<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: It&#8217;s a WRAP</title>
	<atom:link href="http://benlog.com/articles/2009/12/22/its-a-wrap/feed/" rel="self" type="application/rss+xml" />
	<link>http://benlog.com/articles/2009/12/22/its-a-wrap/</link>
	<description>security, privacy, transparency.</description>
	<lastBuildDate>Thu, 17 May 2012 19:16:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: OAuth Bearer Tokens are a Terrible Idea &#171; hueniverse</title>
		<link>http://benlog.com/articles/2009/12/22/its-a-wrap/comment-page-1/#comment-632792</link>
		<dc:creator>OAuth Bearer Tokens are a Terrible Idea &#171; hueniverse</dc:creator>
		<pubDate>Wed, 29 Sep 2010 19:09:51 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=1053#comment-632792</guid>
		<description>[...] is not new. Ben Adida described this exact issue when reviewing the original WRAP proposal: But wait, you say, don’t worry, the token is sent over SSL, so it’s all [...]</description>
		<content:encoded><![CDATA[<p>[...] is not new. Ben Adida described this exact issue when reviewing the original WRAP proposal: But wait, you say, don’t worry, the token is sent over SSL, so it’s all [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OAuth 2.0 security used by Facebook, others called weak &#124; PCM Tech Center</title>
		<link>http://benlog.com/articles/2009/12/22/its-a-wrap/comment-page-1/#comment-632532</link>
		<dc:creator>OAuth 2.0 security used by Facebook, others called weak &#124; PCM Tech Center</dc:creator>
		<pubDate>Fri, 24 Sep 2010 01:13:50 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=1053#comment-632532</guid>
		<description>[...] might actually be worse than passwords,&#8221; security expert Ben Adida noted last December in a blog post. It&#8217;s &#8220;very hard for users to gauge whether web applications are doing the right thing [...]</description>
		<content:encoded><![CDATA[<p>[...] might actually be worse than passwords,&#8221; security expert Ben Adida noted last December in a blog post. It&#8217;s &#8220;very hard for users to gauge whether web applications are doing the right thing [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Twitter: big on social, small on security &#8211; RAAK</title>
		<link>http://benlog.com/articles/2009/12/22/its-a-wrap/comment-page-1/#comment-632522</link>
		<dc:creator>Twitter: big on social, small on security &#8211; RAAK</dc:creator>
		<pubDate>Thu, 23 Sep 2010 09:09:38 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=1053#comment-632522</guid>
		<description>[...] we start digging into the really scary stuff, let&#8217;s look at the issue at hand: how did this worm [...]</description>
		<content:encoded><![CDATA[<p>[...] we start digging into the really scary stuff, let&#8217;s look at the issue at hand: how did this worm [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OAuth and OAuth WRAP: defeating the password anti-pattern &#171; I.T News &#38; Stuff</title>
		<link>http://benlog.com/articles/2009/12/22/its-a-wrap/comment-page-1/#comment-624394</link>
		<dc:creator>OAuth and OAuth WRAP: defeating the password anti-pattern &#171; I.T News &#38; Stuff</dc:creator>
		<pubDate>Fri, 22 Jan 2010 04:32:07 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=1053#comment-624394</guid>
		<description>[...] introduce a token-as-password web security protocol in 2010 is somewhat mind-boggling,&#8221; he wrote. &#8220;I see reasons to simplify OAuth. Maybe rethink the combination of consumer and access [...]</description>
		<content:encoded><![CDATA[<p>[...] introduce a token-as-password web security protocol in 2010 is somewhat mind-boggling,&#8221; he wrote. &#8220;I see reasons to simplify OAuth. Maybe rethink the combination of consumer and access [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Links &#187; Security Is Hard: Live With It</title>
		<link>http://benlog.com/articles/2009/12/22/its-a-wrap/comment-page-1/#comment-623583</link>
		<dc:creator>Links &#187; Security Is Hard: Live With It</dc:creator>
		<pubDate>Tue, 05 Jan 2010 16:59:29 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=1053#comment-623583</guid>
		<description>[...] a bad idea, it&#8217;s difficult to know where to start. So I was pleased to see that Ben Adida saved me the trouble. I understand. Security is hard. Getting those timestamps and nonces right, making sure you’ve [...]</description>
		<content:encoded><![CDATA[<p>[...] a bad idea, it&#8217;s difficult to know where to start. So I was pleased to see that Ben Adida saved me the trouble. I understand. Security is hard. Getting those timestamps and nonces right, making sure you’ve [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Benlog &#187; It&#8217;s a WRAP followup: maybe the goal was client-side certs?</title>
		<link>http://benlog.com/articles/2009/12/22/its-a-wrap/comment-page-1/#comment-623370</link>
		<dc:creator>Benlog &#187; It&#8217;s a WRAP followup: maybe the goal was client-side certs?</dc:creator>
		<pubDate>Wed, 23 Dec 2009 19:48:26 +0000</pubDate>
		<guid isPermaLink="false">http://benlog.com/?p=1053#comment-623370</guid>
		<description>[...] Home            &#171; It&#8217;s a WRAP [...]</description>
		<content:encoded><![CDATA[<p>[...] Home            &laquo; It&#8217;s a WRAP [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

