<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Wil Tan &#187; firefox</title>
	<atom:link href="http://dready.org/blog/category/firefox/feed/" rel="self" type="application/rss+xml" />
	<link>http://dready.org/blog</link>
	<description>musings on internationalized identifiers: domain names, OpenID, TLDs</description>
	<lastBuildDate>Thu, 15 Dec 2011 03:42:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>FoXRI Updated for Firefox 3</title>
		<link>http://dready.org/blog/2008/10/18/foxri-updated-for-firefox-3/</link>
		<comments>http://dready.org/blog/2008/10/18/foxri-updated-for-firefox-3/#comments</comments>
		<pubDate>Fri, 17 Oct 2008 18:05:22 +0000</pubDate>
		<dc:creator>wil</dc:creator>
				<category><![CDATA[firefox]]></category>
		<category><![CDATA[foxri]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[xri]]></category>

		<guid isPermaLink="false">http://dready.org/blog/?p=178</guid>
		<description><![CDATA[Prompted by Emanuel in a comment to my post on i-names, I&#8217;ve finally tended to the long-overdue item in my TODO queue, i.e. update FoXRI to work with Firefox 3. The request from Emanuel came almost serendipitously 2 days after =les nonchalantly asked me if I had plans to update it to FF3, to which [...]
No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Prompted by <a href="http://jaudo.com/">Emanuel</a> in a comment to <a href="http://dready.org/blog/2006/07/10/whats-in-an-i-name/">my post on i-names</a>, I&#8217;ve finally tended to the long-overdue item in my TODO queue, i.e. update <a href="http://foxri.sourceforge.net/">FoXRI</a> to work with Firefox 3.</p>
<p>The request from Emanuel came almost serendipitously 2 days after <a href="xri://=les">=les</a> nonchalantly asked me if I had plans to update it to FF3, to which I answered &#8220;one of these days.&#8221;</p>
<p>New in this version are 2 patches from <a href="http://www.plaxo.com/directory/profile/90194353111/1159c0c6/Michael/Krelin">Michael Krelin</a> which adds detection of URIs for more OpenID versions, and the handling of <code>append</code> attribute values. Changelog for the patches are available at <a href="http://git.klever.net/view/cgit/patchwork/foxri.git/">his git repository</a>.<br />
Thanks, Michael!</p>
<p>Due to what seems like a new security restriction that protocol handlers are not allowed to link to chrome URIs, I can&#8217;t seem to get it to load the CSS and icons from the chrome any more. Therefore, those files are now hosted remotely at <a href="http://xrid.net/">xrid.net</a> so if you see requests to that host, please don&#8217;t be alarmed.</p>
<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://dready.org/blog/2008/10/18/foxri-updated-for-firefox-3/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Security Restricted Domains Database</title>
		<link>http://dready.org/blog/2007/01/22/security-restricted-domains-database/</link>
		<comments>http://dready.org/blog/2007/01/22/security-restricted-domains-database/#comments</comments>
		<pubDate>Sun, 21 Jan 2007 16:25:45 +0000</pubDate>
		<dc:creator>wil</dc:creator>
				<category><![CDATA[dns]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[idn]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://dready.org/blog/2007/01/22/security-restricted-domains-database/</guid>
		<description><![CDATA[This was going to be a &#8220;Dear LazyWeb&#8221; request, but after some research I found what I wanted. Recent discussions about security and phishing on the OpenID list got me thinking about the problem space. DNS plays a critical role in the security of OpenID because URL is the identifier type used User should only [...]
No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>This was going to be a &#8220;<a href="http://www.lazyweb.org/">Dear LazyWeb</a>&#8221; request, but after some research I found what I wanted.</p>
<p><a href="http://openid.net/pipermail/general/2007-January/thread.html#1219">Recent discussions</a> about security and phishing on the OpenID list got me thinking about the problem space.</p>
<p>DNS plays a critical role in the security of OpenID because</p>
<ol>
<li>URL is the identifier type used</li>
<li>User should only trust the <acronym title="OpenID Provider">OP</acronym> with which he/she has an account with.</li>
</ol>
<p>The &#8220;Phishing and OpenID&#8221; discussions on the OpenID list actually hinges on point #2 above. <a href="http://www.links.org/?p=187">Ben Laurie wrote about it here</a>. In short, OpenID opens the door for a malicious <acronym title="Relying Party">RP</acronym> to send a user to a spoofed OP-lookalike and collect his/her password.</p>
<p>Back to DNS. I have, on numerous occasions in the past, tried to look for a list of domains where registrations are open for public. This varies from TLD to TLD, e.g. <em>.biz</em> accepts registration directly on the second level, <em>.us</em> also does but delegates two-letter subdomains to US states, and <em>.uk</em> only accepts registrations on the third level after <em>.co.uk</em>, <em>.ac.uk</em>, etc.</p>
<p>Well, it turns out that the Mozilla folks needed this list in order to disallow web sites setting cookies for the entire <em>.co.uk</em> or similar domains. Currently, they block just the TLDs so <em>example.com</em> cannot set a cookie for <em>.com</em>, but 2nd level onwards domain cookies are allowed. This could easily cause cookies to be stolen by any site rooted in the same domain.</p>
<p>So, <a href="http://www.westpoint.ltd.uk/advisories/wp-04-0001.txt">this advisory</a> started <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=252342">this bugzilla entry</a> at Mozilla and it eventually led to the creation of <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=331510" title="Add knowledge of subdomains to necko (create nsEffectiveTLDService)">this API</a> and <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=342314" title="Need effective-TLD file">this list (see attachment)</a>. They call it the <a href="http://wiki.mozilla.org/Gecko:TLD_Service">&#8220;Effective TLD&#8221; list</a>, which is really a misnomer because they are not necessary just <acronym title="Top Level Domains">TLDs</acronym>. It was decided in the bug discussions that the term &#8220;effective TLD&#8221; is easier to digest that anything else, though I&#8217;d prefer to call it &#8220;Security Restricted Domains&#8221;. Whatever, as long as it gives me the content I want.</p>
<p>Many will probably criticize Mozilla for creating yet another list that gets stale the moment it is created. Indeed, TLDs get created and 2LDs within TLDs are introduced and deprecated so often that such a list will be hard to maintain. Moreover, many organizations assign names to registrants at a level that doesn&#8217;t involve the TLD registry. Examples include CentralNIC&#8217;s <em>.&lt;country-code&gt;.com</em> and <em>*.blogspot.com</em>, and countless others. Add to it the introduction of IDN TLD may well be in less than 2 years. Keeping a definitive list is not feasible. Nevertheless, I would argue that depending on your needs, this list could still be very valuable, as is the case with the cookie problem that they are trying to solve.</p>
<p>So, what has this got to do with OpenID? I shall leave that to a different post.</p>
<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://dready.org/blog/2007/01/22/security-restricted-domains-database/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>FoXRI updated for Firefox 2.0</title>
		<link>http://dready.org/blog/2006/11/04/foxri-updated-for-firefox-20/</link>
		<comments>http://dready.org/blog/2006/11/04/foxri-updated-for-firefox-20/#comments</comments>
		<pubDate>Sat, 04 Nov 2006 12:09:22 +0000</pubDate>
		<dc:creator>wil</dc:creator>
				<category><![CDATA[firefox]]></category>
		<category><![CDATA[foxri]]></category>
		<category><![CDATA[iname]]></category>
		<category><![CDATA[xri]]></category>

