<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Google&#8217;s Safe Browsing built into Firefox 2</title>
	<link>http://garrettgee.com/2007/01/14/googles-safe-browsing-built-into-firefox-2/</link>
	<description>Confessions of an Information Addict</description>
	<pubDate>Wed, 07 Jan 2009 06:47:02 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: Google’s Anti-Phishing Blacklist Leaked Passwords at Garrett Gee</title>
		<link>http://garrettgee.com/2007/01/14/googles-safe-browsing-built-into-firefox-2/#comment-7</link>
		<dc:creator>Google’s Anti-Phishing Blacklist Leaked Passwords at Garrett Gee</dc:creator>
		<pubDate>Mon, 29 Jan 2007 01:13:54 +0000</pubDate>
		<guid>http://garrettgee.com/2007/01/14/googles-safe-browsing-built-into-firefox-2/#comment-7</guid>
		<description>[...] But what is this blacklist and how did the data get there? The blacklist is a list of url&#8217;s that Google classified as a phishing site, which would help end users avoid fraud. So how does google determine this, and how is that data getting transfered? Nitesh Dhanjani has a pretty good writeup about this over at Oreilly. We know that information is getting transfered to google via the safe-browsing extension, but which version is vulnerable to this? The downloadable Google Toolbar has one version, the Firefox extension has another version, and Firefox 2 has a built in version. And as to how the data got there, that was due to poor design from the website(s). The username and password were in the url, and since the extension sends whole urls, that data ended up on Google&#8217;s blacklist. I didn&#8217;t even think people coded sites in this way anymore! [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] But what is this blacklist and how did the data get there? The blacklist is a list of url&#8217;s that Google classified as a phishing site, which would help end users avoid fraud. So how does google determine this, and how is that data getting transfered? Nitesh Dhanjani has a pretty good writeup about this over at Oreilly. We know that information is getting transfered to google via the safe-browsing extension, but which version is vulnerable to this? The downloadable Google Toolbar has one version, the Firefox extension has another version, and Firefox 2 has a built in version. And as to how the data got there, that was due to poor design from the website(s). The username and password were in the url, and since the extension sends whole urls, that data ended up on Google&#8217;s blacklist. I didn&#8217;t even think people coded sites in this way anymore! [&#8230;]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
