<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Intra-iframe Message Passing</title>
	<atom:link href="http://ajaxian.com/archives/intra-iframe-message-passing/feed" rel="self" type="application/rss+xml" />
	<link>http://ajaxian.com/archives/intra-iframe-message-passing</link>
	<description>Cleaning up the web with Ajax</description>
	<lastBuildDate>Thu, 17 May 2012 07:43:39 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Julien Couvreur</title>
		<link>http://ajaxian.com/archives/intra-iframe-message-passing/comment-page-1#comment-114676</link>
		<dc:creator>Julien Couvreur</dc:creator>
		<pubDate>Wed, 04 Oct 2006 01:39:40 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/intra-iframe-message-passing#comment-114676</guid>
		<description>Optimus Paul,
Privacy reasons would prevent you from implementing the Windows Live Contact Gadget by doing the mashup on the server.
Another reason for doing client-side cross-domain communication is to avoid un-necessary proxying traffic to your server. Agreed there are times where this traffic is necessary, but in many occasions it is not.</description>
		<content:encoded><![CDATA[<p>Optimus Paul,<br />
Privacy reasons would prevent you from implementing the Windows Live Contact Gadget by doing the mashup on the server.<br />
Another reason for doing client-side cross-domain communication is to avoid un-necessary proxying traffic to your server. Agreed there are times where this traffic is necessary, but in many occasions it is not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: optimus paul</title>
		<link>http://ajaxian.com/archives/intra-iframe-message-passing/comment-page-1#comment-107322</link>
		<dc:creator>optimus paul</dc:creator>
		<pubDate>Wed, 27 Sep 2006 22:00:23 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/intra-iframe-message-passing#comment-107322</guid>
		<description>I&#039;ve always found it easier and perhaps better do do my mash-ups on the server, then there are no xss concerns.  I&#039;ve never really understood the fascination with attempting to do xss in ajax.

I do think this is good news, now we can get the problem fixed.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve always found it easier and perhaps better do do my mash-ups on the server, then there are no xss concerns.  I&#8217;ve never really understood the fascination with attempting to do xss in ajax.</p>
<p>I do think this is good news, now we can get the problem fixed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: henrah</title>
		<link>http://ajaxian.com/archives/intra-iframe-message-passing/comment-page-1#comment-103319</link>
		<dc:creator>henrah</dc:creator>
		<pubDate>Sun, 24 Sep 2006 02:51:13 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/intra-iframe-message-passing#comment-103319</guid>
		<description>@Fnustle:
&gt; given the hypervigilant attitude MS has had towards securityâ€¦

Since the Windows Live team is actually exporing this technique, it&#039;s reasonable to assume that Microsoft are treating this as a security solution rather than a flaw.</description>
		<content:encoded><![CDATA[<p>@Fnustle:<br />
&gt; given the hypervigilant attitude MS has had towards securityâ€¦</p>
<p>Since the Windows Live team is actually exporing this technique, it&#8217;s reasonable to assume that Microsoft are treating this as a security solution rather than a flaw.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joseph Smarr</title>
		<link>http://ajaxian.com/archives/intra-iframe-message-passing/comment-page-1#comment-102306</link>
		<dc:creator>Joseph Smarr</dc:creator>
		<pubDate>Sat, 23 Sep 2006 04:04:01 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/intra-iframe-message-passing#comment-102306</guid>
		<description>For those interested in more info and more options for cross-site scripting technicques and their challenges, you might enjoy the talk I gave this year at OSCON on the subject (including the infamous &quot;JavaScript Wormhole&quot;).

Slides:http://www.plaxo.com/css/api/Joseph-Smarr-Plaxo-OSCON-2006.ppt 

Summary: http://www.sitepoint.com/blogs/2006/07/28/oscon-2006-cross-site-ajax/</description>
		<content:encoded><![CDATA[<p>For those interested in more info and more options for cross-site scripting technicques and their challenges, you might enjoy the talk I gave this year at OSCON on the subject (including the infamous &#8220;JavaScript Wormhole&#8221;).</p>
<p>Slides:<a href="http://www.plaxo.com/css/api/Joseph-Smarr-Plaxo-OSCON-2006.ppt" rel="nofollow">http://www.plaxo.com/css/api/Joseph-Smarr-Plaxo-OSCON-2006.ppt</a> </p>
<p>Summary: <a href="http://www.sitepoint.com/blogs/2006/07/28/oscon-2006-cross-site-ajax/" rel="nofollow">http://www.sitepoint.com/blogs/2006/07/28/oscon-2006-cross-site-ajax/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: srabbit23</title>
		<link>http://ajaxian.com/archives/intra-iframe-message-passing/comment-page-1#comment-102217</link>
		<dc:creator>srabbit23</dc:creator>
		<pubDate>Sat, 23 Sep 2006 00:12:00 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/intra-iframe-message-passing#comment-102217</guid>
		<description>&lt;strong&gt;Intra-iframe Message Passing&lt;/strong&gt;

nice</description>
		<content:encoded><![CDATA[<p><strong>Intra-iframe Message Passing</strong></p>
<p>nice</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ahmed Kamel</title>
		<link>http://ajaxian.com/archives/intra-iframe-message-passing/comment-page-1#comment-102206</link>
		<dc:creator>Ahmed Kamel</dc:creator>
		<pubDate>Fri, 22 Sep 2006 23:47:28 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/intra-iframe-message-passing#comment-102206</guid>
		<description>I agree that this doesn&#039;t seem to be a security hole; because it requires both frames (parent and iframe) to work together, and hence neither A or B can exploit each other.

However, this can become an exploit, if E (for evil) comes along and decides to spoof B&#039;s dynamic iframe creation; passing bad information to A.

Somehow a security mechanism (identification) must be established between A and B.</description>
		<content:encoded><![CDATA[<p>I agree that this doesn&#8217;t seem to be a security hole; because it requires both frames (parent and iframe) to work together, and hence neither A or B can exploit each other.</p>
<p>However, this can become an exploit, if E (for evil) comes along and decides to spoof B&#8217;s dynamic iframe creation; passing bad information to A.</p>
<p>Somehow a security mechanism (identification) must be established between A and B.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Julien Couvreur</title>
		<link>http://ajaxian.com/archives/intra-iframe-message-passing/comment-page-1#comment-102065</link>
		<dc:creator>Julien Couvreur</dc:creator>
		<pubDate>Fri, 22 Sep 2006 20:50:12 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/intra-iframe-message-passing#comment-102065</guid>
		<description>Fnustle, I don&#039;t think that this can be &quot;fixed&quot;. There is no hole per-se. Which part would you want to fix? The ability to create iframes that load any url? The ability to enumerate all iframes in a document?</description>
		<content:encoded><![CDATA[<p>Fnustle, I don&#8217;t think that this can be &#8220;fixed&#8221;. There is no hole per-se. Which part would you want to fix? The ability to create iframes that load any url? The ability to enumerate all iframes in a document?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fnustle</title>
		<link>http://ajaxian.com/archives/intra-iframe-message-passing/comment-page-1#comment-101996</link>
		<dc:creator>Fnustle</dc:creator>
		<pubDate>Fri, 22 Sep 2006 18:55:31 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/intra-iframe-message-passing#comment-101996</guid>
		<description>Neat, but I wouldn&#039;t rely on a security hole staying around even if it is one that would be highly improbable to exploit, given the hypervigilant attitude MS has had towards security...</description>
		<content:encoded><![CDATA[<p>Neat, but I wouldn&#8217;t rely on a security hole staying around even if it is one that would be highly improbable to exploit, given the hypervigilant attitude MS has had towards security&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

