<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Add-on Security Restrictions Landed</title>
	<atom:link href="http://www.oxymoronical.com/blog/2007/09/Add-on-Security-Restrictions-Landed/feed" rel="self" type="application/rss+xml" />
	<link>http://www.oxymoronical.com/blog/2007/09/Add-on-Security-Restrictions-Landed</link>
	<description>Spouting nonsense from the depths of my spare time</description>
	<lastBuildDate>Sat, 14 Jan 2012 22:20:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Steffen Wilberg</title>
		<link>http://www.oxymoronical.com/blog/2007/09/Add-on-Security-Restrictions-Landed#comment-18</link>
		<dc:creator>Steffen Wilberg</dc:creator>
		<pubDate>Tue, 04 Sep 2007 21:25:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.oxymoronical.com/blog/2007/09/Add-on-Security-Restrictions-Landed#comment-18</guid>
		<description>StartSSL offers free SSL certs:&lt;br&gt;

https://www.startssl.com/?app=1&lt;br&gt;

&lt;br&gt;

Just go and get one for your server.</description>
		<content:encoded><![CDATA[<p>StartSSL offers free SSL certs:</p>
<p><a href="https://www.startssl.com/?app=1" rel="nofollow">https://www.startssl.com/?app=1</a></p>
<p>Just go and get one for your server.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dafi</title>
		<link>http://www.oxymoronical.com/blog/2007/09/Add-on-Security-Restrictions-Landed#comment-17</link>
		<dc:creator>dafi</dc:creator>
		<pubDate>Tue, 04 Sep 2007 06:44:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.oxymoronical.com/blog/2007/09/Add-on-Security-Restrictions-Landed#comment-17</guid>
		<description>Please don&#039;t hate me but I&#039;m not sure this approach is correct for poor extension&#039;s authors like me.&lt;br&gt;

AMO doesn&#039;t publish my extensions because Remora app uses the ugly sandbox model.&lt;br&gt;

- Many extensions live in sandbox for eternity so I can&#039;t use the AMO security trust&lt;br&gt;

- I&#039;ve my site on sourceforge the best free FOSS web space but I haven&#039;t SSL support&lt;br&gt;

So I must buy HTTPS space and buy a certificate.&lt;br&gt;

The self signed key seems the only way possibile for poor programmers.&lt;br&gt;

&lt;br&gt;

Why disabling extension?? Should be simpler disable *only* update so user know he/she must check for new version.&lt;br&gt;

I understand this can be awful but user can continue to use extensions&lt;br&gt;

&lt;br&gt;

thanks&lt;br&gt;

dafi&lt;br&gt;</description>
		<content:encoded><![CDATA[<p>Please don&#8217;t hate me but I&#8217;m not sure this approach is correct for poor extension&#8217;s authors like me.</p>
<p>AMO doesn&#8217;t publish my extensions because Remora app uses the ugly sandbox model.</p>
<p>- Many extensions live in sandbox for eternity so I can&#8217;t use the AMO security trust</p>
<p>- I&#8217;ve my site on sourceforge the best free FOSS web space but I haven&#8217;t SSL support</p>
<p>So I must buy HTTPS space and buy a certificate.</p>
<p>The self signed key seems the only way possibile for poor programmers.</p>
<p>Why disabling extension?? Should be simpler disable *only* update so user know he/she must check for new version.</p>
<p>I understand this can be awful but user can continue to use extensions</p>
<p>thanks</p>
<p>dafi</p>
]]></content:encoded>
	</item>
</channel>
</rss>

