<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Single-Site Browsers</title>
	<atom:link href="http://blogs.yankeegroup.com/2008/04/21/single-site-browsers/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.yankeegroup.com/2008/04/21/single-site-browsers/</link>
	<description>the global connectivity experts™</description>
	<lastBuildDate>Wed, 10 Mar 2010 15:11:25 -0500</lastBuildDate>
	
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Dan Guido</title>
		<link>http://blogs.yankeegroup.com/2008/04/21/single-site-browsers/comment-page-1/#comment-2432</link>
		<dc:creator>Dan Guido</dc:creator>
		<pubDate>Mon, 21 Apr 2008 23:52:42 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.yankeegroup.com/2008/04/21/single-site-browsers/#comment-2432</guid>
		<description>The one critical problem that I see with SSBs is that if someone receives a phishing e-mail and the website it brings them to looks exactly like the one they see in the SSB, will they still give up their credentials? Or will they close Firefox and open the SSB? My money is on them giving up the info anyway.

Also, I think it requires that you deny access to your website from normal browsers to derive the most benefit from using SSBs, both from a user uptake perspective and as a protection against CSRF.

I&#039;m writing up something about this that should be ready tonight or tomorrow at my blog here: http://isisblogs.poly.edu. If you have trackbacks turned on, you should see it.

Last thing, the multiple SSBs problem isn&#039;t so much of a problem. I&#039;ve been using one for Gmail, Gcal, Twitter, and Facebook for a few days now and it hasn&#039;t overwhelmed me (yet).</description>
		<content:encoded><![CDATA[<p>The one critical problem that I see with SSBs is that if someone receives a phishing e-mail and the website it brings them to looks exactly like the one they see in the SSB, will they still give up their credentials? Or will they close Firefox and open the SSB? My money is on them giving up the info anyway.</p>
<p>Also, I think it requires that you deny access to your website from normal browsers to derive the most benefit from using SSBs, both from a user uptake perspective and as a protection against CSRF.</p>
<p>I&#8217;m writing up something about this that should be ready tonight or tomorrow at my blog here: <a href="http://isisblogs.poly.edu" rel="nofollow">http://isisblogs.poly.edu</a>. If you have trackbacks turned on, you should see it.</p>
<p>Last thing, the multiple SSBs problem isn&#8217;t so much of a problem. I&#8217;ve been using one for Gmail, Gcal, Twitter, and Facebook for a few days now and it hasn&#8217;t overwhelmed me (yet).</p>
]]></content:encoded>
	</item>
</channel>
</rss>
