<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: &quot;Import email addresses&quot; Considered Harmful</title>
	<atom:link href="http://www.mcgrewsecurity.com/2008/03/30/import-email-addresses-considered-harmful/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mcgrewsecurity.com/2008/03/30/import-email-addresses-considered-harmful/</link>
	<description></description>
	<lastBuildDate>Thu, 05 Jan 2012 11:44:23 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: admin</title>
		<link>http://www.mcgrewsecurity.com/2008/03/30/import-email-addresses-considered-harmful/#comment-284</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Tue, 08 Apr 2008 16:14:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=96#comment-284</guid>
		<description>Thanks for the comment, soup!  I also SSL everything in GMail, so I don&#039;t see why they wouldn&#039;t be able to do the same.

I guess the only way I could see these &quot;import&quot; features really working well would be to compartmentalize:  In GMail for example, have a way to allow access only to (approved) contacts, and only with a password or passphrase that&#039;s separate from your main login.

That way you at least have some control over what these sites see/do/reveal once they&#039;re logged into your GMail/etc. account</description>
		<content:encoded><![CDATA[<p>Thanks for the comment, soup!  I also SSL everything in GMail, so I don&#8217;t see why they wouldn&#8217;t be able to do the same.</p>
<p>I guess the only way I could see these &#8220;import&#8221; features really working well would be to compartmentalize:  In GMail for example, have a way to allow access only to (approved) contacts, and only with a password or passphrase that&#8217;s separate from your main login.</p>
<p>That way you at least have some control over what these sites see/do/reveal once they&#8217;re logged into your GMail/etc. account</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: soup</title>
		<link>http://www.mcgrewsecurity.com/2008/03/30/import-email-addresses-considered-harmful/#comment-283</link>
		<dc:creator>soup</dc:creator>
		<pubDate>Tue, 08 Apr 2008 15:53:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=96#comment-283</guid>
		<description>I had an experience with Plaxo along these lines.

My email to them:
=-=-=-=-=-=-=-=-=-=-=-=-=-=
Subject: lack of SSL

I noticed that the pages you have to import contact information from other sources (specifically for me LinkedIn and GMail) are not
encrypted.
I am not comfortable putting in my password information on a page that isn&#039;t secured by at least 128-bit SSL.
=-=-=-=-=-=-=-=-=-=-=-=-=-=

Their reply:
=-=-=-=-=-=-=-=-=-=-=-=-=-=
Good catch.  However, anywhere you place your PW or any type of authentication to Plaxo plus any other sync point are in SSL.  When transferring data such as data syncs between LinkedIn or GMail, those are not in SSL.  Why?  Because they don&#039;t support it.  In fact, all sites like Yahoo and Hotmail practice the same method - it&#039;s only when you&#039;re signing in or when changing password (actually, anytime credentials are requested) is when the SSL pages are used.  And because we have to work with their sites, we must abide by their protocol.
=-=-=-=-=-=-=-=-=-=-=-=-=-=

What?  I use Greasemonkey to force SSL for every single page I view in GMail.  I know it&#039;s possible.</description>
		<content:encoded><![CDATA[<p>I had an experience with Plaxo along these lines.</p>
<p>My email to them:<br />
=-=-=-=-=-=-=-=-=-=-=-=-=-=<br />
Subject: lack of SSL</p>
<p>I noticed that the pages you have to import contact information from other sources (specifically for me LinkedIn and GMail) are not<br />
encrypted.<br />
I am not comfortable putting in my password information on a page that isn&#8217;t secured by at least 128-bit SSL.<br />
=-=-=-=-=-=-=-=-=-=-=-=-=-=</p>
<p>Their reply:<br />
=-=-=-=-=-=-=-=-=-=-=-=-=-=<br />
Good catch.  However, anywhere you place your PW or any type of authentication to Plaxo plus any other sync point are in SSL.  When transferring data such as data syncs between LinkedIn or GMail, those are not in SSL.  Why?  Because they don&#8217;t support it.  In fact, all sites like Yahoo and Hotmail practice the same method &#8211; it&#8217;s only when you&#8217;re signing in or when changing password (actually, anytime credentials are requested) is when the SSL pages are used.  And because we have to work with their sites, we must abide by their protocol.<br />
=-=-=-=-=-=-=-=-=-=-=-=-=-=</p>
<p>What?  I use Greasemonkey to force SSL for every single page I view in GMail.  I know it&#8217;s possible.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

