<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: iPhone applications that transmit credentials using &#8220;unsafe&#8221; protocols</title>
	<atom:link href="http://blog.0x0lab.org/2010/04/unsafe-iphone-applications/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.0x0lab.org/2010/04/unsafe-iphone-applications/</link>
	<description>Just another damn blog</description>
	<lastBuildDate>Thu, 18 Aug 2011 00:08:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: The Web has still not switched to SSL-only &#124; DataProtectionCenter.com: Tech and Security - Data Recovery and Protection, Internet, Technology, Security, Reviews, Softwares</title>
		<link>http://blog.0x0lab.org/2010/04/unsafe-iphone-applications/comment-page-1/#comment-5312</link>
		<dc:creator>The Web has still not switched to SSL-only &#124; DataProtectionCenter.com: Tech and Security - Data Recovery and Protection, Internet, Technology, Security, Reviews, Softwares</dc:creator>
		<pubDate>Fri, 12 Aug 2011 14:13:04 +0000</pubDate>
		<guid isPermaLink="false">https://blog.0x0lab.org/?p=127#comment-5312</guid>
		<description>[...] &#084;&#104;&#101; situation &#105;&#115; even worse &#105;&#110; &#116;&#104;&#101; mobile space. &#077;&#111;&#115;&#116; &#111;&#102; &#116;&#104;&#101; applications used &#111;&#110; smartphones &#097;&#110;&#100; tablets need &#116;&#111; contact a web server &#116;&#111; function: &#116;&#111; retrieve advertising (Admob/Adsense Mobile), &#116;&#111; &#103;&#101;&#116; data &#102;&#114;&#111;&#109; a web service, etc. &#066;&#117;&#116; &#116;&#104;&#101;&#114;&#101; &#105;&#115; &#110;&#111; way &#102;&#111;&#114; &#116;&#104;&#101; user &#116;&#111; know whether sensitive information &#105;&#115; sent over HTTP &#111;&#114; HTTPS. &#084;&#104;&#101;&#114;&#101; &#105;&#115; &#110;&#111; UI element equivalent &#116;&#111; &#116;&#104;&#101; lock shown &#105;&#110; browsers &#097;&#110;&#100; &#110;&#111; visibility &#105;&#110;&#116;&#111; &#116;&#104;&#101; URLs. Researchers &#104;&#097;&#118;&#101; illustrated &#116;&#104;&#097;&#116; mobile developers &#099;&#097;&#110;&#110;&#111;&#116; &#098;&#101; trusted &#116;&#111; secure communications, &#097;&#115; &#097;&#108;&#108; &#116;&#111;&#111; &#111;&#102;&#116;&#101;&#110;, &#116;&#104;&#101;&#121;&#160;send user credentials &#105;&#110; plain text. [...]</description>
		<content:encoded><![CDATA[<p>[...] &#084;&#104;&#101; situation &#105;&#115; even worse &#105;&#110; &#116;&#104;&#101; mobile space. &#077;&#111;&#115;&#116; &#111;&#102; &#116;&#104;&#101; applications used &#111;&#110; smartphones &#097;&#110;&#100; tablets need &#116;&#111; contact a web server &#116;&#111; function: &#116;&#111; retrieve advertising (Admob/Adsense Mobile), &#116;&#111; &#103;&#101;&#116; data &#102;&#114;&#111;&#109; a web service, etc. &#066;&#117;&#116; &#116;&#104;&#101;&#114;&#101; &#105;&#115; &#110;&#111; way &#102;&#111;&#114; &#116;&#104;&#101; user &#116;&#111; know whether sensitive information &#105;&#115; sent over HTTP &#111;&#114; HTTPS. &#084;&#104;&#101;&#114;&#101; &#105;&#115; &#110;&#111; UI element equivalent &#116;&#111; &#116;&#104;&#101; lock shown &#105;&#110; browsers &#097;&#110;&#100; &#110;&#111; visibility &#105;&#110;&#116;&#111; &#116;&#104;&#101; URLs. Researchers &#104;&#097;&#118;&#101; illustrated &#116;&#104;&#097;&#116; mobile developers &#099;&#097;&#110;&#110;&#111;&#116; &#098;&#101; trusted &#116;&#111; secure communications, &#097;&#115; &#097;&#108;&#108; &#116;&#111;&#111; &#111;&#102;&#116;&#101;&#110;, &#116;&#104;&#101;&#121;&nbsp;send user credentials &#105;&#110; plain text. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Web has still not switched to SSL-only &#124; Triple-N</title>
		<link>http://blog.0x0lab.org/2010/04/unsafe-iphone-applications/comment-page-1/#comment-5303</link>
		<dc:creator>The Web has still not switched to SSL-only &#124; Triple-N</dc:creator>
		<pubDate>Thu, 11 Aug 2011 23:00:16 +0000</pubDate>
		<guid isPermaLink="false">https://blog.0x0lab.org/?p=127#comment-5303</guid>