		<guid isPermaLink="false">http://dready.org/blog/2006/11/04/foxri-updated-for-firefox-20/</guid>
		<description><![CDATA[Just a quick mention that I&#8217;ve updated FoXRI to be compatible to Firefox 2.0. I haven&#8217;t had time to implement URI construction (which explains why some URI links don&#8217;t work in the FoXRI explorer). Thanks to Gabe and Ken Walsh for the reminder. No related posts. Related posts brought to you by Yet Another Related [...]
No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Just a quick mention that I&#8217;ve updated <a href="http://xri.dready.org/">FoXRI</a> to be compatible to Firefox 2.0. I haven&#8217;t had time to implement URI construction (which explains why some URI links don&#8217;t work in the FoXRI explorer).</p>
<p>Thanks to <a href="http://blog.wachob.com/">Gabe</a> and <a href="http://xreye.com/">Ken Walsh</a> for the reminder.</p>
<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://dready.org/blog/2006/11/04/foxri-updated-for-firefox-20/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New FoXRI Out Now</title>
		<link>http://dready.org/blog/2006/08/21/new-foxri-out-now/</link>
		<comments>http://dready.org/blog/2006/08/21/new-foxri-out-now/#comments</comments>
		<pubDate>Mon, 21 Aug 2006 03:53:12 +0000</pubDate>
		<dc:creator>wil</dc:creator>
				<category><![CDATA[firefox]]></category>
		<category><![CDATA[flock]]></category>
		<category><![CDATA[foxri]]></category>
		<category><![CDATA[xri]]></category>

