<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: It&#8217;s a question of trust&#8230;</title>
	<atom:link href="http://domsparks.wordpress.com/2009/01/11/its-a-question-of-trust/feed/" rel="self" type="application/rss+xml" />
	<link>http://domsparks.wordpress.com/2009/01/11/its-a-question-of-trust/</link>
	<description>for what it's worth...</description>
	<lastBuildDate>Tue, 13 Jan 2009 18:16:37 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Losing faith in the software startup community&#8230; &#171; Dominic Sparks</title>
		<link>http://domsparks.wordpress.com/2009/01/11/its-a-question-of-trust/#comment-7</link>
		<dc:creator>Losing faith in the software startup community&#8230; &#171; Dominic Sparks</dc:creator>
		<pubDate>Tue, 13 Jan 2009 01:38:01 +0000</pubDate>
		<guid isPermaLink="false">http://domsparks.wordpress.com/?p=48#comment-7</guid>
		<description>[...] a comment &#187;  Further to my previous entry &#8220;It&#8217;s A Question Of Trust&#8221;, and comments thereon, I have done a little further research into the blatant disregard for [...]</description>
		<content:encoded><![CDATA[<p>[...] a comment &raquo;  Further to my previous entry &#8220;It&#8217;s A Question Of Trust&#8221;, and comments thereon, I have done a little further research into the blatant disregard for [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: domsparks</title>
		<link>http://domsparks.wordpress.com/2009/01/11/its-a-question-of-trust/#comment-6</link>
		<dc:creator>domsparks</dc:creator>
		<pubDate>Mon, 12 Jan 2009 01:45:52 +0000</pubDate>
		<guid isPermaLink="false">http://domsparks.wordpress.com/?p=48#comment-6</guid>
		<description>Hi Nick, thanks for the response.
I guess that&#039;s the reason those other sites only secure their login-post action.  I suppose the only downside is the lack of a padlock, but if your site has a reputation as being trustworthy maybe it&#039;s enough to simply say that it is secure, e.g. by having a button that says &#039;Secure Login&#039;, much like Amazon do on their login page...

In the mean time, I&#039;m now going to concentrate my efforts on trying to improve my twitorfit rating. I can live with the security issues, but not so much with my inexplicably low score.  Are you sure the Maths are correct on this site? :-)

Cheers,
Dominic.</description>
		<content:encoded><![CDATA[<p>Hi Nick, thanks for the response.<br />
I guess that&#8217;s the reason those other sites only secure their login-post action.  I suppose the only downside is the lack of a padlock, but if your site has a reputation as being trustworthy maybe it&#8217;s enough to simply say that it is secure, e.g. by having a button that says &#8216;Secure Login&#8217;, much like Amazon do on their login page&#8230;</p>
<p>In the mean time, I&#8217;m now going to concentrate my efforts on trying to improve my twitorfit rating. I can live with the security issues, but not so much with my inexplicably low score.  Are you sure the Maths are correct on this site? <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Cheers,<br />
Dominic.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick Halstead</title>
		<link>http://domsparks.wordpress.com/2009/01/11/its-a-question-of-trust/#comment-4</link>
		<dc:creator>Nick Halstead</dc:creator>
		<pubDate>Mon, 12 Jan 2009 00:00:09 +0000</pubDate>
		<guid isPermaLink="false">http://domsparks.wordpress.com/?p=48#comment-4</guid>
		<description>Hi Dominic,

Completely correct, for something like twitorfit (and thousands of others) it is a lot of extra work to put SSL behind it. 

But fav.or.it *should* have been done ages ago, we have a SSL certificate, but like you I took it that so many sites were *not* using SSL due to the lack of the padlock. And given other priorities we never went back and sorted it, we only just moved to making &#039;all&#039; authentication go through &#039;my.fav.or.it&#039; which which will now make it very easy to implement. 

The question of if the main login page should be SSL (the downside is that nothing can be cached on a SSL page, and therefore takes up 4-5x the processing) - or if we just use SSL for the post. 

I appreciate the timely reminder and will make sure it is sorted this week,

Nick</description>
		<content:encoded><![CDATA[<p>Hi Dominic,</p>
<p>Completely correct, for something like twitorfit (and thousands of others) it is a lot of extra work to put SSL behind it. </p>
<p>But fav.or.it *should* have been done ages ago, we have a SSL certificate, but like you I took it that so many sites were *not* using SSL due to the lack of the padlock. And given other priorities we never went back and sorted it, we only just moved to making &#8216;all&#8217; authentication go through &#8216;my.fav.or.it&#8217; which which will now make it very easy to implement. </p>
<p>The question of if the main login page should be SSL (the downside is that nothing can be cached on a SSL page, and therefore takes up 4-5x the processing) &#8211; or if we just use SSL for the post. </p>
<p>I appreciate the timely reminder and will make sure it is sorted this week,</p>
<p>Nick</p>
]]></content:encoded>
	</item>
</channel>
</rss>
