<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Nonces and WordPress</title>
	<atom:link href="http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/</link>
	<description>We only do fun stuff.</description>
	<pubDate>Sun, 12 Oct 2008 12:01:51 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: Paul Mitchell aka Libertus</title>
		<link>http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-14000</link>
		<dc:creator>Paul Mitchell aka Libertus</dc:creator>
		<pubDate>Fri, 02 Jun 2006 21:27:52 +0000</pubDate>
		<guid isPermaLink="false">http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-14000</guid>
		<description>&lt;p&gt;I tend to check validity once or twince when invited to do so by such quality statements as "Valid XHTML". &lt;em&gt;Truly&lt;/em&gt; caught my attention.&lt;/p&gt;

&lt;p&gt;The page validated. I'm looking at the plugin.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I tend to check validity once or twince when invited to do so by such quality statements as &#8220;Valid XHTML&#8221;. <em>Truly</em> caught my attention.</p>

<p>The page validated. I&#8217;m looking at the plugin.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Rudd-O</title>
		<link>http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13950</link>
		<dc:creator>Rudd-O</dc:creator>
		<pubDate>Fri, 02 Jun 2006 19:04:34 +0000</pubDate>
		<guid isPermaLink="false">http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13950</guid>
		<description>&lt;p&gt;It's okay, David.  You were right all along.  Thanks for the swift heads-up -- you made me realize my mistake early enough.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>It&#8217;s okay, David.  You were right all along.  Thanks for the swift heads-up &#8212; you made me realize my mistake early enough.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: David House</title>
		<link>http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13949</link>
		<dc:creator>David House</dc:creator>
		<pubDate>Fri, 02 Jun 2006 19:02:44 +0000</pubDate>
		<guid isPermaLink="false">http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13949</guid>
		<description>&lt;p&gt;For the record, I'll take back my first commen, now you've amended your post:&lt;/p&gt;

&lt;p&gt;"Instead of implementing nonces" -&#62; "Instead of implmenting nonces alone"&lt;/p&gt;

&lt;p&gt;I'm in accord with the latter.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>For the record, I&#8217;ll take back my first commen, now you&#8217;ve amended your post:</p>

<p>&#8220;Instead of implementing nonces&#8221; -&gt; &#8220;Instead of implmenting nonces alone&#8221;</p>

<p>I&#8217;m in accord with the latter.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Rudd-O</title>
		<link>http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13948</link>
		<dc:creator>Rudd-O</dc:creator>
		<pubDate>Fri, 02 Jun 2006 18:55:28 +0000</pubDate>
		<guid isPermaLink="false">http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13948</guid>
		<description>&lt;p&gt;BTW, which IRC server is #wordpress in?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>BTW, which IRC server is #wordpress in?</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Rudd-O</title>
		<link>http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13947</link>
		<dc:creator>Rudd-O</dc:creator>
		<pubDate>Fri, 02 Jun 2006 18:54:27 +0000</pubDate>
		<guid isPermaLink="false">http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13947</guid>
		<description>&lt;p&gt;Hope you didn't catch the page in an invalid state.  Been editing and "Saving and continuing" just right now.&lt;/p&gt;

&lt;p&gt;To everyone in this post: thanks for your contributions and comments.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hope you didn&#8217;t catch the page in an invalid state.  Been editing and &#8220;Saving and continuing&#8221; just right now.</p>

<p>To everyone in this post: thanks for your contributions and comments.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Mitchell aka Libertus</title>
		<link>http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13946</link>
		<dc:creator>Paul Mitchell aka Libertus</dc:creator>
		<pubDate>Fri, 02 Jun 2006 18:52:39 +0000</pubDate>
		<guid isPermaLink="false">http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13946</guid>
		<description>&lt;p&gt;&lt;em&gt;Truly Valid&lt;/em&gt;. Very nice.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p><em>Truly Valid</em>. Very nice.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Rudd-O</title>
		<link>http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13945</link>
		<dc:creator>Rudd-O</dc:creator>
		<pubDate>Fri, 02 Jun 2006 18:51:25 +0000</pubDate>
		<guid isPermaLink="false">http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13945</guid>
		<description>&lt;p&gt;Thanks for your contribution, David.&lt;/p&gt;

&lt;p&gt;But I'm still convinced that nonces should have been introduced with the corresponding move to POSTs.  As you can see, rather than disagreeing, we agree on the basic issues.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Thanks for your contribution, David.</p>

<p>But I&#8217;m still convinced that nonces should have been introduced with the corresponding move to POSTs.  As you can see, rather than disagreeing, we agree on the basic issues.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Mitchell aka Libertus</title>
		<link>http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13943</link>
		<dc:creator>Paul Mitchell aka Libertus</dc:creator>
		<pubDate>Fri, 02 Jun 2006 18:49:52 +0000</pubDate>
		<guid isPermaLink="false">http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13943</guid>
		<description>&lt;p&gt;ringmaster on #wordpress linked the channel to your site, which is how I found you.&lt;/p&gt;

&lt;p&gt;The GET/POST stuff will be cleaned up over time, especially if people with the necessary programmming skills and technical knowledge have time and effort to donate to the project, which is heartily encouraged by the core developers.&lt;/p&gt;

&lt;p&gt;Nonces solve a more fundamental problem than the rather odd battle between GET and POST for idempotent actions. Nonces create a stronger cause-and-effect link between the page delivered and the action generated, discouraging and perhaps even negating the possibility of some computer-based attacks on your blog via your WordPress login cookies, especially if HTTP referer checks have been disabled.&lt;/p&gt;

&lt;p&gt;Pity about the choice of name. http://urbandictionary.com/nonce&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>ringmaster on #wordpress linked the channel to your site, which is how I found you.</p>

<p>The GET/POST stuff will be cleaned up over time, especially if people with the necessary programmming skills and technical knowledge have time and effort to donate to the project, which is heartily encouraged by the core developers.</p>

<p>Nonces solve a more fundamental problem than the rather odd battle between GET and POST for idempotent actions. Nonces create a stronger cause-and-effect link between the page delivered and the action generated, discouraging and perhaps even negating the possibility of some computer-based attacks on your blog via your WordPress login cookies, especially if HTTP referer checks have been disabled.</p>

<p>Pity about the choice of name. <a href="http://urbandictionary.com/nonce" rel="nofollow">http://urbandictionary.com/nonce</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: David House</title>
		<link>http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13942</link>
		<dc:creator>David House</dc:creator>
		<pubDate>Fri, 02 Jun 2006 18:44:38 +0000</pubDate>
		<guid isPermaLink="false">http://rudd-o.com/archives/2006/06/02/nonces-and-wordpress/#comment-13942</guid>
		<description>&lt;p&gt;Please don't make throwaway dismissals of WordPress policy without first informing yourself. Had you actually read the wp-hackers discussion on this, you'd have come across emails like one I sent:&lt;/p&gt;

&lt;p&gt;http://comox.textdrive.com/pipermail/wp-hackers/2006-April/005980.html&lt;/p&gt;

&lt;p&gt;I'll leave you with that thought.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Please don&#8217;t make throwaway dismissals of WordPress policy without first informing yourself. Had you actually read the wp-hackers discussion on this, you&#8217;d have come across emails like one I sent:</p>

<p><a href="http://comox.textdrive.com/pipermail/wp-hackers/2006-April/005980.html" rel="nofollow">http://comox.textdrive.com/pipermail/wp-hackers/2006-April/005980.html</a></p>

<p>I&#8217;ll leave you with that thought.</p>]]></content:encoded>
	</item>
</channel>
</rss>
