<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Security in Syndicated and Federated Systems</title>
	<atom:link href="http://theharmonyguy.com/2009/12/08/security-in-syndicated-and-federated-systems/feed/" rel="self" type="application/rss+xml" />
	<link>http://theharmonyguy.com/2009/12/08/security-in-syndicated-and-federated-systems/</link>
	<description>Investigating privacy and security issues in online social networking</description>
	<lastBuildDate>Thu, 09 Feb 2012 10:47:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: LeLelia</title>
		<link>http://theharmonyguy.com/2009/12/08/security-in-syndicated-and-federated-systems/comment-page-1/#comment-35062</link>
		<dc:creator>LeLelia</dc:creator>
		<pubDate>Mon, 05 Sep 2011 04:09:40 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=576#comment-35062</guid>
		<description>Houses are expensive and not everybody can buy it. But, &lt;a href=&quot;http://bestfinance-blog.com/topics/business-loans&quot; rel=&quot;nofollow&quot;&gt;business loans&lt;/a&gt; was invented to aid different people in such kind of hard situations.</description>
		<content:encoded><![CDATA[<p>Houses are expensive and not everybody can buy it. But, <a href="http://bestfinance-blog.com/topics/business-loans" rel="nofollow">business loans</a> was invented to aid different people in such kind of hard situations.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan A</title>
		<link>http://theharmonyguy.com/2009/12/08/security-in-syndicated-and-federated-systems/comment-page-1/#comment-7453</link>
		<dc:creator>Ryan A</dc:creator>
		<pubDate>Wed, 09 Dec 2009 17:41:47 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=576#comment-7453</guid>
		<description>The issue mentioned with executing content remotely when it was sourced from another application is not a difficult problem to fix. I&#039;ve seen this a number of times when rendering CDATA content with XSL; no matter how the content is enclosed/sanitized, CDATA and notably disable-output-escaping needs output sanitizing as well.

I&#039;d be interested in your brewing article, &quot;In Defense of Walled-Gardens.&quot; I am not for these large centralized services with user lock-in, and federation is an appealing concept, be it an old concept when we look at email. The benefit is openness and detachedness.

I can&#039;t say how many times I&#039;ve wanted to post a reply to a number forums topics, but am unable without registering and logging in. The issue is, I don&#039;t want multiple accounts on services with redundant functionality. Social networks are a great example because they generally all provide the same features, but each requires usership to interact, they are all closed communities.

If you do write the article, I hope to see some analysis of the OpenMicroblogging specification, which imo is a decent open solution, and I think it keys on the main factor federated social system must rely on for &quot;security&quot; and that is the social relation opt-in. A user subscribing to another [possibly federated] user&#039;s content is making that decision, essentially yielding authorization for a publisher to post to the subscriber&#039;s inbox. If the publisher decides to exploit this fact, or is compromised, what is the exact security threat? I believe it varies between systems, especially when comparing OMB and Wave.

OMB is generally rendered in one specific way, while Wave will allow self-defined rendering with widgets/html/js/css. In that light, I don&#039;t necessarily feel the architecture is a threat, but I do think the content possibilities need a sanitizing method at a more fundamental level in the overall system.

Federation is a long-standing, open solution, email proves that. When the concept of &quot;walled gardens&quot; expires and the focus shifts to federated solutions, I think we will have the right answers.

This is why I enjoy the best open+social community, the blogosphere.</description>
		<content:encoded><![CDATA[<p>The issue mentioned with executing content remotely when it was sourced from another application is not a difficult problem to fix. I&#8217;ve seen this a number of times when rendering CDATA content with XSL; no matter how the content is enclosed/sanitized, CDATA and notably disable-output-escaping needs output sanitizing as well.</p>
<p>I&#8217;d be interested in your brewing article, &#8220;In Defense of Walled-Gardens.&#8221; I am not for these large centralized services with user lock-in, and federation is an appealing concept, be it an old concept when we look at email. The benefit is openness and detachedness.</p>
<p>I can&#8217;t say how many times I&#8217;ve wanted to post a reply to a number forums topics, but am unable without registering and logging in. The issue is, I don&#8217;t want multiple accounts on services with redundant functionality. Social networks are a great example because they generally all provide the same features, but each requires usership to interact, they are all closed communities.</p>
<p>If you do write the article, I hope to see some analysis of the OpenMicroblogging specification, which imo is a decent open solution, and I think it keys on the main factor federated social system must rely on for &#8220;security&#8221; and that is the social relation opt-in. A user subscribing to another [possibly federated] user&#8217;s content is making that decision, essentially yielding authorization for a publisher to post to the subscriber&#8217;s inbox. If the publisher decides to exploit this fact, or is compromised, what is the exact security threat? I believe it varies between systems, especially when comparing OMB and Wave.</p>
<p>OMB is generally rendered in one specific way, while Wave will allow self-defined rendering with widgets/html/js/css. In that light, I don&#8217;t necessarily feel the architecture is a threat, but I do think the content possibilities need a sanitizing method at a more fundamental level in the overall system.</p>
<p>Federation is a long-standing, open solution, email proves that. When the concept of &#8220;walled gardens&#8221; expires and the focus shifts to federated solutions, I think we will have the right answers.</p>
<p>This is why I enjoy the best open+social community, the blogosphere.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security in Syndicated and Federated Systems &#124; Social Hacking Search Engine</title>
		<link>http://theharmonyguy.com/2009/12/08/security-in-syndicated-and-federated-systems/comment-page-1/#comment-7430</link>
		<dc:creator>Security in Syndicated and Federated Systems &#124; Social Hacking Search Engine</dc:creator>
		<pubDate>Wed, 09 Dec 2009 09:26:22 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=576#comment-7430</guid>
		<description>[...] the rest here: Security in Syndicated and Federated Systems &#124; Social Hacking          By admin &#124; category: Cuil, search engine &#124; tags: Cuil, facebook, friends, [...]</description>
		<content:encoded><![CDATA[<p>[...] the rest here: Security in Syndicated and Federated Systems | Social Hacking          By admin | category: Cuil, search engine | tags: Cuil, facebook, friends, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tweets that mention Security in Syndicated and Federated Systems &#124; Social Hacking -- Topsy.com</title>
		<link>http://theharmonyguy.com/2009/12/08/security-in-syndicated-and-federated-systems/comment-page-1/#comment-7417</link>
		<dc:creator>Tweets that mention Security in Syndicated and Federated Systems &#124; Social Hacking -- Topsy.com</dc:creator>
		<pubDate>Wed, 09 Dec 2009 03:38:58 +0000</pubDate>
		<guid isPermaLink="false">http://theharmonyguy.com/?p=576#comment-7417</guid>
		<description>[...] This post was mentioned on Twitter by Moui and theharmonyguy, SocialMediaSecurity. SocialMediaSecurity said: Security in Syndicated and Federated Systems http://bit.ly/5FW92q [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Moui and theharmonyguy, SocialMediaSecurity. SocialMediaSecurity said: Security in Syndicated and Federated Systems <a href="http://bit.ly/5FW92q" rel="nofollow">http://bit.ly/5FW92q</a> [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

