<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Privacy Fail</title>
	<atom:link href="http://www.hrgeeks.com/2008/11/20/privacy-fail/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hrgeeks.com/2008/11/20/privacy-fail/</link>
	<description>Hampton Roads Geek community</description>
	<lastBuildDate>Sun, 15 Aug 2010 04:00:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Zackatoustra</title>
		<link>http://www.hrgeeks.com/2008/11/20/privacy-fail/comment-page-1/#comment-459</link>
		<dc:creator>Zackatoustra</dc:creator>
		<pubDate>Sat, 06 Feb 2010 15:57:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.hrgeeks.com/?p=106#comment-459</guid>
		<description>Thanks to LittleSnitch for warning us of that kind of &quot;undercover&quot; connections.
Thanks a bunch to you for  googling that issue for us, and bringing the answer to the community.

Back to LittleSnitch now and deny forever these certificate requests...</description>
		<content:encoded><![CDATA[<p>Thanks to LittleSnitch for warning us of that kind of &#8220;undercover&#8221; connections.<br />
Thanks a bunch to you for  googling that issue for us, and bringing the answer to the community.</p>
<p>Back to LittleSnitch now and deny forever these certificate requests&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JT</title>
		<link>http://www.hrgeeks.com/2008/11/20/privacy-fail/comment-page-1/#comment-448</link>
		<dc:creator>JT</dc:creator>
		<pubDate>Mon, 30 Nov 2009 13:47:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.hrgeeks.com/?p=106#comment-448</guid>
		<description>Camino also ends up with ocspd asking to connect to verisign. Probably because it&#039;s built off of Modzilla FF and/or Safari?

I set to deny on Little Snitch as well after reading the page (looking for what ocspd was). I&#039;ll probably switch it when I have to go to my bank site or something secure I suppose.</description>
		<content:encoded><![CDATA[<p>Camino also ends up with ocspd asking to connect to verisign. Probably because it&#8217;s built off of Modzilla FF and/or Safari?</p>
<p>I set to deny on Little Snitch as well after reading the page (looking for what ocspd was). I&#8217;ll probably switch it when I have to go to my bank site or something secure I suppose.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: adam</title>
		<link>http://www.hrgeeks.com/2008/11/20/privacy-fail/comment-page-1/#comment-340</link>
		<dc:creator>adam</dc:creator>
		<pubDate>Fri, 19 Jun 2009 22:44:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.hrgeeks.com/?p=106#comment-340</guid>
		<description>Well, that doesn&#039;t &#039;do&#039; much for you, as the entire point of OCSP is to validate the certificates you encounter when hitting SSL enabled sites.
If you just deny the connection each time, you can&#039;t validate the cert.

I&#039;d probably be ok with a published privacy policy dictating that the information disclosed via OCSP would never be used for any purpose beyond validation of a certificate in question.</description>
		<content:encoded><![CDATA[<p>Well, that doesn&#8217;t &#8216;do&#8217; much for you, as the entire point of OCSP is to validate the certificates you encounter when hitting SSL enabled sites.<br />
If you just deny the connection each time, you can&#8217;t validate the cert.</p>
<p>I&#8217;d probably be ok with a published privacy policy dictating that the information disclosed via OCSP would never be used for any purpose beyond validation of a certificate in question.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David</title>
		<link>http://www.hrgeeks.com/2008/11/20/privacy-fail/comment-page-1/#comment-337</link>
		<dc:creator>David</dc:creator>
		<pubDate>Tue, 16 Jun 2009 03:41:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.hrgeeks.com/?p=106#comment-337</guid>
		<description>COMMENTS PLEASE:I think this should be done but I am open to your comments:

Leave the &quot;safe browsing, alert for fraudulent websites&quot; on. Say no to it when it pops up in Little Snitch for sites you wish to remain private: peer to peer sites etc...

