<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Safe JSON</title>
	<atom:link href="http://robubu.com/?feed=rss2&#038;p=24" rel="self" type="application/rss+xml" />
	<link>http://robubu.com/?p=24</link>
	<description>the weblog of Rob Yates</description>
	<lastBuildDate>Sat, 14 Aug 2010 17:34:10 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: JavaScript Vulnerabilities &#8211; From GWT(Google web toolkit) &#124; Little knowledge is dangerous</title>
		<link>http://robubu.com/?p=24&#038;cpage=1#comment-90641</link>
		<dc:creator>JavaScript Vulnerabilities &#8211; From GWT(Google web toolkit) &#124; Little knowledge is dangerous</dc:creator>
		<pubDate>Thu, 29 Jul 2010 01:05:39 +0000</pubDate>
		<guid isPermaLink="false">http://robubu.com/?p=24#comment-90641</guid>
		<description>[...] Safe JSON [...]</description>
		<content:encoded><![CDATA[<p>[...] Safe JSON [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JSON is not as safe as people think it is &#171; Dogfeeds——IT Telescope</title>
		<link>http://robubu.com/?p=24&#038;cpage=1#comment-72185</link>
		<dc:creator>JSON is not as safe as people think it is &#171; Dogfeeds——IT Telescope</dc:creator>
		<pubDate>Wed, 10 Jun 2009 03:44:48 +0000</pubDate>
		<guid isPermaLink="false">http://robubu.com/?p=24#comment-72185</guid>
		<description>[...] saw some discussion recently about using JSON for secured data, and I&#8217;m not sure that everyone understands the [...]</description>
		<content:encoded><![CDATA[<p>[...] saw some discussion recently about using JSON for secured data, and I&#8217;m not sure that everyone understands the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tagz &#124; &#34;robubu » Safe JSON&#34; &#124; Comments</title>
		<link>http://robubu.com/?p=24&#038;cpage=1#comment-71615</link>
		<dc:creator>Tagz &#124; &#34;robubu » Safe JSON&#34; &#124; Comments</dc:creator>
		<pubDate>Sat, 16 May 2009 17:07:35 +0000</pubDate>
		<guid isPermaLink="false">http://robubu.com/?p=24#comment-71615</guid>
		<description></description>
		<content:encoded><![CDATA[<p>[...]               [upmod] [downmod]     robubu » Safe JSON  (robubu.com)    0 points posted 10 months, 1 week ago by jeethu  tags webdev json javascript [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David-Sarah Hopwood</title>
		<link>http://robubu.com/?p=24&#038;cpage=1#comment-65698</link>
		<dc:creator>David-Sarah Hopwood</dc:creator>
		<pubDate>Tue, 20 Jan 2009 07:28:34 +0000</pubDate>
		<guid isPermaLink="false">http://robubu.com/?p=24#comment-65698</guid>
		<description>&quot;The attack that was used in the post you referenced relied on the JSON being in ().&quot;

No it didn&#039;t, as far as I can see.</description>
		<content:encoded><![CDATA[<p>&#8220;The attack that was used in the post you referenced relied on the JSON being in ().&#8221;</p>
<p>No it didn&#8217;t, as far as I can see.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Yates</title>
		<link>http://robubu.com/?p=24&#038;cpage=1#comment-39638</link>
		<dc:creator>Rob Yates</dc:creator>
		<pubDate>Sun, 11 May 2008 23:18:50 +0000</pubDate>
		<guid isPermaLink="false">http://robubu.com/?p=24#comment-39638</guid>
		<description>David-Sarah,


