<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Black Hat 2008: Google Gadgets insecurity</title>
	<atom:link href="http://hackaday.com/2008/08/09/black-hat-2008-google-gadgets-insecurity/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com/2008/08/09/black-hat-2008-google-gadgets-insecurity/</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Wed, 25 Nov 2009 12:46:25 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: peruser</title>
		<link>http://hackaday.com/2008/08/09/black-hat-2008-google-gadgets-insecurity/comment-page-1/#comment-40329</link>
		<dc:creator>peruser</dc:creator>
		<pubDate>Mon, 11 Aug 2008 18:17:52 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/09/black-hat-2008-google-gadgets-insecurity/#comment-40329</guid>
		<description>how exactly is this a hack? &lt;br&gt;&lt;br&gt;I&#039;m sorry but maybe you guys should just change your name to engadget LITE...&lt;br&gt;&lt;br&gt;I know you just hired a lot of people to help the content flowing, but c&#039;mon Will, I come to this site for innovative hardware projects.  Not this &#039;latest google news&#039; crap.  I can go to any lamer Associated Press feed for this.  What&#039;s worse this isn&#039;t even &quot;news&quot;.  Google addressed this LAST YEAR.&lt;br&gt;&lt;br&gt;Please, I&#039;m begging you.  I&#039;ll take any hack at all.  Arduino, WRT, FPGAs, even NOACs.  &lt;br&gt;&lt;br&gt;</description>
		<content:encoded><![CDATA[<p>how exactly is this a hack? </p>
<p>I&#8217;m sorry but maybe you guys should just change your name to engadget LITE&#8230;</p>
<p>I know you just hired a lot of people to help the content flowing, but c&#8217;mon Will, I come to this site for innovative hardware projects.  Not this &#8216;latest google news&#8217; crap.  I can go to any lamer Associated Press feed for this.  What&#8217;s worse this isn&#8217;t even &#8220;news&#8221;.  Google addressed this LAST YEAR.</p>
<p>Please, I&#8217;m begging you.  I&#8217;ll take any hack at all.  Arduino, WRT, FPGAs, even NOACs.  </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Cutts</title>
		<link>http://hackaday.com/2008/08/09/black-hat-2008-google-gadgets-insecurity/comment-page-1/#comment-40328</link>
		<dc:creator>Matt Cutts</dc:creator>
		<pubDate>Sun, 10 Aug 2008 10:08:46 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/09/black-hat-2008-google-gadgets-insecurity/#comment-40328</guid>
		<description>(Disclosure: I&#039;m a software engineer at Google.)&lt;br&gt;&lt;br&gt;I think the AP story about this had more info from Google:&lt;br&gt;&lt;br&gt;&quot;Google disputes Hansen&#039;s characterization of its vetting process for gadgets.&lt;br&gt;&lt;br&gt;The company said in a statement that it scans all gadgets regularly for malicious code, and in the &quot;very rare&quot; instance in which one is found, it&#039;s immediately blacklisted.&lt;br&gt;&lt;br&gt;Google added that since November 2007 no new &quot;inline&quot; gadgets â which have access to user account information â have been created. And the authors of existing &quot;inline&quot; gadgets can&#039;t modify them further.&quot;&lt;br&gt;&lt;br&gt;I haven&#039;t been following this story, but if the vulnerability is only on inlined gadgets, it sounds like Google responded a while ago. See also&lt;br&gt;&lt;a href=&quot;http://groups.google.com/group/Google-Gadgets-API/browse_thread/thread/5776dc1be6dfd0b&quot; rel=&quot;nofollow&quot;&gt;http://groups.google.com/group/Google-Gadgets-API/browse_thread/thread/5776dc1be6dfd0b&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://igoogledeveloper.blogspot.com/2008/08/changes-to-inlined-gadgets.html&quot; rel=&quot;nofollow&quot;&gt;http://igoogledeveloper.blogspot.com/2008/08/changes-to-inlined-gadgets.html&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>(Disclosure: I&#8217;m a software engineer at Google.)</p>
<p>I think the AP story about this had more info from Google:</p>
<p>&#8220;Google disputes Hansen&#8217;s characterization of its vetting process for gadgets.</p>
<p>The company said in a statement that it scans all gadgets regularly for malicious code, and in the &#8220;very rare&#8221; instance in which one is found, it&#8217;s immediately blacklisted.</p>
<p>Google added that since November 2007 no new &#8220;inline&#8221; gadgets â which have access to user account information â have been created. And the authors of existing &#8220;inline&#8221; gadgets can&#8217;t modify them further.&#8221;</p>
<p>I haven&#8217;t been following this story, but if the vulnerability is only on inlined gadgets, it sounds like Google responded a while ago. See also<br /><a href="http://groups.google.com/group/Google-Gadgets-API/browse_thread/thread/5776dc1be6dfd0b" rel="nofollow">http://groups.google.com/group/Google-Gadgets-API/browse_thread/thread/5776dc1be6dfd0b</a><br /><a href="http://igoogledeveloper.blogspot.com/2008/08/changes-to-inlined-gadgets.html" rel="nofollow">http://igoogledeveloper.blogspot.com/2008/08/changes-to-inlined-gadgets.html</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