If you are going to a banking site you then will have it on for &quot;security&quot;
I presume OCSP does not compromise your secure online banking processes. (your thoughts)</description>
		<content:encoded><![CDATA[<p>COMMENTS PLEASE:I think this should be done but I am open to your comments:</p>
<p>Leave the &#8220;safe browsing, alert for fraudulent websites&#8221; on. Say no to it when it pops up in Little Snitch for sites you wish to remain private: peer to peer sites etc&#8230;</p>
<p>If you are going to a banking site you then will have it on for &#8220;security&#8221;<br />
I presume OCSP does not compromise your secure online banking processes. (your thoughts)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mary</title>
		<link>http://www.hrgeeks.com/2008/11/20/privacy-fail/comment-page-1/#comment-329</link>
		<dc:creator>Mary</dc:creator>
		<pubDate>Fri, 29 May 2009 15:35:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.hrgeeks.com/?p=106#comment-329</guid>
		<description>what do you mean by &quot;security&quot;? Isn&#039;t privacy going to be more important and aren&#039;t most of the sites out there having the same security issues? I use Noscript to try to protect my security and I am glad to know that my privacy was being violated. Unless I know of some other reason to allow it, I think I&#039;ll set little snitch to deny this.</description>
		<content:encoded><![CDATA[<p>what do you mean by &#8220;security&#8221;? Isn&#8217;t privacy going to be more important and aren&#8217;t most of the sites out there having the same security issues? I use Noscript to try to protect my security and I am glad to know that my privacy was being violated. Unless I know of some other reason to allow it, I think I&#8217;ll set little snitch to deny this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: McKs</title>
		<link>http://www.hrgeeks.com/2008/11/20/privacy-fail/comment-page-1/#comment-322</link>
		<dc:creator>McKs</dc:creator>
		<pubDate>Mon, 18 May 2009 18:42:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.hrgeeks.com/?p=106#comment-322</guid>
		<description>I&#039;m seeing the LS alert at regular intervals, browser running or not. Haven&#039;t been able to figure out what is requesting certificate verification on a such a regular bases, but I don&#039;t like (not knowing) it.
Also, I rarely use Safari, Camino being my default browser.</description>
		<content:encoded><![CDATA[<p>I&#8217;m seeing the LS alert at regular intervals, browser running or not. Haven&#8217;t been able to figure out what is requesting certificate verification on a such a regular bases, but I don&#8217;t like (not knowing) it.<br />
Also, I rarely use Safari, Camino being my default browser.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elmz</title>
		<link>http://www.hrgeeks.com/2008/11/20/privacy-fail/comment-page-1/#comment-321</link>
		<dc:creator>Elmz</dc:creator>
		<pubDate>Wed, 13 May 2009 15:33:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.hrgeeks.com/?p=106#comment-321</guid>
		<description>Thanks for the write up, I just ran into the exam same scenario.  I really liked using Safari but I guess I&#039;m going back to FF...</description>
		<content:encoded><![CDATA[<p>Thanks for the write up, I just ran into the exam same scenario.  I really liked using Safari but I guess I&#8217;m going back to FF&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bill</title>
		<link>http://www.hrgeeks.com/2008/11/20/privacy-fail/comment-page-1/#comment-320</link>
		<dc:creator>bill</dc:creator>
		<pubDate>Mon, 11 May 2009 18:18:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.hrgeeks.com/?p=106#comment-320</guid>
		<description>sounds like the better choice is just not to use safari.  then again, why would you, unless for testing.  thanks for the info!</description>
		<content:encoded><![CDATA[<p>sounds like the better choice is just not to use safari.  then again, why would you, unless for testing.  thanks for the info!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dvromeu</title>
		<link>http://www.hrgeeks.com/2008/11/20/privacy-fail/comment-page-1/#comment-274</link>
		<dc:creator>dvromeu</dc:creator>
		<pubDate>Tue, 03 Mar 2009 20:31:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.hrgeeks.com/?p=106#comment-274</guid>
		<description>I ended up here also after asking myself what exactly ocspd was and what it was doing...

Like you say, it&#039;s a choice between security and privacy...</description>
		<content:encoded><![CDATA[<p>I ended up here also after asking myself what exactly ocspd was and what it was doing&#8230;</p>
<p>Like you say, it&#8217;s a choice between security and privacy&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: adam</title>
		<link>http://www.hrgeeks.com/2008/11/20/privacy-fail/comment-page-1/#comment-244</link>
		<dc:creator>adam</dc:creator>
		<pubDate>Tue, 24 Feb 2009 12:06:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.hrgeeks.com/?p=106#comment-244</guid>
		<description>Depends on what is important to you - EV SSL certificates can&#039;t be verified without it.
It&#039;s the age old problem of trading security for privacy.</description>
		<content:encoded><![CDATA[<p>Depends on what is important to you &#8211; EV SSL certificates can&#8217;t be verified without it.<br />
It&#8217;s the age old problem of trading security for privacy.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
