<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Discussion on Google Services in HTPPS | Userscripts.org</title>
    <link>http://userscripts.org/scripts/show/14161</link>
    <description>Recent comments on userscript: Google Services in HTPPS</description>
    <language>en-us</language>
    <ttl>60</ttl>
    <item>
      <title>Archived Comments, replied by Anmar Mansur</title>
      <description>&lt;p&gt;Victor, granted your script works in more cases than my &lt;a href=&quot;http://userscripts.org/scripts/show/10731&quot;&gt;Force HTTPS for GMail, GCal, and GDocs&lt;/a&gt; script, but yours only modifies the protocol to secure HTTPS after the page has loaded in non-secure HTTP and the damage was already done.&lt;/p&gt;

&lt;p&gt;In a man in the middle attack scenario, the attacker will obtain access to an authenticated session with your Google service of choice, while you unknowingly continue to use the service over HTTPS feeling (falsely) secure.&lt;/p&gt;

&lt;p&gt;I strongly suggest you modify your script or take it down immediately.&lt;/p&gt;</description>
      <pubDate>Mon, 28 Apr 2008 09:22:02 +0000</pubDate>
      <guid isPermaLink="false">userscripts.org:13997:47595</guid>
      <author>Anmar Mansur</author>
      <link>http://userscripts.org/posts/47595</link>
    </item>
    <item>
      <title>Archived Comments, replied by Jesse Andrews</title>
      <description>&lt;p&gt;The following is an archive of comments made before threaded discussions was implemented (November 16th, 2008)&lt;/p&gt;</description>
      <pubDate>Wed, 17 Nov 2004 01:05:16 +0000</pubDate>
      <guid isPermaLink="false">userscripts.org:13997:47594</guid>
      <author>Jesse Andrews</author>
      <link>http://userscripts.org/posts/47594</link>
    </item>
  </channel>
</rss>
