<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Google: Do What You Say</title>
	<atom:link href="http://securitypie.com/do-what-you-say/feed/" rel="self" type="application/rss+xml" />
	<link>http://securitypie.com/do-what-you-say/</link>
	<description>The ramblings of three security curmudgeons</description>
	<lastBuildDate>Mon, 05 Jul 2010 02:16:52 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: sharon</title>
		<link>http://securitypie.com/do-what-you-say/comment-page-1/#comment-660</link>
		<dc:creator>sharon</dc:creator>
		<pubDate>Wed, 20 Jan 2010 09:22:42 +0000</pubDate>
		<guid isPermaLink="false">http://securitypie.com/?p=711#comment-660</guid>
		<description>@Sylvain 
In my opinion it&#039;s not just the issue of selectively not encrypting specific pages. I believe that a company like Google should act differently and send a clear message stating that it encrypts all pages for this sensitive service (even if it carry no data). In addition I believe that it will prevent future issues: when you apply selective rules and start to exclude pages, you will miss something. If it will not happen today, it might happen tomorrow.</description>
		<content:encoded><![CDATA[<p>@Sylvain<br />
In my opinion it&#8217;s not just the issue of selectively not encrypting specific pages. I believe that a company like Google should act differently and send a clear message stating that it encrypts all pages for this sensitive service (even if it carry no data). In addition I believe that it will prevent future issues: when you apply selective rules and start to exclude pages, you will miss something. If it will not happen today, it might happen tomorrow.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sharon</title>
		<link>http://securitypie.com/do-what-you-say/comment-page-1/#comment-659</link>
		<dc:creator>sharon</dc:creator>
		<pubDate>Wed, 20 Jan 2010 09:15:03 +0000</pubDate>
		<guid isPermaLink="false">http://securitypie.com/?p=711#comment-659</guid>
		<description>Hi Arik,

Thanks for the detailed answer, I hope to see you in person soon and explain in depth why it is important to act in a smart way, not  just &#039;right&#039; (sounds better in Hebrew...)</description>
		<content:encoded><![CDATA[<p>Hi Arik,</p>
<p>Thanks for the detailed answer, I hope to see you in person soon and explain in depth why it is important to act in a smart way, not  just &#8216;right&#8217; (sounds better in Hebrew&#8230;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tweets that mention Google: Do What You Say at Security Pie -- Topsy.com</title>
		<link>http://securitypie.com/do-what-you-say/comment-page-1/#comment-615</link>
		<dc:creator>Tweets that mention Google: Do What You Say at Security Pie -- Topsy.com</dc:creator>
		<pubDate>Thu, 14 Jan 2010 17:18:36 +0000</pubDate>
		<guid isPermaLink="false">http://securitypie.com/?p=711#comment-615</guid>
		<description>[...] This post was mentioned on Twitter by Sharon Besser, Security Pie. Security Pie said: SecurityPie Blog Post: Do What You Say http://securitypie.com/do-what-you-say/ [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Sharon Besser, Security Pie. Security Pie said: SecurityPie Blog Post: Do What You Say <a href="http://securitypie.com/do-what-you-say/" rel="nofollow">http://securitypie.com/do-what-you-say/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arik</title>
		<link>http://securitypie.com/do-what-you-say/comment-page-1/#comment-614</link>
		<dc:creator>Arik</dc:creator>
		<pubDate>Thu, 14 Jan 2010 16:08:46 +0000</pubDate>
		<guid isPermaLink="false">http://securitypie.com/?p=711#comment-614</guid>
		<description>Hi Sharon

1. Nobody. Absolutely nobody. No not a single soul, not Google in their &lt;a href=&quot;http://gmailblog.blogspot.com/2010/01/default-https-access-for-gmail.html&quot; rel=&quot;nofollow&quot;&gt;official announcement&lt;/a&gt;, not the article you linked and nobody else I&#039;ve read (and I read quite a few of those). Nobody claimed Google will encrypt all of their services or even all of the pages in the gmail.com domain. They only claimed to encrypt the gmail service.

That is what they say and that is what they did. The only comment contradicting that is the vague sentence from Newswire saying &quot;Consumer Watchdog said Google should use encryption for connections to all its Internet-based services, not just Gmail&quot;. I don&#039;t understand the title of your post, because outside of the wishful thinking of Consumer Watchdog, Google have done precisely what they have said they will.

If you want to say that they SHOULD have invested more of their money to make the public help pages go over SSL for some reason, then please state that clearly; saying they promised to do something and didn&#039;t is a case of failing at reading comprehension.

2. Browsers usually don&#039;t display TIFF files, I suggest PNG instead.

-- Arik</description>
		<content:encoded><![CDATA[<p>Hi Sharon</p>
<p>1. Nobody. Absolutely nobody. No not a single soul, not Google in their <a href="http://gmailblog.blogspot.com/2010/01/default-https-access-for-gmail.html" rel="nofollow">official announcement</a>, not the article you linked and nobody else I&#8217;ve read (and I read quite a few of those). Nobody claimed Google will encrypt all of their services or even all of the pages in the gmail.com domain. They only claimed to encrypt the gmail service.</p>
<p>That is what they say and that is what they did. The only comment contradicting that is the vague sentence from Newswire saying &#8220;Consumer Watchdog said Google should use encryption for connections to all its Internet-based services, not just Gmail&#8221;. I don&#8217;t understand the title of your post, because outside of the wishful thinking of Consumer Watchdog, Google have done precisely what they have said they will.</p>
<p>If you want to say that they SHOULD have invested more of their money to make the public help pages go over SSL for some reason, then please state that clearly; saying they promised to do something and didn&#8217;t is a case of failing at reading comprehension.</p>
<p>2. Browsers usually don&#8217;t display TIFF files, I suggest PNG instead.</p>
<p>&#8211; Arik</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sylvain</title>
		<link>http://securitypie.com/do-what-you-say/comment-page-1/#comment-611</link>
		<dc:creator>Sylvain</dc:creator>
		<pubDate>Thu, 14 Jan 2010 13:31:37 +0000</pubDate>
		<guid isPermaLink="false">http://securitypie.com/?p=711#comment-611</guid>
		<description>Google does what&#039;s right for privacy and for performance by encrypting the application and not the help pages. Most users don&#039;t care, those who do can use NoScript and its Force HTTPS option.

http://noscript.net/faq#qa6_3</description>
		<content:encoded><![CDATA[<p>Google does what&#8217;s right for privacy and for performance by encrypting the application and not the help pages. Most users don&#8217;t care, those who do can use NoScript and its Force HTTPS option.</p>
<p><a href="http://noscript.net/faq#qa6_3" rel="nofollow">http://noscript.net/faq#qa6_3</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
