<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: OpenSocial: JavaScript Code of Flixster on MySpace &#8211; Start Hacking!</title>
	<atom:link href="http://blog.stevepoland.com/opensocial-javascript-code-of-flixster-on-myspace-start-hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.stevepoland.com/opensocial-javascript-code-of-flixster-on-myspace-start-hacking/</link>
	<description>web entrepreneur &#124; obsessed music fan &#124; b-lo forever!</description>
	<lastBuildDate>Fri, 25 Jun 2010 14:32:45 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: sandy</title>
		<link>http://blog.stevepoland.com/opensocial-javascript-code-of-flixster-on-myspace-start-hacking/comment-page-1/#comment-1400</link>
		<dc:creator>sandy</dc:creator>
		<pubDate>Wed, 27 Aug 2008 10:58:12 +0000</pubDate>
		<guid isPermaLink="false">http://stevepoland.com/?p=302#comment-1400</guid>
		<description>above link for zip file is not working also txt file link not working. can u plz check if possible send by email

thanks</description>
		<content:encoded><![CDATA[<p>above link for zip file is not working also txt file link not working. can u plz check if possible send by email</p>
<p>thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Miron C</title>
		<link>http://blog.stevepoland.com/opensocial-javascript-code-of-flixster-on-myspace-start-hacking/comment-page-1/#comment-1176</link>
		<dc:creator>Miron C</dc:creator>
		<pubDate>Sun, 04 Nov 2007 18:58:46 +0000</pubDate>
		<guid isPermaLink="false">http://stevepoland.com/?p=302#comment-1176</guid>
		<description>A quick look at the JavaScript code shows that the client-side JavaScript is passing the user ID to the backend without any authentication.  This means that it&#039;s trivial to mess up anybody&#039;s Flixter profile.

This seems to be a general issue with OpenSocial.  Unlike Facebook, Opensocial seems to be missing user to app authentication.  I wrote an article about it:

http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/

I hope that the Facebook version of Flixster does take advantage of
their authentication mechanism.</description>
		<content:encoded><![CDATA[<p>A quick look at the JavaScript code shows that the client-side JavaScript is passing the user ID to the backend without any authentication.  This means that it&#8217;s trivial to mess up anybody&#8217;s Flixter profile.</p>
<p>This seems to be a general issue with OpenSocial.  Unlike Facebook, Opensocial seems to be missing user to app authentication.  I wrote an article about it:</p>
<p><a href="http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/" rel="nofollow" target="_blank">http://hyper.to/blog/link/opensocial-insecurity-no-user-to-app-authentication/</a></p>
<p>I hope that the Facebook version of Flixster does take advantage of<br />
their authentication mechanism.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wal</title>
		<link>http://blog.stevepoland.com/opensocial-javascript-code-of-flixster-on-myspace-start-hacking/comment-page-1/#comment-1175</link>
		<dc:creator>Wal</dc:creator>
		<pubDate>Fri, 02 Nov 2007 22:05:48 +0000</pubDate>
		<guid isPermaLink="false">http://stevepoland.com/?p=302#comment-1175</guid>
		<description>I was looking for good examples. Thanks for the tip.</description>
		<content:encoded><![CDATA[<p>I was looking for good examples. Thanks for the tip.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve Poland</title>
		<link>http://blog.stevepoland.com/opensocial-javascript-code-of-flixster-on-myspace-start-hacking/comment-page-1/#comment-1174</link>
		<dc:creator>Steve Poland</dc:creator>
		<pubDate>Fri, 02 Nov 2007 12:53:36 +0000</pubDate>
		<guid isPermaLink="false">http://stevepoland.com/?p=302#comment-1174</guid>
		<description>http://www.myspace.com/aber -- CTO, MySpace</description>
		<content:encoded><![CDATA[<p><a href="http://www.myspace.com/aber" rel="nofollow" target="_blank">http://www.myspace.com/aber</a> &#8212; CTO, MySpace</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Smith</title>
		<link>http://blog.stevepoland.com/opensocial-javascript-code-of-flixster-on-myspace-start-hacking/comment-page-1/#comment-1173</link>
		<dc:creator>Matt Smith</dc:creator>
		<pubDate>Fri, 02 Nov 2007 03:17:11 +0000</pubDate>
		<guid isPermaLink="false">http://stevepoland.com/?p=302#comment-1173</guid>
		<description>Steve, where did you get these files?</description>
		<content:encoded><![CDATA[<p>Steve, where did you get these files?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kiakanpa</title>
		<link>http://blog.stevepoland.com/opensocial-javascript-code-of-flixster-on-myspace-start-hacking/comment-page-1/#comment-1172</link>
		<dc:creator>kiakanpa</dc:creator>
		<pubDate>Thu, 01 Nov 2007 21:01:16 +0000</pubDate>
		<guid isPermaLink="false">http://stevepoland.com/?p=302#comment-1172</guid>
		<description>Quick work ;-) will take a look</description>
		<content:encoded><![CDATA[<p>Quick work <img src='http://blog.stevepoland.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  will take a look</p>
]]></content:encoded>
	</item>
</channel>
</rss>
