<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Apple&#8217;s MobileMe Web Apps don&#8217;t use HTTPS</title>
	<atom:link href="http://rantsandstuff.com/2008/07/28/apples-mobileme-web-apps-dont-use-https/feed/" rel="self" type="application/rss+xml" />
	<link>http://rantsandstuff.com/2008/07/28/apples-mobileme-web-apps-dont-use-https/</link>
	<description>A Tech Blog by Brad and Jon</description>
	<lastBuildDate>Fri, 22 Jan 2010 13:11:38 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Mike</title>
		<link>http://rantsandstuff.com/2008/07/28/apples-mobileme-web-apps-dont-use-https/comment-page-1/#comment-128</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Thu, 21 Aug 2008 13:45:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.rantsandstuff.com/?p=21#comment-128</guid>
		<description>The &quot;trick&quot; to use https instead of http, as said by the Apple help desk, does not work for me.com. No way to switch to https. So all confidential address book data and all confidential and personal calendar data is transferred unencrypted. Don&#039;t use MobileMe until this is fixed!

Regarding &quot;ssl in the background&quot; - this is not possible with AJAX, as it&#039;s a different &quot;domain&quot; and prohibited by the browser.</description>
		<content:encoded><![CDATA[<p>The &#8220;trick&#8221; to use https instead of http, as said by the Apple help desk, does not work for me.com. No way to switch to https. So all confidential address book data and all confidential and personal calendar data is transferred unencrypted. Don&#8217;t use MobileMe until this is fixed!</p>
<p>Regarding &#8220;ssl in the background&#8221; &#8211; this is not possible with AJAX, as it&#8217;s a different &#8220;domain&#8221; and prohibited by the browser.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon</title>
		<link>http://rantsandstuff.com/2008/07/28/apples-mobileme-web-apps-dont-use-https/comment-page-1/#comment-123</link>
		<dc:creator>Jon</dc:creator>
		<pubDate>Sun, 10 Aug 2008 03:09:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.rantsandstuff.com/?p=21#comment-123</guid>
		<description>Bwahahahaha... You can always count on someone named John/Jon to make some sense of a situation!</description>
		<content:encoded><![CDATA[<p>Bwahahahaha&#8230; You can always count on someone named John/Jon to make some sense of a situation!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://rantsandstuff.com/2008/07/28/apples-mobileme-web-apps-dont-use-https/comment-page-1/#comment-122</link>
		<dc:creator>John</dc:creator>
		<pubDate>Sat, 09 Aug 2008 12:47:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.rantsandstuff.com/?p=21#comment-122</guid>
		<description>There&#039;s no need to use https/ssl with email.  Why?  email is more analogous to post cards than mail.  Any sysadmin can read email that passes through his/her systems.  If you want to protect email, you need to use digital certificates or PGP/GPG to encrypt the message.

without proper encryption sensitive info should NEVER be sent via email.</description>
		<content:encoded><![CDATA[<p>There&#8217;s no need to use https/ssl with email.  Why?  email is more analogous to post cards than mail.  Any sysadmin can read email that passes through his/her systems.  If you want to protect email, you need to use digital certificates or PGP/GPG to encrypt the message.</p>
<p>without proper encryption sensitive info should NEVER be sent via email.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad</title>
		<link>http://rantsandstuff.com/2008/07/28/apples-mobileme-web-apps-dont-use-https/comment-page-1/#comment-87</link>
		<dc:creator>Brad</dc:creator>
		<pubDate>Wed, 30 Jul 2008 18:46:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.rantsandstuff.com/?p=21#comment-87</guid>
		<description>It&#039;s still interesting to me though that they only use SSL on part of the site and not all of it.  As some people have commented, it&#039;s not just my password and credit card number that I want encrypted...</description>
		<content:encoded><![CDATA[<p>It&#8217;s still interesting to me though that they only use SSL on part of the site and not all of it.  As some people have commented, it&#8217;s not just my password and credit card number that I want encrypted&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan</title>
		<link>http://rantsandstuff.com/2008/07/28/apples-mobileme-web-apps-dont-use-https/comment-page-1/#comment-86</link>
		<dc:creator>Jonathan</dc:creator>
		<pubDate>Wed, 30 Jul 2008 18:09:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.rantsandstuff.com/?p=21#comment-86</guid>
		<description>Good stuff to know - at least Apple is taking security into consideration, even if they do still leave email out.  Now I&#039;ll feel better about eventually buying a Mac when I&#039;m able... :)</description>
		<content:encoded><![CDATA[<p>Good stuff to know &#8211; at least Apple is taking security into consideration, even if they do still leave email out.  Now I&#8217;ll feel better about eventually buying a Mac when I&#8217;m able&#8230; :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad</title>
		<link>http://rantsandstuff.com/2008/07/28/apples-mobileme-web-apps-dont-use-https/comment-page-1/#comment-77</link>
		<dc:creator>Brad</dc:creator>
		<pubDate>Mon, 28 Jul 2008 20:55:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.rantsandstuff.com/?p=21#comment-77</guid>
		<description>The source of the info was from the article on Daring Fireball.net and was not verified by us.  I simply gave my opinion on that post.  We will try to conduct our own tests and update the post if necessary.  Thanks for the heads up ben.</description>
		<content:encoded><![CDATA[<p>The source of the info was from the article on Daring Fireball.net and was not verified by us.  I simply gave my opinion on that post.  We will try to conduct our own tests and update the post if necessary.  Thanks for the heads up ben.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jon</title>
		<link>http://rantsandstuff.com/2008/07/28/apples-mobileme-web-apps-dont-use-https/comment-page-1/#comment-76</link>
		<dc:creator>jon</dc:creator>
		<pubDate>Mon, 28 Jul 2008 20:45:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.rantsandstuff.com/?p=21#comment-76</guid>
		<description>That is very possible Ben. Thanks for doing the legwork and letting us know. I&#039;d like to do a sniff when I get home today and I&#039;ll look into it. Note that the source of the info was not from captures that we had performed. I also find it funny that if you are correct that no one else has caught it, that I am aware of, and that everyone assumed it to be true. Oh, the power of assumption. 