		<description>[...] The situation is even worse in the mobile space. Most of the applications used on smartphones and tablets need to contact a web server to function: to retrieve advertising (Admob/Adsense Mobile), to get data from a web service, etc. But there is no way for the user to know whether sensitive information is sent over HTTP or HTTPS. There is no UI element equivalent to the lock shown in browsers and no visibility into the URLs. Researchers have illustrated that mobile developers cannot be trusted to secure communications, as all too often, they&#160;send user credentials in plain text. [...]</description>
		<content:encoded><![CDATA[<p>[...] The situation is even worse in the mobile space. Most of the applications used on smartphones and tablets need to contact a web server to function: to retrieve advertising (Admob/Adsense Mobile), to get data from a web service, etc. But there is no way for the user to know whether sensitive information is sent over HTTP or HTTPS. There is no UI element equivalent to the lock shown in browsers and no visibility into the URLs. Researchers have illustrated that mobile developers cannot be trusted to secure communications, as all too often, they&nbsp;send user credentials in plain text. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Web has still not switched to SSL-only &#124; 2thepress.nl</title>
		<link>http://blog.0x0lab.org/2010/04/unsafe-iphone-applications/comment-page-1/#comment-5302</link>
		<dc:creator>The Web has still not switched to SSL-only &#124; 2thepress.nl</dc:creator>
		<pubDate>Thu, 11 Aug 2011 22:15:14 +0000</pubDate>
		<guid isPermaLink="false">https://blog.0x0lab.org/?p=127#comment-5302</guid>
		<description>[...] The situation is even worse in the mobile space. Most of the applications used on smartphones and tablets need to contact a web server to function: to retrieve advertising (Admob/Adsense Mobile), to get data from a web service, etc. But there is no way for the user to know whether sensitive information is sent over HTTP or HTTPS. There is no UI element equivalent to the lock shown in browsers and no visibility into the URLs. Researchers have illustrated that mobile developers cannot be trusted to secure communications, as all too often, they&#160;send user credentials in plain text. [...]</description>
		<content:encoded><![CDATA[<p>[...] The situation is even worse in the mobile space. Most of the applications used on smartphones and tablets need to contact a web server to function: to retrieve advertising (Admob/Adsense Mobile), to get data from a web service, etc. But there is no way for the user to know whether sensitive information is sent over HTTP or HTTPS. There is no UI element equivalent to the lock shown in browsers and no visibility into the URLs. Researchers have illustrated that mobile developers cannot be trusted to secure communications, as all too often, they&nbsp;send user credentials in plain text. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: baking toys</title>
		<link>http://blog.0x0lab.org/2010/04/unsafe-iphone-applications/comment-page-1/#comment-409</link>
		<dc:creator>baking toys</dc:creator>
		<pubDate>Sat, 11 Sep 2010 12:15:42 +0000</pubDate>
		<guid isPermaLink="false">https://blog.0x0lab.org/?p=127#comment-409</guid>
		<description>Awesome post.</description>
		<content:encoded><![CDATA[<p>Awesome post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://blog.0x0lab.org/2010/04/unsafe-iphone-applications/comment-page-1/#comment-270</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Sun, 22 Aug 2010 16:38:24 +0000</pubDate>
		<guid isPermaLink="false">https://blog.0x0lab.org/?p=127#comment-270</guid>
		<description>Add Foursquare and Gowalla to that list (http://martinkou.blogspot.com/2010/08/foursquare-considered-harmful-dont-use.html)</description>
		<content:encoded><![CDATA[<p>Add Foursquare and Gowalla to that list (<a href="http://martinkou.blogspot.com/2010/08/foursquare-considered-harmful-dont-use.html" rel="nofollow">http://martinkou.blogspot.com/2010/08/foursquare-considered-harmful-dont-use.html</a>)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

