<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Gmail Flaw can Give Anyone your Contact List</title>
	<atom:link href="http://cybernetnews.com/gmail-flaw-can-give-anyone-your-contact-list/feed/" rel="self" type="application/rss+xml" />
	<link>http://cybernetnews.com/gmail-flaw-can-give-anyone-your-contact-list/</link>
	<description>Technology News</description>
	<lastBuildDate>Sun, 08 Nov 2009 20:26:55 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: //M-Tech Development Blog &#187; Gmail Hackable?</title>
		<link>http://cybernetnews.com/gmail-flaw-can-give-anyone-your-contact-list/comment-page-1/#comment-68233</link>
		<dc:creator>//M-Tech Development Blog &#187; Gmail Hackable?</dc:creator>
		<pubDate>Wed, 03 Jan 2007 02:18:02 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2007/01/01/gmail-flaw-can-give-anyone-your-contact-list/#comment-68233</guid>
		<description>[...] More bad news for Google: Gmail is vulnerable to a hack which enables malicious websites to hijack your contacts list, including the name, email address and avatar of all your contacts. Google claims to have fixed the flaw, but apparently it still exists on the Google Notebook and Google Groups server. What do you think? Post your comments! [...]</description>
		<content:encoded><![CDATA[<p>[...] More bad news for Google: Gmail is vulnerable to a hack which enables malicious websites to hijack your contacts list, including the name, email address and avatar of all your contacts. Google claims to have fixed the flaw, but apparently it still exists on the Google Notebook and Google Groups server. What do you think? Post your comments! [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: natmaster</title>
		<link>http://cybernetnews.com/gmail-flaw-can-give-anyone-your-contact-list/comment-page-1/#comment-67076</link>
		<dc:creator>natmaster</dc:creator>
		<pubDate>Tue, 02 Jan 2007 02:27:12 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2007/01/01/gmail-flaw-can-give-anyone-your-contact-list/#comment-67076</guid>
		<description>Not ironic...more like insult to injury.</description>
		<content:encoded><![CDATA[<p>Not ironic&#8230;more like insult to injury.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://cybernetnews.com/gmail-flaw-can-give-anyone-your-contact-list/comment-page-1/#comment-66917</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Mon, 01 Jan 2007 21:31:54 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2007/01/01/gmail-flaw-can-give-anyone-your-contact-list/#comment-66917</guid>
		<description>&lt;div id=&quot;commentquote&quot;&gt;&lt;a href=&quot;#comment-66906&quot;&gt;ClausValca wrote:&lt;/a&gt;&lt;blockquote&gt;In fact,  I do that anyway for just about all the &quot;medium security&quot; sites when I browse except for just a handful of &quot;low-security&quot; forum sites that I just generally stay logged into at all times.  &quot;High-security&quot; sites (related to on-line banking activities) always get a new browser window...login...perform the activity...logout...delete cache/forms...close browser..then reopen a fresh browser session for regular web surfing again.  Do others to that as well?&lt;/blockquote&gt;&lt;/div&gt;
I haven&#039;t gone to those extremes but I have to admit that it&#039;s a good idea. I may have to start doing things like that as well.</description>
		<content:encoded><![CDATA[<div id="commentquote"><a href="#comment-66906">ClausValca wrote:</a><br />
<blockquote>In fact,  I do that anyway for just about all the &#8220;medium security&#8221; sites when I browse except for just a handful of &#8220;low-security&#8221; forum sites that I just generally stay logged into at all times.  &#8220;High-security&#8221; sites (related to on-line banking activities) always get a new browser window&#8230;login&#8230;perform the activity&#8230;logout&#8230;delete cache/forms&#8230;close browser..then reopen a fresh browser session for regular web surfing again.  Do others to that as well?</p></blockquote>
</div>
<p>I haven&#8217;t gone to those extremes but I have to admit that it&#8217;s a good idea. I may have to start doing things like that as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ClausValca</title>
		<link>http://cybernetnews.com/gmail-flaw-can-give-anyone-your-contact-list/comment-page-1/#comment-66906</link>
		<dc:creator>ClausValca</dc:creator>
		<pubDate>Mon, 01 Jan 2007 21:13:19 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2007/01/01/gmail-flaw-can-give-anyone-your-contact-list/#comment-66906</guid>
		<description>I must agree with OldManDeath&#039;s suggestion.

