<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Client-Side protection from XSS</title>
	<atom:link href="http://kyran.wordpress.com/2006/10/11/client-side-protection-from-xss/feed/" rel="self" type="application/rss+xml" />
	<link>http://kyran.wordpress.com/2006/10/11/client-side-protection-from-xss/</link>
	<description>Security, Technology and Life</description>
	<lastBuildDate>Sun, 21 Dec 2008 13:05:46 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Brian</title>
		<link>http://kyran.wordpress.com/2006/10/11/client-side-protection-from-xss/#comment-2</link>
		<dc:creator>Brian</dc:creator>
		<pubDate>Fri, 13 Oct 2006 21:05:29 +0000</pubDate>
		<guid isPermaLink="false">http://kyran.wordpress.com/2006/10/11/client-side-protection-from-xss/#comment-2</guid>
		<description>I think browsers are going to need to help with the reflected XSS and CSRF problems.  I posted a proposal on how web sites could tell browsers what kind of cross-site linking was expected to the webappsec list at one point, and it turned out that Ivan Ristic had written up some notes in a similar vein (only his ideas go much further...)

CSL Policy: http://www.webappsec.org/lists/websecurity/archive/2006-06/msg00070.html

Secure Browsing Mode:
http://www.webappsec.org/lists/websecurity/archive/2006-06/msg00085.html</description>
		<content:encoded><![CDATA[<p>I think browsers are going to need to help with the reflected XSS and CSRF problems.  I posted a proposal on how web sites could tell browsers what kind of cross-site linking was expected to the webappsec list at one point, and it turned out that Ivan Ristic had written up some notes in a similar vein (only his ideas go much further&#8230;)</p>
<p>CSL Policy: <a href="http://www.webappsec.org/lists/websecurity/archive/2006-06/msg00070.html" rel="nofollow">http://www.webappsec.org/lists/websecurity/archive/2006-06/msg00070.html</a></p>
<p>Secure Browsing Mode:<br />
<a href="http://www.webappsec.org/lists/websecurity/archive/2006-06/msg00085.html" rel="nofollow">http://www.webappsec.org/lists/websecurity/archive/2006-06/msg00085.html</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
