<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Is InformationWeek right?  Are most all Drupal sites insecure?</title>
	<atom:link href="http://robinmonks.com/2008/08/21/is-informationweek-right-are-most-all-drupal-sites-insecure/feed/" rel="self" type="application/rss+xml" />
	<link>http://robinmonks.com/2008/08/21/is-informationweek-right-are-most-all-drupal-sites-insecure/</link>
	<description>Only the interesting stuff.</description>
	<lastBuildDate>Fri, 19 Mar 2010 18:00:29 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: In the eyes of Robin Monks &#187; Security theater #1 - Using SSL for login &#124; Heine</title>
		<link>http://robinmonks.com/2008/08/21/is-informationweek-right-are-most-all-drupal-sites-insecure/comment-page-1/#comment-1365</link>
		<dc:creator>In the eyes of Robin Monks &#187; Security theater #1 - Using SSL for login &#124; Heine</dc:creator>
		<pubDate>Fri, 22 Aug 2008 16:03:54 +0000</pubDate>
		<guid isPermaLink="false">http://robinmonks.com/?p=85#comment-1365</guid>
		<description>[...] from Drupal IRC was kind enough to explain the SSL issues that I mentioned here and here in much greater detail. Head to his blog for the full article. Thanks Heine! Image via [...]</description>
		<content:encoded><![CDATA[<p>[...] from Drupal IRC was kind enough to explain the SSL issues that I mentioned here and here in much greater detail. Head to his blog for the full article. Thanks Heine! Image via [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: In the eyes of Robin Monks &#187; Are HTTPS Drupal sites insecure? Not anymore!</title>
		<link>http://robinmonks.com/2008/08/21/is-informationweek-right-are-most-all-drupal-sites-insecure/comment-page-1/#comment-1363</link>
		<dc:creator>In the eyes of Robin Monks &#187; Are HTTPS Drupal sites insecure? Not anymore!</dc:creator>
		<pubDate>Fri, 22 Aug 2008 12:13:11 +0000</pubDate>
		<guid isPermaLink="false">http://robinmonks.com/?p=85#comment-1363</guid>
		<description>[...] Facebook, Gmail, addons.mozilla.org, most Drupal sites, and many online merchants and banks. ”In the eyes of Robin Monks, Aug [...]</description>
		<content:encoded><![CDATA[<p>[...] Facebook, Gmail, addons.mozilla.org, most Drupal sites, and many online merchants and banks. ”In the eyes of Robin Monks, Aug [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christefano</title>
		<link>http://robinmonks.com/2008/08/21/is-informationweek-right-are-most-all-drupal-sites-insecure/comment-page-1/#comment-1362</link>
		<dc:creator>Christefano</dc:creator>
		<pubDate>Fri, 22 Aug 2008 09:41:44 +0000</pubDate>
		<guid isPermaLink="false">http://robinmonks.com/?p=85#comment-1362</guid>
		<description>There&#039;s a patch that just landed in core that addresses this particular issue in Drupal:

http://drupal.org/node/170310

Mike Perry probably mentioned Drupal since that&#039;s what his website is running.</description>
		<content:encoded><![CDATA[<p>There&#8217;s a patch that just landed in core that addresses this particular issue in Drupal:</p>
<p><a href="http://drupal.org/node/170310" rel="nofollow">http://drupal.org/node/170310</a></p>
<p>Mike Perry probably mentioned Drupal since that&#8217;s what his website is running.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Wilkins</title>
		<link>http://robinmonks.com/2008/08/21/is-informationweek-right-are-most-all-drupal-sites-insecure/comment-page-1/#comment-1361</link>
		<dc:creator>John Wilkins</dc:creator>
		<pubDate>Fri, 22 Aug 2008 02:22:57 +0000</pubDate>
		<guid isPermaLink="false">http://robinmonks.com/?p=85#comment-1361</guid>
		<description>We&#039;re way ahead of you! :-)

http://drupal.org/node/170310 addresses the SSL-based session cookie issue. Dries committed it 3 days ago to Drupal 7 and Drupal 6. And Drupal 5 will be patched shortly.

Here&#039;s the comments I wrote for the patch:

“To prevent session cookies from being hijacked, a user can configure the SSL version of their website to only transfer session cookies via SSL by using PHP&#039;s session.cookie_secure setting. The browser will then use two separate session cookies for the HTTPS and HTTP versions of the site.” And the HTTPS session cookie will be protected from hijacking.

You&#039;ll still need to configure HP&#039;s session.cookie_secure setting on the SSL version of the website, as Drupal doesn&#039;t enforce that.</description>
		<content:encoded><![CDATA[<p>We&#8217;re way ahead of you! <img src='http://robinmonks.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><a href="http://drupal.org/node/170310" rel="nofollow">http://drupal.org/node/170310</a> addresses the SSL-based session cookie issue. Dries committed it 3 days ago to Drupal 7 and Drupal 6. And Drupal 5 will be patched shortly.</p>
<p>Here&#8217;s the comments I wrote for the patch:</p>
<p>“To prevent session cookies from being hijacked, a user can configure the SSL version of their website to only transfer session cookies via SSL by using PHP&#8217;s session.cookie_secure setting. The browser will then use two separate session cookies for the HTTPS and HTTP versions of the site.” And the HTTPS session cookie will be protected from hijacking.</p>
<p>You&#8217;ll still need to configure HP&#8217;s session.cookie_secure setting on the SSL version of the website, as Drupal doesn&#8217;t enforce that.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
