<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Webmind's blog</title>
	<atom:link href="http://blog.u2m.nl/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.u2m.nl</link>
	<description>Stuff that doesn't matter.</description>
	<lastBuildDate>Sun, 11 Apr 2010 12:25:09 +0200</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Firefox 3.5 and DNS Prefetches by admin</title>
		<link>http://blog.u2m.nl/archives/520/comment-page-1#comment-6222</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Sun, 11 Apr 2010 12:25:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.u2m.nl/?p=520#comment-6222</guid>
		<description>@mike ah, misunderstood the thunderbird version. The prefetching with non-https is still pretty bad though.</description>
		<content:encoded><![CDATA[<p>@mike ah, misunderstood the thunderbird version. The prefetching with non-https is still pretty bad though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Firefox 3.5 and DNS Prefetches by admin</title>
		<link>http://blog.u2m.nl/archives/520/comment-page-1#comment-6221</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Sun, 11 Apr 2010 11:29:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.u2m.nl/?p=520#comment-6221</guid>
		<description>@habbie, indeed. must say it was a bit of late hacking so we didn&#039;t check all well enough. 

firefox3.5.9 here indeed doesn&#039;t do it when viewing pages over HTTPS., but it DOES do it for local pages, which IMHO is still wrong. Also it could provide information of sites you might be visiting on an closed intranet, firefox has no real way to tell the difference.

webmail providers should indeed fix this, and squirrelmail has indeed released a new version with fix, the question is though, how many webmail apps have done this.

Thunderbird 2.0.0.4 also doesn&#039;t do the dns queries (we got this information from https://secure.grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_and_Webmail but didn&#039;t get arround checking it), might still work for older versions though.

As for plain HTTP connections. yes letting someone else do the resolving for you helps, but usually this still gives a lot of information of the viewer, usually atleast who the ISP is. This  could be used for say people looking at a post on indymedia.nl where a unique domain has been used for one of the posters to see where (perhaps only roughly) the viewers come from, and in some cases what the users IP&#039;s are. 

I try to use a trusted DNS server, which usually is my own, or used by very few people, which makes the pool of &#039;suspects&#039; rather small.

Has anyone checked what the default in chrome is btw?</description>
		<content:encoded><![CDATA[<p>@habbie, indeed. must say it was a bit of late hacking so we didn&#8217;t check all well enough. </p>
<p>firefox3.5.9 here indeed doesn&#8217;t do it when viewing pages over HTTPS., but it DOES do it for local pages, which IMHO is still wrong. Also it could provide information of sites you might be visiting on an closed intranet, firefox has no real way to tell the difference.</p>
<p>webmail providers should indeed fix this, and squirrelmail has indeed released a new version with fix, the question is though, how many webmail apps have done this.</p>
<p>Thunderbird 2.0.0.4 also doesn&#8217;t do the dns queries (we got this information from <a href="https://secure.grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_and_Webmail" rel="nofollow">https://secure.grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_and_Webmail</a> but didn&#8217;t get arround checking it), might still work for older versions though.</p>
<p>As for plain HTTP connections. yes letting someone else do the resolving for you helps, but usually this still gives a lot of information of the viewer, usually atleast who the ISP is. This  could be used for say people looking at a post on indymedia.nl where a unique domain has been used for one of the posters to see where (perhaps only roughly) the viewers come from, and in some cases what the users IP&#8217;s are. </p>
<p>I try to use a trusted DNS server, which usually is my own, or used by very few people, which makes the pool of &#8217;suspects&#8217; rather small.</p>
<p>Has anyone checked what the default in chrome is btw?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Firefox 3.5 and DNS Prefetches by Mike</title>
		<link>http://blog.u2m.nl/archives/520/comment-page-1#comment-6220</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sun, 11 Apr 2010 11:25:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.u2m.nl/?p=520#comment-6220</guid>
		<description>DNS prefetching didn&#039;t happen in Thunderbird 2, only in early versions of Thunderbird 3. In the latest version of Thunderbird 3 it doesn&#039;t happen. And as Habbie said, dns prefetching doesn&#039;t happen in Firefox when the page is loaded via https. Rick: Using a caching dns server wouldn&#039;t change anything...?</description>
		<content:encoded><![CDATA[<p>DNS prefetching didn&#8217;t happen in Thunderbird 2, only in early versions of Thunderbird 3. In the latest version of Thunderbird 3 it doesn&#8217;t happen. And as Habbie said, dns prefetching doesn&#8217;t happen in Firefox when the page is loaded via https. Rick: Using a caching dns server wouldn&#8217;t change anything&#8230;?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Firefox 3.5 and DNS Prefetches by dwizzy</title>
		<link>http://blog.u2m.nl/archives/520/comment-page-1#comment-6219</link>
		<dc:creator>dwizzy</dc:creator>
		<pubDate>Sun, 11 Apr 2010 10:54:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.u2m.nl/?p=520#comment-6219</guid>
		<description>found it in options, advanced, config editor :)</description>
		<content:encoded><![CDATA[<p>found it in options, advanced, config editor :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Firefox 3.5 and DNS Prefetches by dwizzy</title>
		<link>http://blog.u2m.nl/archives/520/comment-page-1#comment-6218</link>
		<dc:creator>dwizzy</dc:creator>
		<pubDate>Sun, 11 Apr 2010 10:52:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.u2m.nl/?p=520#comment-6218</guid>
		<description>Thanks for the heads-up. Now I have to find out how to disable this in Thunderbird!</description>
		<content:encoded><![CDATA[<p>Thanks for the heads-up. Now I have to find out how to disable this in Thunderbird!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Firefox 3.5 and DNS Prefetches by Rick Deckardt</title>
		<link>http://blog.u2m.nl/archives/520/comment-page-1#comment-6216</link>
		<dc:creator>Rick Deckardt</dc:creator>
		<pubDate>Sun, 11 Apr 2010 07:20:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.u2m.nl/?p=520#comment-6216</guid>
		<description>or just run your own local caching dns...</description>
		<content:encoded><![CDATA[<p>or just run your own local caching dns&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Firefox 3.5 and DNS Prefetches by Habbie</title>
		<link>http://blog.u2m.nl/archives/520/comment-page-1#comment-6215</link>
		<dc:creator>Habbie</dc:creator>
		<pubDate>Sun, 11 Apr 2010 07:08:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.u2m.nl/?p=520#comment-6215</guid>
		<description>Also, webmail should always be HTTPS, so there is not, by default, an actual issue there.</description>
		<content:encoded><![CDATA[<p>Also, webmail should always be HTTPS, so there is not, by default, an actual issue there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Firefox 3.5 and DNS Prefetches by Habbie</title>
		<link>http://blog.u2m.nl/archives/520/comment-page-1#comment-6214</link>
		<dc:creator>Habbie</dc:creator>
		<pubDate>Sun, 11 Apr 2010 07:04:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.u2m.nl/?p=520#comment-6214</guid>
		<description>Note that this is, in fact, disabled for HTTPS per default - of course, being explicit about disabling it is never bad.

