<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Commonwealth Insecurity: Banking over HTTP</title>
	<atom:link href="http://www.orzeszek.org/blog/2009/03/20/commonwealth-insecurity-banking-over-http/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.orzeszek.org/blog/2009/03/20/commonwealth-insecurity-banking-over-http/</link>
	<description>An inchoate upside-down perspective</description>
	<lastBuildDate>Tue, 09 Mar 2010 22:03:00 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Online broker CommSec criticised for weak passwords, lack of SSL &#124; Zero Day &#124; ZDNet.com</title>
		<link>http://www.orzeszek.org/blog/2009/03/20/commonwealth-insecurity-banking-over-http/comment-page-1/#comment-28</link>
		<dc:creator>Online broker CommSec criticised for weak passwords, lack of SSL &#124; Zero Day &#124; ZDNet.com</dc:creator>
		<pubDate>Wed, 29 Apr 2009 15:47:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.orzeszek.org/blog/?p=245#comment-28</guid>
		<description>[...] best practices come a month after another security design flaw was exposed at the online broker - CommSec’s use of non-SSL frames pages potentially resulting in successful man-in-the-middle attacks. Sadly, the company is also not [...]</description>
		<content:encoded><![CDATA[<p>[...] best practices come a month after another security design flaw was exposed at the online broker &#8211; CommSec’s use of non-SSL frames pages potentially resulting in successful man-in-the-middle attacks. Sadly, the company is also not [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Force CommSec to Use HTTPS with NoScript</title>
		<link>http://www.orzeszek.org/blog/2009/03/20/commonwealth-insecurity-banking-over-http/comment-page-1/#comment-10</link>
		<dc:creator>Force CommSec to Use HTTPS with NoScript</dc:creator>
		<pubDate>Wed, 08 Apr 2009 04:01:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.orzeszek.org/blog/?p=245#comment-10</guid>
		<description>[...] 20 March 2008, I wrote about CommSec’s use of non-SSL frames pages for its online banking. Although the CommSec homepage is delivered using SSL with an Extended [...]</description>
		<content:encoded><![CDATA[<p>[...] 20 March 2008, I wrote about CommSec’s use of non-SSL frames pages for its online banking. Although the CommSec homepage is delivered using SSL with an Extended [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
