<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: WordPress Security : User account details at risk</title>
	<atom:link href="http://cuasan.wordpress.com/2007/10/05/insecurepresscom/feed/" rel="self" type="application/rss+xml" />
	<link>http://cuasan.wordpress.com/2007/10/05/insecurepresscom/</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Thu, 05 Nov 2009 08:02:05 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: dmom</title>
		<link>http://cuasan.wordpress.com/2007/10/05/insecurepresscom/#comment-69</link>
		<dc:creator>dmom</dc:creator>
		<pubDate>Mon, 09 Jun 2008 20:26:16 +0000</pubDate>
		<guid isPermaLink="false">http://cuasan.wordpress.com/2007/10/05/insecurepresscom/#comment-69</guid>
		<description>I never received a response from wordpress.
I have re-checked their landing page over the last few months, and indeed the login form is deferring to a secure location via a HTTP POST to a HTTPS URI.</description>
		<content:encoded><![CDATA[<p>I never received a response from wordpress.<br />
I have re-checked their landing page over the last few months, and indeed the login form is deferring to a secure location via a HTTP POST to a HTTPS URI.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Secure Wordpress.com login &#171; RoundPicture</title>
		<link>http://cuasan.wordpress.com/2007/10/05/insecurepresscom/#comment-68</link>
		<dc:creator>Secure Wordpress.com login &#171; RoundPicture</dc:creator>
		<pubDate>Sat, 07 Jun 2008 20:47:22 +0000</pubDate>
		<guid isPermaLink="false">http://cuasan.wordpress.com/2007/10/05/insecurepresscom/#comment-68</guid>
		<description>[...] http://cuasan.wordpress.com/2007/10/05/insecurepresscom/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://cuasan.wordpress.com/2007/10/05/insecurepresscom/" rel="nofollow">http://cuasan.wordpress.com/2007/10/05/insecurepresscom/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Secure Wordpress.com login &#171; LifelongPassion</title>
		<link>http://cuasan.wordpress.com/2007/10/05/insecurepresscom/#comment-58</link>
		<dc:creator>Secure Wordpress.com login &#171; LifelongPassion</dc:creator>
		<pubDate>Mon, 05 May 2008 18:55:23 +0000</pubDate>
		<guid isPermaLink="false">http://cuasan.wordpress.com/2007/10/05/insecurepresscom/#comment-58</guid>
		<description>[...] http://cuasan.wordpress.com/2007/10/05/insecurepresscom/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://cuasan.wordpress.com/2007/10/05/insecurepresscom/" rel="nofollow">http://cuasan.wordpress.com/2007/10/05/insecurepresscom/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dmom</title>
		<link>http://cuasan.wordpress.com/2007/10/05/insecurepresscom/#comment-15</link>
		<dc:creator>dmom</dc:creator>
		<pubDate>Tue, 13 Nov 2007 13:33:44 +0000</pubDate>
		<guid isPermaLink="false">http://cuasan.wordpress.com/2007/10/05/insecurepresscom/#comment-15</guid>
		<description>omg, I see today, unfortunately, at http://wordpress.com/blog/2007/03/06/openid/ that people can use their wordpress blog as an openID. 
Without a secure login capabiliity at wordpress.com, this is just nuts ! Now, in addition to an insecure blog, you have a bunch of insecure services online because your openID provider is insecure. Crazy crazy crazy.

Wordpress.com, where are you ?
What say you about the insecure login ?</description>
		<content:encoded><![CDATA[<p>omg, I see today, unfortunately, at <a href="http://wordpress.com/blog/2007/03/06/openid/" rel="nofollow">http://wordpress.com/blog/2007/03/06/openid/</a> that people can use their wordpress blog as an openID.<br />
Without a secure login capabiliity at wordpress.com, this is just nuts ! Now, in addition to an insecure blog, you have a bunch of insecure services online because your openID provider is insecure. Crazy crazy crazy.</p>
<p>WordPress.com, where are you ?<br />
What say you about the insecure login ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dmom</title>
		<link>http://cuasan.wordpress.com/2007/10/05/insecurepresscom/#comment-14</link>
		<dc:creator>dmom</dc:creator>
		<pubDate>Wed, 31 Oct 2007 11:09:22 +0000</pubDate>
		<guid isPermaLink="false">http://cuasan.wordpress.com/2007/10/05/insecurepresscom/#comment-14</guid>
		<description>I have updated this post today with the ddetails of the login form link and the image snapshot of the warning firefox gives me when i go to login.

For some reason, I don&#039;t see this pop-up consistently, which is further cause for worry.

So far I have no response from wordpress regarding this issue and slahsdot have rejected my posting of this issue.</description>
		<content:encoded><![CDATA[<p>I have updated this post today with the ddetails of the login form link and the image snapshot of the warning firefox gives me when i go to login.</p>
<p>For some reason, I don&#8217;t see this pop-up consistently, which is further cause for worry.</p>
<p>So far I have no response from wordpress regarding this issue and slahsdot have rejected my posting of this issue.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dmom</title>
		<link>http://cuasan.wordpress.com/2007/10/05/insecurepresscom/#comment-13</link>
		<dc:creator>dmom</dc:creator>
		<pubDate>Fri, 26 Oct 2007 10:29:29 +0000</pubDate>
		<guid isPermaLink="false">http://cuasan.wordpress.com/2007/10/05/insecurepresscom/#comment-13</guid>
		<description>I have reported this to wordpress, as I&#039;ve just tried it again and it&#039;s still unsecure.

I captured some data from the transfer from when I hit the &#039;login&#039; button on the page.


log=my-fake-user-name&amp;pwd=top+secret&amp;testcookie=1&amp;submit=LoginHTTP/1.1 200 OK
Vary: Cookie
X-hacker: If you&#039;re reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.
</description>
		<content:encoded><![CDATA[<p>I have reported this to wordpress, as I&#8217;ve just tried it again and it&#8217;s still unsecure.</p>
<p>I captured some data from the transfer from when I hit the &#8216;login&#8217; button on the page.</p>
<p>log=my-fake-user-name&amp;pwd=top+secret&amp;testcookie=1&amp;submit=LoginHTTP/1.1 200 OK<br />
Vary: Cookie<br />
X-hacker: If you&#8217;re reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
