<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: How to End Phishing With RSS</title>
	<atom:link href="http://www.hexten.net/2006/09/25/how-to-end-phishing-with-rss/feed" rel="self" type="application/rss+xml" />
	<link>http://www.hexten.net/2006/09/25/how-to-end-phishing-with-rss</link>
	<description>Better than Slashdot</description>
	<pubDate>Fri, 09 Jan 2009 10:32:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: Andy</title>
		<link>http://www.hexten.net/2006/09/25/how-to-end-phishing-with-rss#comment-3688</link>
		<dc:creator>Andy</dc:creator>
		<pubDate>Tue, 26 Sep 2006 08:04:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.hexten.net/?p=56#comment-3688</guid>
		<description>Hence offering it as an option - to wean people off email.

It only has to be as secure as email currently is - it's not going to be used for anything that they don't currently put in an email notification. Generating a random, unguessable feed URL gets you just about as much security as mail gives you.</description>
		<content:encoded><![CDATA[<p>Hence offering it as an option - to wean people off email.</p>
<p>It only has to be as secure as email currently is - it&#8217;s not going to be used for anything that they don&#8217;t currently put in an email notification. Generating a random, unguessable feed URL gets you just about as much security as mail gives you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Olly</title>
		<link>http://www.hexten.net/2006/09/25/how-to-end-phishing-with-rss#comment-3680</link>
		<dc:creator>Olly</dc:creator>
		<pubDate>Tue, 26 Sep 2006 00:28:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.hexten.net/?p=56#comment-3680</guid>
		<description>It's a great idea in theory, but I think it has a way to go before joe public can use it. To begin with, most users don't have a clue what an RSS/Atom feed is - hopefully the functionality in IE7/Safari/Firefox/Opera will go some way towards rectifying that.

Secondly, you need to deal with authentication - you don't really want your personal ebay / paypal / bank / etc account feed to be public, do you? The thing is, you can't do that until the most popular feed-readers support SSL, http-auth, etc. Some of the big names still don't.

Much more viable in the longer term methinks. Mind you, there's nothing to stop them implementing it now for the likes of you and me :)</description>
		<content:encoded><![CDATA[<p>It&#8217;s a great idea in theory, but I think it has a way to go before joe public can use it. To begin with, most users don&#8217;t have a clue what an RSS/Atom feed is - hopefully the functionality in IE7/Safari/Firefox/Opera will go some way towards rectifying that.</p>
<p>Secondly, you need to deal with authentication - you don&#8217;t really want your personal ebay / paypal / bank / etc account feed to be public, do you? The thing is, you can&#8217;t do that until the most popular feed-readers support SSL, http-auth, etc. Some of the big names still don&#8217;t.</p>
<p>Much more viable in the longer term methinks. Mind you, there&#8217;s nothing to stop them implementing it now for the likes of you and me :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