		<guid isPermaLink="false">http://dready.org/blog/2006/08/21/new-foxri-out-now/</guid>
		<description><![CDATA[I&#8217;ve just released version 1.1 of FoXRI &#8211; XRI extension for Firefox (and Flock!). This version features an XRDS explorer that renders an XRI (I-name or I-number) in a nice user interface (see screenshot below). Go install it at xri://=wil (oh you&#8217;re not XRI-enabled yet? No problem, go here instead). Under the hood The extension [...]
No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve just released version 1.1 of FoXRI &#8211; XRI extension for Firefox (and <a href="http://flock.com/">Flock</a>!).</p>
<p>This version features an XRDS explorer that renders an XRI (I-name or I-number) in a nice user interface (see screenshot below).</p>
<p>Go install it at <a href="xri://=wil">xri://=wil</a> (oh you&#8217;re not XRI-enabled yet? No problem, go <a href="http://xri.dready.org/=wil">here</a> instead).</p>
<p><img src="http://xri.dready.org/media/images/foxri-1.1-flock-shot.jpg" /></p>
<p><br/>
</p>
<p><H5>Under the hood</H5>
<p>The extension installs an XUL overlay that autocorrects an I-name / I-number in shorthand notation (e.g. =wil or @neustar) to the full version with &#8220;xri://&#8221; prefix. This is only for XRIs entered on the URL bar. Everything else is left untouched and functions as per normal.</p>
<p>At the same time, it installs an XRI protocol handler (XPCOM component implemented in Javascript) that takes care of resolving the XRI. For &#8220;bare&#8221; XRI &#8211; no path or query e.g. xri://=wil , it fetches the XRDS document from the xri.net proxy and renders it in HTML. Otherwise, the XRI is simply prefixed with http://xri.net/ and hands it off to the normal HTTP handler.<br/>
</p>
<p><!-- technorati tags begin -->
<p style="font-size:10px;text-align:right;">technorati tags:<a href="http://technorati.com/tag/xri" rel="tag">xri</a>, <a href="http://technorati.com/tag/iname" rel="tag">iname</a>, <a href="http://technorati.com/tag/foxri" rel="tag">foxri</a>, <a href="http://technorati.com/tag/firefox" rel="tag">firefox</a></p>
<p><!-- technorati tags end -->
<p style="text-align: right; font-size: 8px">Blogged with <a href="http://www.flock.com" title="Flock" target="_new">Flock</a></p>
<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://dready.org/blog/2006/08/21/new-foxri-out-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I&#8217;m Flocked</title>
		<link>http://dready.org/blog/2006/08/21/im-flocked/</link>
		<comments>http://dready.org/blog/2006/08/21/im-flocked/#comments</comments>
		<pubDate>Mon, 21 Aug 2006 02:50:46 +0000</pubDate>
		<dc:creator>wil</dc:creator>
				<category><![CDATA[firefox]]></category>
		<category><![CDATA[flock]]></category>

		<guid isPermaLink="false">http://dready.org/blog/2006/08/21/im-flocked/</guid>
		<description><![CDATA[Just downloaded flock and am totally lovin&#8217; it. Being able to manage my flickr and photobucket account with drag-n-drop and a feed reader that rocks plus all host of goodies tucked in unobtrusive corners are just the beginning. Buit on the Firefox engine, Flock supports all the extensions that are built for Firefox. This post [...]
No related posts.

Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p><a href="http://flock.com/" title="Flock: The web browser for you and your friends."><img border="0" alt="Flock: The web browser for you and your friends." src="http://www.flock.com/images/banners/Get_flock_88x31_black.png" /></a><br />
<br/></p>
<p>Just downloaded flock and am totally lovin&#8217; it. Being able to manage my flickr and photobucket account with drag-n-drop and a feed reader that rocks plus all host of goodies tucked in unobtrusive corners are just the beginning. Buit on the Firefox engine, Flock supports all the extensions that are built for Firefox.</p>
<p>This post was created using Flock&#8217;s built-in blog composer &#8211; what can I say?</p>
<p><strong>I&#8217;m totally flocked!</strong></p>
<p><!-- technorati tags begin -->
<p style="font-size:10px;text-align:right;">technorati tags:<a href="http://technorati.com/tag/web2.0" rel="tag">web2.0</a>, <a href="http://technorati.com/tag/flock" rel="tag">flock</a></p>
<p><!-- technorati tags end -->
<p style="text-align: right; font-size: 8px">Blogged with <a href="http://www.flock.com" title="Flock" target="_new">Flock</a></p>
<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://yarpp.org'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://dready.org/blog/2006/08/21/im-flocked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

