content:encoded><![CDATA[<p>Hi,<br />
After monster.com had their<br />
problems, I changed my<br />
password and found the login<br />
process and the password<br />
change process is not<br />
encrypted at all.</p>
<p>I&#8217;ve sent them a message<br />
which will certainly go<br />
unanswered.</p>
<p>It seemed like there might<br />
be some guidelines at the<br />
Safe Harbor web pages.  Sad<br />
to say, there is nothing<br />
there indicating encryption<br />
should be used during the<br />
login and password changing<br />
processes.</p>
<p>I used Wireshark to capture<br />
packets during the login<br />
process and during the<br />
password change process.<br />
Both were in the clear using<br />
HTTP instead of HTTPS.</p>
<p>Perhaps this information can<br />
be shared out to Monster and<br />
other companies to fix this<br />
issue.  And, shared to the<br />
customers to put pressure<br />
on these companies.</p>
<p>We&#8217;ve learned NOT to hold<br />
our breath for these simple,<br />
yet effective security<br />
methods.  </p>
<p>Regards,<br />
E L<br />
<a href="mailto:nojunkmail4ebl@comcast.net">nojunkmail4ebl@comcast.net</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Book review: After The Software Wars by Book Review!-- keithcu.com</title>
		<link>http://www.1sd.org/2009/01/16/book-review-after-the-software-wars/#comment-3177</link>
		<dc:creator>Book Review!-- keithcu.com</dc:creator>
		<pubDate>Fri, 16 Jan 2009 22:05:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.1sd.org/?p=837#comment-3177</guid>
		<description>[...] is a book review from Francis Jacquerye, a Master of Arts in design who lives in [...]</description>
		<content:encoded><![CDATA[<p>[...] is a book review from Francis Jacquerye, a Master of Arts in design who lives in [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Public domain T-shirt template by kramero</title>
		<link>http://www.1sd.org/2007/02/19/t-shirt/#comment-649</link>
		<dc:creator>kramero</dc:creator>
		<pubDate>Tue, 11 Nov 2008 03:03:43 +0000</pubDate>
		<guid isPermaLink="false">http://1sd.org/?p=	36#comment-649</guid>
		<description>Thanks for sharing... I've been looking everywhere for this..</description>
		<content:encoded><![CDATA[<p>Thanks for sharing&#8230; I&#8217;ve been looking everywhere for this..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Zimbra, Yahoo&#8217;s new mail client by Dan K.</title>
		<link>http://www.1sd.org/2008/10/28/zimbra-yahoos-new-mail-client/#comment-278</link>
		<dc:creator>Dan K.</dc:creator>
		<pubDate>Tue, 28 Oct 2008 21:06:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.1sd.org/?p=405#comment-278</guid>
		<description>There's underlying support for vCard import, though it may not currently be surfaced in the UI.  Go ahead and request it in the Zimbra bug tracking system: http://bugzilla.zimbra.com</description>
		<content:encoded><![CDATA[<p>There&#8217;s underlying support for vCard import, though it may not currently be surfaced in the UI.  Go ahead and request it in the Zimbra bug tracking system: <a href="http://bugzilla.zimbra.com" rel="nofollow">http://bugzilla.zimbra.com</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