To back up the people who have posted comments, we haven&#039;t actually argued the validity of the post yet, but why it is (or isn&#039;t :)) important to pass some info via HTTPS.</description>
		<content:encoded><![CDATA[<p>That is very possible Ben. Thanks for doing the legwork and letting us know. I&#8217;d like to do a sniff when I get home today and I&#8217;ll look into it. Note that the source of the info was not from captures that we had performed. I also find it funny that if you are correct that no one else has caught it, that I am aware of, and that everyone assumed it to be true. Oh, the power of assumption. </p>
<p>To back up the people who have posted comments, we haven&#8217;t actually argued the validity of the post yet, but why it is (or isn&#8217;t :)) important to pass some info via HTTPS.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ben</title>
		<link>http://rantsandstuff.com/2008/07/28/apples-mobileme-web-apps-dont-use-https/comment-page-1/#comment-75</link>
		<dc:creator>ben</dc:creator>
		<pubDate>Mon, 28 Jul 2008 20:30:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.rantsandstuff.com/?p=21#comment-75</guid>
		<description>I did a packet sniff and it appeared that the asynchronous information is sent SSL over port 443.

With a web 2.0 page like this, isn&#039;t it possible that the basic page template is non-SSL, but all asynchronous calls for data are done over SSL?

In other words, are you guys SURE this isn&#039;t secure, or are you just guessing because it doesn&#039;t say https:// in the URL?</description>
		<content:encoded><![CDATA[<p>I did a packet sniff and it appeared that the asynchronous information is sent SSL over port 443.</p>
<p>With a web 2.0 page like this, isn&#8217;t it possible that the basic page template is non-SSL, but all asynchronous calls for data are done over SSL?</p>
<p>In other words, are you guys SURE this isn&#8217;t secure, or are you just guessing because it doesn&#8217;t say https:// in the URL?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad</title>
		<link>http://rantsandstuff.com/2008/07/28/apples-mobileme-web-apps-dont-use-https/comment-page-1/#comment-74</link>
		<dc:creator>Brad</dc:creator>
		<pubDate>Mon, 28 Jul 2008 17:42:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.rantsandstuff.com/?p=21#comment-74</guid>
		<description>Thanks for the comments everyone.  Hopefully we&#039;ll have a forum up in the future for discussions like this.

Sorry Jon, I&#039;m going to stick to my guns on this one.  My reasoning is, why not use HTTPS?  Again, it can&#039;t be hard to implement and James is right, if it&#039;s supposed to be &quot;Exchange like&quot; then make it secure.</description>
		<content:encoded><![CDATA[<p>Thanks for the comments everyone.  Hopefully we&#8217;ll have a forum up in the future for discussions like this.</p>
<p>Sorry Jon, I&#8217;m going to stick to my guns on this one.  My reasoning is, why not use HTTPS?  Again, it can&#8217;t be hard to implement and James is right, if it&#8217;s supposed to be &#8220;Exchange like&#8221; then make it secure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan</title>
		<link>http://rantsandstuff.com/2008/07/28/apples-mobileme-web-apps-dont-use-https/comment-page-1/#comment-73</link>
		<dc:creator>Jonathan</dc:creator>
		<pubDate>Mon, 28 Jul 2008 16:55:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.rantsandstuff.com/?p=21#comment-73</guid>
		<description>My argument for needing HTTPS is simply that although people *shouldn&#039;t* put personal information in email, etc., is that they still *do*.  No, that doesn&#039;t make it Apple&#039;s problem, but most software companies are taking precautions these days anyway, for their users&#039; protection.

At the same time, I usually take the stance that if somebody wants to find something out about me, they will whether I volunteer the information or not.</description>
		<content:encoded><![CDATA[<p>My argument for needing HTTPS is simply that although people *shouldn&#8217;t* put personal information in email, etc., is that they still *do*.  No, that doesn&#8217;t make it Apple&#8217;s problem, but most software companies are taking precautions these days anyway, for their users&#8217; protection.</p>
<p>At the same time, I usually take the stance that if somebody wants to find something out about me, they will whether I volunteer the information or not.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