Since I have come to depend a great deal on the Google resources...and have been a bit paranoid about an exploit like that occurring...I have always been in the habit of fully logging out of any Google/Blogger/Gmail/etc. resource when I am done.

In fact,  I do that anyway for just about all the &quot;medium security&quot; sites when I browse except for just a handful of &quot;low-security&quot; forum sites that I just generally stay logged into at all times.  &quot;High-security&quot; sites (related to on-line banking activities) always get a new browser window...login...perform the activity...logout...delete cache/forms...close browser..then reopen a fresh browser session for regular web surfing again.  Do others to that as well?

It&#039;s not quite as convenient, but (I hope) more secure.

Then again, now that tabbed browsing is pretty common in FF and IE7, I guess I have to be that much more careful that opening any additional site-pages while I am signed in to my Google accounts.</description>
		<content:encoded><![CDATA[<p>I must agree with OldManDeath&#8217;s suggestion.</p>
<p>Since I have come to depend a great deal on the Google resources&#8230;and have been a bit paranoid about an exploit like that occurring&#8230;I have always been in the habit of fully logging out of any Google/Blogger/Gmail/etc. resource when I am done.</p>
<p>In fact,  I do that anyway for just about all the &#8220;medium security&#8221; sites when I browse except for just a handful of &#8220;low-security&#8221; forum sites that I just generally stay logged into at all times.  &#8220;High-security&#8221; sites (related to on-line banking activities) always get a new browser window&#8230;login&#8230;perform the activity&#8230;logout&#8230;delete cache/forms&#8230;close browser..then reopen a fresh browser session for regular web surfing again.  Do others to that as well?</p>
<p>It&#8217;s not quite as convenient, but (I hope) more secure.</p>
<p>Then again, now that tabbed browsing is pretty common in FF and IE7, I guess I have to be that much more careful that opening any additional site-pages while I am signed in to my Google accounts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lewis</title>
		<link>http://cybernetnews.com/gmail-flaw-can-give-anyone-your-contact-list/comment-page-1/#comment-66902</link>
		<dc:creator>Lewis</dc:creator>
		<pubDate>Mon, 01 Jan 2007 21:09:42 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2007/01/01/gmail-flaw-can-give-anyone-your-contact-list/#comment-66902</guid>
		<description>You just have to be logged in to a Gmail service on your browser.

I didn&#039;t worry about clicking that link, as it&#039;s my contacts that would have been spammed :P</description>
		<content:encoded><![CDATA[<p>You just have to be logged in to a Gmail service on your browser.</p>
<p>I didn&#8217;t worry about clicking that link, as it&#8217;s my contacts that would have been spammed <img src='http://cybernetnews.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://cybernetnews.com/gmail-flaw-can-give-anyone-your-contact-list/comment-page-1/#comment-66873</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Mon, 01 Jan 2007 19:51:50 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2007/01/01/gmail-flaw-can-give-anyone-your-contact-list/#comment-66873</guid>
		<description>It works fine for me without having any of the things open...except I have Google Talk but I wouldn&#039;t think that an application could affect it.</description>
		<content:encoded><![CDATA[<p>It works fine for me without having any of the things open&#8230;except I have Google Talk but I wouldn&#8217;t think that an application could affect it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OldManDeath</title>
		<link>http://cybernetnews.com/gmail-flaw-can-give-anyone-your-contact-list/comment-page-1/#comment-66862</link>
		<dc:creator>OldManDeath</dc:creator>
		<pubDate>Mon, 01 Jan 2007 19:35:33 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2007/01/01/gmail-flaw-can-give-anyone-your-contact-list/#comment-66862</guid>
		<description>This shows everything associated with a contact, phone numbers, addresses, etc.

I have heard that for this to be exploited, you have to have one of your Google resources (Gmail, Calendar, etc.) running while you are browsing the web.  If you hit a website that is exploiting this with one of those other resources open, then the exploit will work and your contact information will be taken.

I guess I need to get into the habit of closing Gmail when I am browsing the web as I normally leave it open.</description>
		<content:encoded><![CDATA[<p>This shows everything associated with a contact, phone numbers, addresses, etc.</p>
<p>I have heard that for this to be exploited, you have to have one of your Google resources (Gmail, Calendar, etc.) running while you are browsing the web.  If you hit a website that is exploiting this with one of those other resources open, then the exploit will work and your contact information will be taken.</p>
<p>I guess I need to get into the habit of closing Gmail when I am browsing the web as I normally leave it open.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
