<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Malicious XPIs run executable binaries</title>
	<atom:link href="http://blog.codefront.net/2004/03/27/malicious-xpis-run-executable-binaries/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.codefront.net/2004/03/27/malicious-xpis-run-executable-binaries/</link>
	<description>Rails, Firefox, Anime, Mac</description>
	<lastBuildDate>Thu, 11 Mar 2010 23:55:41 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Minh Nguy&#x1ec5;n</title>
		<link>http://blog.codefront.net/2004/03/27/malicious-xpis-run-executable-binaries/comment-page-1/#comment-2147</link>
		<dc:creator>Minh Nguy&#x1ec5;n</dc:creator>
		<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.codefront.net/archives/2004/03/27/malicious-xpis-run-executable-binaries/#comment-2147</guid>
		<description>I&#8217;m not so sure that David Tenser verifying all the XPIs alone would scale too well. :)</description>
		<content:encoded><![CDATA[<p>I&rsquo;m not so sure that David Tenser verifying all the XPIs alone would scale too well. :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dark Reflexions</title>
		<link>http://blog.codefront.net/2004/03/27/malicious-xpis-run-executable-binaries/comment-page-1/#comment-2148</link>
		<dc:creator>Dark Reflexions</dc:creator>
		<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.codefront.net/archives/2004/03/27/malicious-xpis-run-executable-binaries/#comment-2148</guid>
		<description>&lt;strong&gt;Disappointing&lt;/strong&gt;
A malicious Firefox .XPI was created I&#039;m just gunna trackback and link you to the blog of a person I know (internet-wise), because his post was very well written. It will be fixed by the Mozilla developement project somehow, but...
</description>
		<content:encoded><![CDATA[<p><strong>Disappointing</strong><br />
A malicious Firefox .XPI was created I&#8217;m just gunna trackback and link you to the blog of a person I know (internet-wise), because his post was very well written. It will be fixed by the Mozilla developement project somehow, but&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cheah Chu Yeow</title>
		<link>http://blog.codefront.net/2004/03/27/malicious-xpis-run-executable-binaries/comment-page-1/#comment-2146</link>
		<dc:creator>Cheah Chu Yeow</dc:creator>
		<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.codefront.net/archives/2004/03/27/malicious-xpis-run-executable-binaries/#comment-2146</guid>
		<description>&lt;blockquote&gt;Verified by whom? mozilla.org?&lt;/blockquote&gt;

I&#039;d say a good, trusted authority is good enough. The people at mozdev.org, David Tenser, mozilla.org are possible candidates.</description>
		<content:encoded><![CDATA[<blockquote><p>Verified by whom? mozilla.org?</p></blockquote>
<p>I&#8217;d say a good, trusted authority is good enough. The people at mozdev.org, David Tenser, mozilla.org are possible candidates.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 0zone</title>
		<link>http://blog.codefront.net/2004/03/27/malicious-xpis-run-executable-binaries/comment-page-1/#comment-2145</link>
		<dc:creator>0zone</dc:creator>
		<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.codefront.net/archives/2004/03/27/malicious-xpis-run-executable-binaries/#comment-2145</guid>
		<description>There should be a team that checks packages that are submitted, if the team finds that the packages are ok then they add the file name and md5 of the file to a database that gets checked by the installer. If the installer can&#039;t find the entry then it should display a warning stating that the package could not be verified and ask them if they want to continue (no should be default).</description>
		<content:encoded><![CDATA[<p>There should be a team that checks packages that are submitted, if the team finds that the packages are ok then they add the file name and md5 of the file to a database that gets checked by the installer. If the installer can&#8217;t find the entry then it should display a warning stating that the package could not be verified and ask them if they want to continue (no should be default).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jesse Ruderman</title>
		<link>http://blog.codefront.net/2004/03/27/malicious-xpis-run-executable-binaries/comment-page-1/#comment-2144</link>
		<dc:creator>Jesse Ruderman</dc:creator>
		<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.codefront.net/archives/2004/03/27/malicious-xpis-run-executable-binaries/#comment-2144</guid>
		<description>&quot;Best solution, to me? Verified and digitally signed XPIs are allowed to run without hindrance.&quot;

Verified by whom?  mozilla.org?</description>
		<content:encoded><![CDATA[<p>&#8220;Best solution, to me? Verified and digitally signed XPIs are allowed to run without hindrance.&#8221;</p>
<p>Verified by whom?  mozilla.org?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
