Securing feed enclosures

Greetings, I am one of the developers on the RSS team, and to complement Sean’s and Walter’s recent postings on feed security, I would like to talk about one topic that didn’t get as much attention in recent discussions on feed security as perhaps it should have – feed enclosures. Enclosures are files “attached” to…

24

More on Feed Security

Shortly after the SPI Dynamics presentation that sparked a renewed discussion on feed security in the community last month, James Snell developed a suite of tests (based on an earlier set by James Holderness), and generously made them available quietly to aggregator developers. He has now made the tests public. I contacted James last month (via…

13

Script in Feeds

You might have read the c|net article “Blog feeds may carry security risk” which summarizes the presentation given by Robert Auger and Caleb Sima of SPI Dynamics. The presentation points to potential dangers of malicious script embedded in feeds. This has sparked some discussion in the community. We think it’s good for the RSS community and…

21