Log in

View Full Version : Safari RSS Vulnerability Revealed


Vincent Ferrari
01-13-2009, 03:00 PM
<div class='os_post_top_link'><a href='http://www.tuaw.com/2009/01/13/safari-rss-vulnerability-might-reveal-your-personal-data/' target='_blank'>http://www.tuaw.com/2009/01/13/safa...-personal-data/</a><br /><br /></div><p><em>"In this case, the issue is that a hole in Safari's handling of RSS feeds could allow an attacker (via a malicious web page) to capture a user's personal information, cookies or even passwords. While Brian has not posted more details of the vulnerability publicly, he has acknowledgment from Apple that the issue exists; hopefully we will see an update soon that closes this hole. In the meantime, although Windows Safari users are advised to use a different browser to avoid the vulnerability, Mac users can simply set an alternative RSS feed handler to work around the issue."</em></p><p><img height="365" src="http://images.thoughtsmedia.com/resizer/thumbs/size/600/at/auto/1231847309.usr18053.jpg" width="365" /></p><p>If you use Safari for its RSS goodness, this one is pretty darned important, so beware for now.&nbsp; You may even consider switching to something else for your RSS needs until this is ironed out and patched.</p>

doogald
01-13-2009, 03:30 PM
While this is too bad, why in the world would you use Safai (or Mail) for RSS when there are some great web services like Google Reader (which supports Gears, so you can work offline, too) or Bloglines?

Spooof
01-13-2009, 03:43 PM
I have really never used Safari and do not even have it on my doc. I know many web sites can look great in Safari I am stuck in Firefox.

Vincent Ferrari
01-13-2009, 03:48 PM
While this is too bad, why in the world would you use Safai (or Mail) for RSS when there are some great web services like Google Reader (which supports Gears, so you can work offline, too) or Bloglines?

I know a couple of people who do out of sheer convenience (syncing bookmarks and such with the iPhone is usually the reason). I personally only use Google Reader. I used to use Bloglines but they suddenly stopped updating feeds regularly and I'm not a big fan of any of the Newsgator products either...

crimsonsky
01-13-2009, 06:24 PM
... I'm not a big fan of any of the Newsgator products either...

Interesting as I use Net News Wire on all my devices including my portable devices. I find it convenient primarily because of the synchronisation - keeps all my computers and gadgets in sync which is lovely.

I use Safari as my primary browser because I don't see any compelling reason to use any other. Firefox is good (better now than it ever has been on the Mac), but I'm not interested in using extensions so I just don't see any need to use it. I wouldn't think of using RSS in a browser - just too weak and feature lacking.