As for webmail - webmail developers are already protecting users against many threats, for example by making sure external images don\&#039;t open by default. This is just another thing they should cover. I think it\&#039;s bad that Thunderbird (apparently, I did not check) has this enabled by default; I thikn it\&#039;s fine that Firefox has this enabled by default.</description>
		<content:encoded><![CDATA[<p>Note that this is, in fact, disabled for HTTPS per default &#8211; of course, being explicit about disabling it is never bad.</p>
<p>As for webmail &#8211; webmail developers are already protecting users against many threats, for example by making sure external images don\&#8217;t open by default. This is just another thing they should cover. I think it\&#8217;s bad that Thunderbird (apparently, I did not check) has this enabled by default; I thikn it\&#8217;s fine that Firefox has this enabled by default.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Hackerspace by Jeremiah C. Foster</title>
		<link>http://blog.u2m.nl/archives/399/comment-page-1#comment-3776</link>
		<dc:creator>Jeremiah C. Foster</dc:creator>
		<pubDate>Tue, 04 Aug 2009 13:32:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.u2m.nl/?p=399#comment-3776</guid>
		<description>Wow. Cool. I hope to check that out when I am in Amsterdam in October. 

We are trying to build a hackerspace in Gothenburg too. :-)</description>
		<content:encoded><![CDATA[<p>Wow. Cool. I hope to check that out when I am in Amsterdam in October. </p>
<p>We are trying to build a hackerspace in Gothenburg too. :-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Obscure mplayer problems by Steffen M. Boelaars</title>
		<link>http://blog.u2m.nl/archives/165/comment-page-1#comment-44</link>
		<dc:creator>Steffen M. Boelaars</dc:creator>
		<pubDate>Fri, 12 Dec 2008 13:26:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.u2m.nl/?p=165#comment-44</guid>
		<description>Lol.

But... what use is mplayer with no joy? (pun intended hahahahaha I kill myself hahahaha! :-P )</description>
		<content:encoded><![CDATA[<p>Lol.</p>
<p>But&#8230; what use is mplayer with no joy? (pun intended hahahahaha I kill myself hahahaha! :-P )</p>
]]></content:encoded>
	</item>
</channel>
</rss>