it&#039;s not out of date yet.  The attack that was used in the post you referenced relied on the JSON being in ().</description>
		<content:encoded><![CDATA[<p>David-Sarah,</p>
<p>it&#8217;s not out of date yet.  The attack that was used in the post you referenced relied on the JSON being in ().</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David-Sarah Hopwood</title>
		<link>http://robubu.com/?p=24&#038;cpage=1#comment-39133</link>
		<dc:creator>David-Sarah Hopwood</dc:creator>
		<pubDate>Wed, 07 May 2008 00:37:14 +0000</pubDate>
		<guid isPermaLink="false">http://robubu.com/?p=24#comment-39133</guid>
		<description>So, given http://getahead.org/blog/joe/2007/03/06/json_is_not_as_safe_as_people_think_it_is_part_2.html
isn&#039;t the advice to use a &quot;Serialized Object&quot; rather than &quot;Array&quot; at the top-level, completely out-of-date?</description>
		<content:encoded><![CDATA[<p>So, given <a href="http://getahead.org/blog/joe/2007/03/06/json_is_not_as_safe_as_people_think_it_is_part_2.html" rel="nofollow">http://getahead.org/blog/joe/2007/03/06/json_is_not_as_safe_as_people_think_it_is_part_2.html</a><br />
isn&#8217;t the advice to use a &#8220;Serialized Object&#8221; rather than &#8220;Array&#8221; at the top-level, completely out-of-date?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bram.us &#187; My note to myself : Prototype.js vs. JSON.js : 1 - 0 (or JSON.js considered evil)</title>
		<link>http://robubu.com/?p=24&#038;cpage=1#comment-13233</link>
		<dc:creator>Bram.us &#187; My note to myself : Prototype.js vs. JSON.js : 1 - 0 (or JSON.js considered evil)</dc:creator>
		<pubDate>Mon, 04 Jun 2007 19:21:12 +0000</pubDate>
		<guid isPermaLink="false">http://robubu.com/?p=24#comment-13233</guid>
		<description>[...] with the same issues out there! Don&#8217;t get me wrong, I&#8217;m not considering JSON dangerous (is it?) as JSON greatly has improved my life as a webnerd, but merely am condemning the javascript [...]</description>
		<content:encoded><![CDATA[<p>[...] with the same issues out there! Don&#8217;t get me wrong, I&#8217;m not considering JSON dangerous (is it?) as JSON greatly has improved my life as a webnerd, but merely am condemning the javascript [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jaisen's Blog</title>
		<link>http://robubu.com/?p=24&#038;cpage=1#comment-7709</link>
		<dc:creator>Jaisen's Blog</dc:creator>
		<pubDate>Thu, 12 Apr 2007 15:37:38 +0000</pubDate>
		<guid isPermaLink="false">http://robubu.com/?p=24#comment-7709</guid>
		<description>&lt;strong&gt;Securing apps that use JSON...&lt;/strong&gt;

Douglas Crockford (wikidpedia) wrote a blog post on the Yahoo! User Interface Blog about securing web applications that use JSON.&#160; The insecurity of JSON has been a hot topic on numerous blogs (here, here and here).&#160;In Douglas&#039; blog post he....</description>
		<content:encoded><![CDATA[<p><strong>Securing apps that use JSON&#8230;</strong></p>
<p>Douglas Crockford (wikidpedia) wrote a blog post on the Yahoo! User Interface Blog about securing web applications that use JSON.&nbsp; The insecurity of JSON has been a hot topic on numerous blogs (here, here and here).&nbsp;In Douglas&#8217; blog post he&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jpsykes &#187; Practical CSRF and JSON Security</title>
		<link>http://robubu.com/?p=24&#038;cpage=1#comment-5765</link>
		<dc:creator>jpsykes &#187; Practical CSRF and JSON Security</dc:creator>
		<pubDate>Wed, 21 Mar 2007 18:28:01 +0000</pubDate>
		<guid isPermaLink="false">http://robubu.com/?p=24#comment-5765</guid>
		<description>[...] For some reason Q1 2007 was JSON security panic quarter. The web is a light with blog posts, discussion forum hysteria, tech. articles about JSON. The debate is swinging back and forth. But what does it all mean, what is CSFR. [...]</description>
		<content:encoded><![CDATA[<p>[...] For some reason Q1 2007 was JSON security panic quarter. The web is a light with blog posts, discussion forum hysteria, tech. articles about JSON. The debate is swinging back and forth. But what does it all mean, what is CSFR. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jpsykes &#187; From March 14th to March 15th I looked at&#8230;</title>
		<link>http://robubu.com/?p=24&#038;cpage=1#comment-5708</link>
		<dc:creator>jpsykes &#187; From March 14th to March 15th I looked at&#8230;</dc:creator>
		<pubDate>Tue, 20 Mar 2007 17:19:36 +0000</pubDate>
		<guid isPermaLink="false">http://robubu.com/?p=24#comment-5708</guid>
		<description>[...] Safe JSON [...]</description>
		<content:encoded><![CDATA[<p>[...] Safe JSON [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
