<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for meandering wildly</title>
	<atom:link href="http://blog.johnath.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.johnath.com</link>
	<description>johnath in blog form</description>
	<lastBuildDate>Thu, 26 Jan 2012 13:11:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on Bringing Android Native Firefox to Beta by Robert Kaiser</title>
		<link>http://blog.johnath.com/2012/01/25/bringing-android-native-firefox-to-beta/comment-page-1/#comment-216161</link>
		<dc:creator>Robert Kaiser</dc:creator>
		<pubDate>Thu, 26 Jan 2012 13:11:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.johnath.com/?p=707#comment-216161</guid>
		<description>To be fair, it actually rides the train, but we&#039;re deciding to pick up mail, passengers and cargo while the train is on the go, which can be tricky but we manage. And we&#039;ll be extra careful with Beta and Release (i.e. we&#039;ll see when the train pull into those stations).
But that said, there will no special effort for it to &quot;get back on the trains&quot;, we only need to stop picking up things while the train is going. :)
The fun is, we&#039;re not stopping trains, we&#039;re just doing some unconventional things with them, just like you see in the movies. And given what comes out of all this, let&#039;s hope it&#039;ll be an action-packed, awesome movie with a strong and happy ending! ;-)</description>
		<content:encoded><![CDATA[<p>To be fair, it actually rides the train, but we&#8217;re deciding to pick up mail, passengers and cargo while the train is on the go, which can be tricky but we manage. And we&#8217;ll be extra careful with Beta and Release (i.e. we&#8217;ll see when the train pull into those stations).<br />
But that said, there will no special effort for it to &#8220;get back on the trains&#8221;, we only need to stop picking up things while the train is going. <img src='http://blog.johnath.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
The fun is, we&#8217;re not stopping trains, we&#8217;re just doing some unconventional things with them, just like you see in the movies. And given what comes out of all this, let&#8217;s hope it&#8217;ll be an action-packed, awesome movie with a strong and happy ending! <img src='http://blog.johnath.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Bringing Android Native Firefox to Beta by Bill Gianopoulos</title>
		<link>http://blog.johnath.com/2012/01/25/bringing-android-native-firefox-to-beta/comment-page-1/#comment-216158</link>
		<dc:creator>Bill Gianopoulos</dc:creator>
		<pubDate>Wed, 25 Jan 2012 22:40:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.johnath.com/?p=707#comment-216158</guid>
		<description>The problem here is that although the native version might not be ready, the move everyone form the xul based nightly and aurora builds to the native ones to get more test coverage on the native builds has resulted in very few (if anyone other than me) testing the xul builds.</description>
		<content:encoded><![CDATA[<p>The problem here is that although the native version might not be ready, the move everyone form the xul based nightly and aurora builds to the native ones to get more test coverage on the native builds has resulted in very few (if anyone other than me) testing the xul builds.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Bringing Android Native Firefox to Beta by Mark Finkle</title>
		<link>http://blog.johnath.com/2012/01/25/bringing-android-native-firefox-to-beta/comment-page-1/#comment-216157</link>
		<dc:creator>Mark Finkle</dc:creator>
		<pubDate>Wed, 25 Jan 2012 21:20:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.johnath.com/?p=707#comment-216157</guid>
		<description>@Eugene Savitsky

