<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Cruciforum: crucially simple</title>
	<atom:link href="http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple/feed" rel="self" type="application/rss+xml" />
	<link>http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple</link>
	<description>scratched tallies on the prison wall</description>
	<pubDate>Tue, 02 Dec 2008 20:53:55 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: OpenCycleRoute &#187; Blog Archive &#187; Discuss</title>
		<link>http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple#comment-107538</link>
		<dc:creator>OpenCycleRoute &#187; Blog Archive &#187; Discuss</dc:creator>
		<pubDate>Mon, 11 Feb 2008 23:54:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple#comment-107538</guid>
		<description>[...] while back I added a simple discussion forum for opencycleroute.org, based on cruciforum by Stuart [...]</description>
		<content:encoded><![CDATA[<p>[...] while back I added a simple discussion forum for opencycleroute.org, based on cruciforum by Stuart [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Round</title>
		<link>http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple#comment-99720</link>
		<dc:creator>Matt Round</dc:creator>
		<pubDate>Thu, 18 Oct 2007 13:41:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple#comment-99720</guid>
		<description>CSRF isn't much of an issue in this case, but it could be abused to make innocent users post on behalf of a spammer (when they visit a site set up by the spammer or a site compromised by XSS). You then wouldn't be able to usefully use IP for blacklisting, and if the spammer's site used HTTPS then there'd be no referer to block either.

Like I said, it's not a major issue though, particularly if the chosen anti-spam measures rely upon content and user interaction rather than IP/referer.</description>
		<content:encoded><![CDATA[<p>CSRF isn&#8217;t much of an issue in this case, but it could be abused to make innocent users post on behalf of a spammer (when they visit a site set up by the spammer or a site compromised by XSS). You then wouldn&#8217;t be able to usefully use IP for blacklisting, and if the spammer&#8217;s site used HTTPS then there&#8217;d be no referer to block either.</p>
<p>Like I said, it&#8217;s not a major issue though, particularly if the chosen anti-spam measures rely upon content and user interaction rather than IP/referer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cruciforum, then. &#171; Exploring Freedom with Matt Lee</title>
		<link>http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple#comment-99717</link>
		<dc:creator>Cruciforum, then. &#171; Exploring Freedom with Matt Lee</dc:creator>
		<pubDate>Thu, 18 Oct 2007 00:55:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple#comment-99717</guid>
		<description>[...] 18th, 2007 &#183; No Comments  Cruciforum - a really (really) simple forum, written inPHP. [...]</description>
		<content:encoded><![CDATA[<p>[...] 18th, 2007 &middot; No Comments  Cruciforum - a really (really) simple forum, written inPHP. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sil</title>
		<link>http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple#comment-99715</link>
		<dc:creator>sil</dc:creator>
		<pubDate>Tue, 16 Oct 2007 15:33:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple#comment-99715</guid>
		<description>Matt: I'm not sure how CSRF applies here. Yes, I could trick your browser into posting as you to a Cruciforum from some other site, but then I could just go to the forum myself and post as you too. There are no identity guarantees. I can't think of a reason why I can't go to some forum you don't know about somewhere else and sign up as mattround, either. I can't fill in my email address as being yours, because I'll fail verification, but I can say "I'm Matt Round and my website is malevolent.com" on every weblog comment form in the land without any problem. Unless we're prepared to demand (not allow, but _demand_) something like OpenID or some trust metric, that's just the way it is. If that counts as CSRF, then Cruciforum isn't any more vulnerable than half the rest of the internet.&lt;br /&gt;
&lt;br /&gt;
Anti-spam, yes, and http://www.kryogenix.org/bugs/cruciforum/spam-protection.html discusses precisely that.</description>
		<content:encoded><![CDATA[<p>Matt: I&#8217;m not sure how CSRF applies here. Yes, I could trick your browser into posting as you to a Cruciforum from some other site, but then I could just go to the forum myself and post as you too. There are no identity guarantees. I can&#8217;t think of a reason why I can&#8217;t go to some forum you don&#8217;t know about somewhere else and sign up as mattround, either. I can&#8217;t fill in my email address as being yours, because I&#8217;ll fail verification, but I can say &#8220;I&#8217;m Matt Round and my website is malevolent.com&#8221; on every weblog comment form in the land without any problem. Unless we&#8217;re prepared to demand (not allow, but _demand_) something like OpenID or some trust metric, that&#8217;s just the way it is. If that counts as CSRF, then Cruciforum isn&#8217;t any more vulnerable than half the rest of the internet.</p>
<p>Anti-spam, yes, and <a href="http://www.kryogenix.org/bugs/cruciforum/spam-protection.html" rel="nofollow">http://www.kryogenix.org/bugs/cruciforum/spam-protection.html</a> discusses precisely that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Round</title>
		<link>http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple#comment-99714</link>
		<dc:creator>Matt Round</dc:creator>
		<pubDate>Tue, 16 Oct 2007 14:33:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple#comment-99714</guid>
		<description>The simplicity is refreshing, but releasing it without anti-spam/validation/anti-CSRF/throttling measures makes me wince a little. Anyone installing this version will be wide open to abuse.</description>
		<content:encoded><![CDATA[<p>The simplicity is refreshing, but releasing it without anti-spam/validation/anti-CSRF/throttling measures makes me wince a little. Anyone installing this version will be wide open to abuse.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: N.</title>
		<link>http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple#comment-99711</link>
		<dc:creator>N.</dc:creator>
		<pubDate>Tue, 16 Oct 2007 08:13:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple#comment-99711</guid>
		<description>Why does the name make me think someone's been reading too much JK Rowling... :)</description>
		<content:encoded><![CDATA[<p>Why does the name make me think someone&#8217;s been reading too much JK Rowling&#8230; :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adriatic</title>
		<link>http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple#comment-99710</link>
		<dc:creator>Adriatic</dc:creator>
		<pubDate>Tue, 16 Oct 2007 07:26:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/2007/10/16/cruciforum-crucially-simple#comment-99710</guid>
		<description>Cool name!
You seem to be Dan Simmons fan (just like myself :-)</description>
		<content:encoded><![CDATA[<p>Cool name!<br />
You seem to be Dan Simmons fan (just like myself :-)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