Native widget Firefox for Android is really focused on phones, not tablets. That said, please file bugs for the tablet issues you see.</description>
		<content:encoded><![CDATA[<p>@Eugene Savitsky</p>
<p>Native widget Firefox for Android is really focused on phones, not tablets. That said, please file bugs for the tablet issues you see.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Bringing Android Native Firefox to Beta by Eugene Savitsky</title>
		<link>http://blog.johnath.com/2012/01/25/bringing-android-native-firefox-to-beta/comment-page-1/#comment-216156</link>
		<dc:creator>Eugene Savitsky</dc:creator>
		<pubDate>Wed, 25 Jan 2012 21:18:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.johnath.com/?p=707#comment-216156</guid>
		<description>Latest Aurora builds are unusable at all. Trying on Asus Transformer (first model).</description>
		<content:encoded><![CDATA[<p>Latest Aurora builds are unusable at all. Trying on Asus Transformer (first model).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Know Thyself &#8211; NSID 2011 by Nukeador</title>
		<link>http://blog.johnath.com/2011/11/30/know-thyself-nsid-2011/comment-page-1/#comment-216107</link>
		<dc:creator>Nukeador</dc:creator>
		<pubDate>Thu, 01 Dec 2011 10:18:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.johnath.com/?p=688#comment-216107</guid>
		<description>Wow, each year your initial post about NSID is getting more and more philosofical, we are like the new sophist school of the beards.</description>
		<content:encoded><![CDATA[<p>Wow, each year your initial post about NSID is getting more and more philosofical, we are like the new sophist school of the beards.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Rapidity by Mozilla: Market Share Isn't Everything &#124; ConceivablyTech</title>
		<link>http://blog.johnath.com/2011/08/26/rapidity/comment-page-1/#comment-216105</link>
		<dc:creator>Mozilla: Market Share Isn't Everything &#124; ConceivablyTech</dc:creator>
		<pubDate>Mon, 10 Oct 2011 01:50:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.johnath.com/?p=657#comment-216105</guid>
		<description>[...] Jonathan Nightingale recently published some notes on Firefox and its competitive field. His thoughts were the most encouraging in awhile [...]</description>
		<content:encoded><![CDATA[<p>[...] Jonathan Nightingale recently published some notes on Firefox and its competitive field. His thoughts were the most encouraging in awhile [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Rapidity by Jason Gates</title>
		<link>http://blog.johnath.com/2011/08/26/rapidity/comment-page-1/#comment-216103</link>
		<dc:creator>Jason Gates</dc:creator>
		<pubDate>Sun, 25 Sep 2011 08:26:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.johnath.com/?p=657#comment-216103</guid>
		<description>Has anyone visited the homepage of https Microsoft.com, because in IE9 it FAILS to provide or show any method to check the SSL certificate as non-secure content is included by Microsoft. 

I bring this up because in Firefox v6, it does show the SSL certificate, but no method is provided to confirm or validate the non-EV certificate. 

In addition, I loaded a SSL website that uses a known Fraudulent SSL Certificate Authority for GTE, same used for Microsoft, in IE9, as a test to see if IE9 would detect the invalid signature...  IE9 FAILED, but Firefox v6 PASSED the test. 

The non-EV certificates can be spoofed, Java injection, MITM and worse NOT even Firefox warns the browser end user about SSL certificate mixing, iframe or popup SSL Phishing attacks.

It&#039;s open season upon the Internet for MITM SSL attacks, especially with DNS redirection. Let&#039;s not forget MD5 collisions is another method of attack, which Google ought to insure all SSL certificates are using SHA512... 

Why isn&#039;t Firefox providing a global certificate repository, so nobody needs to depends upon the Microsoft pre-install, pre-loaded certifciate root authority in Windows?

Why trust Microsoft who cannot insure Certificate Authorities around the world (thousands of them) who PAID Microsoft to ADD them into Windows?

Already 50% of the certificate authorities used in Windows 7 SP1 are UNTRUSTED. 

And that&#039;s the discovered bad ones found, what about the unknown and unreported illegitimate certificates floating around?  

Everyone needs a honest system here, not a proprietary Microsoft knows best for NOT being a security company. 

Please do the good thing Google, Firefox and the open source community. Kick out Microsoft, end the security breaches, design a global repository letting everyone update and check instantly who is legitimate. 

A second benefit here would be to allow everyone to participate, no more PAYING Microsoft to distribute their own root certificates only. 

You get the idea.... lets see some results, okay?</description>
		<content:encoded><![CDATA[<p>Has anyone visited the homepage of https Microsoft.com, because in IE9 it FAILS to provide or show any method to check the SSL certificate as non-secure content is included by Microsoft. </p>
<p>I bring this up because in Firefox v6, it does show the SSL certificate, but no method is provided to confirm or validate the non-EV certificate. </p>
<p>In addition, I loaded a SSL website that uses a known Fraudulent SSL Certificate Authority for GTE, same used for Microsoft, in IE9, as a test to see if IE9 would detect the invalid signature&#8230;  IE9 FAILED, but Firefox v6 PASSED the test. </p>
<p>The non-EV certificates can be spoofed, Java injection, MITM and worse NOT even Firefox warns the browser end user about SSL certificate mixing, iframe or popup SSL Phishing attacks.</p>
<p>It&#8217;s open season upon the Internet for MITM SSL attacks, especially with DNS redirection. Let&#8217;s not forget MD5 collisions is another method of attack, which Google ought to insure all SSL certificates are using SHA512&#8230; </p>
<p>Why isn&#8217;t Firefox providing a global certificate repository, so nobody needs to depends upon the Microsoft pre-install, pre-loaded certifciate root authority in Windows?</p>
<p>Why trust Microsoft who cannot insure Certificate Authorities around the world (thousands of them) who PAID Microsoft to ADD them into Windows?</p>
<p>Already 50% of the certificate authorities used in Windows 7 SP1 are UNTRUSTED. </p>
<p>And that&#8217;s the discovered bad ones found, what about the unknown and unreported illegitimate certificates floating around?  </p>
<p>Everyone needs a honest system here, not a proprietary Microsoft knows best for NOT being a security company. </p>
<p>Please do the good thing Google, Firefox and the open source community. Kick out Microsoft, end the security breaches, design a global repository letting everyone update and check instantly who is legitimate. </p>
<p>A second benefit here would be to allow everyone to participate, no more PAYING Microsoft to distribute their own root certificates only. </p>
<p>You get the idea&#8230;. lets see some results, okay?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Rapidity by Tiago Sá</title>
		<link>http://blog.johnath.com/2011/08/26/rapidity/comment-page-1/#comment-216084</link>
		<dc:creator>Tiago Sá</dc:creator>
		<pubDate>Tue, 30 Aug 2011 23:49:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.johnath.com/?p=657#comment-216084</guid>
		<description>Gervase Markham, I see. Thank you for point that out to me, I have heard about the UX-branch, I didn&#039;t know there were more...

I&#039;ll have to rethink my whole stance on the issue now. Have no idea what to think of it...</description>
		<content:encoded><![CDATA[<p>Gervase Markham, I see. Thank you for point that out to me, I have heard about the UX-branch, I didn&#8217;t know there were more&#8230;</p>
<p>I&#8217;ll have to rethink my whole stance on the issue now. Have no idea what to think of it&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Rapidity by Daniel Glazman</title>
		<link>http://blog.johnath.com/2011/08/26/rapidity/comment-page-1/#comment-216083</link>
		<dc:creator>Daniel Glazman</dc:creator>
		<pubDate>Tue, 30 Aug 2011 17:25:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.johnath.com/?p=657#comment-216083</guid>
		<description>@Randall: correct, but I still don&#039;t understand why there is a threat at all...</description>
		<content:encoded><![CDATA[<p>@Randall: correct, but I still don&#8217;t understand why there is a threat at all&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Rapidity by Randall "Texrat" Arnold</title>
		<link>http://blog.johnath.com/2011/08/26/rapidity/comment-page-1/#comment-216082</link>
		<dc:creator>Randall "Texrat" Arnold</dc:creator>
		<pubDate>Tue, 30 Aug 2011 08:17:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.johnath.com/?p=657#comment-216082</guid>
		<description>Daniel, being more interoperable than ever doesn&#039;t mean there&#039;s no threat...</description>
		<content:encoded><![CDATA[<p>Daniel, being more interoperable than ever doesn&#8217;t mean there&#8217;s no threat&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

