Search the web
Sign In
New User? Sign Up
aggregators
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Show off your group to the world. Share a photo of your group with us.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Slightly OT: Ask Yahoo to enable RSS authentication for groups   Message List  
Reply | Forward Message #804 of 818 |
Re: Slightly OT: Ask Yahoo to enable RSS authentication for groups

--- In aggregators@yahoogroups.com, Jeremy Zawodny <jzawodn@...> wrote:
>
> Believe it or not, we got the message a while ago...
>
> But it's a non-trivial change to our infrastructure and one not to be
> taken lightly.
>
> Jeremy

Thanks for replying, Jeremy. I'm glad the message got to the right people.

Perhaps looking at the way livejournal has implemented RSS authentication would
be
helpful. They set it up so "friends only" post could be viewed in RSS feeds.
Their RSS url is
like this:
https://MY_LIVEJOURNAL_USERNAME:MY_LIVEJOURNAL_PASSWORD@www.livejournal.com/
users/MY_FRIEND'S_USERNAME/data/rss?auth=digest

Sniffing the traffic, it looks like Livejournal is using MD5.

The security question:
Is their RSS authentication secure enough? I.e. can I leave my feedreader
refreshing every
30 minutes even when I'm on an open wi-fi connection without fear that my
livejournal
password will be compromised?

I asked this same basic question in an offtopic comment on this slashdot
article:
LiveJournal XSS Security Challenge
http://it.slashdot.org/article.pl?sid=06/01/31/1324257

Someone replied:
http://it.slashdot.org/comments.pl?sid=175728&pid=14607767#14607982
Digest auth (which I assume from the URL is what LJ is using here) uses a
one-time nonce
as a challenge, so capturing your response would not benefit an attacker since
the same
response cannot be replayed. Also, the MD5 hash you're seeing your client send
is based
not only on your password and the nonce but also on the HTTP method being used
and
the URI being requested. Digest auth does have its flaws, but I think it's
secure enough for
this purpose.

I found a good article about private rss feeds here:
http://labs.silverorange.com/archives/2003/july/privaterss

I hope that info helps.
Thanks for listening,
Simon






Thu Mar 2, 2006 5:43 pm

sdorfman.rm
Offline Offline
Send Email Send Email

Forward
Message #804 of 818 |
Expand Messages Author Sort by Date

Sorry for the slight off-topic-ness of this post, but I'm trying to get Yahoo to enable RSS authentication so I can keep up with several yahoo groups (that...
sdorfman.rm
Offline Send Email
Feb 28, 2006
8:04 am

Believe it or not, we got the message a while ago... But it's a non-trivial change to our infrastructure and one not to be taken lightly. Jeremy...
Jeremy Zawodny
jzawodn
Offline Send Email
Mar 1, 2006
6:51 am

... Thanks for replying, Jeremy. I'm glad the message got to the right people. Perhaps looking at the way livejournal has implemented RSS authentication would...
sdorfman.rm
Offline Send Email
Mar 2, 2006
5:43 pm

sdorfman.rm <sdorfman@...> Tue, 28 Feb 2006 06:34:43 ... I've reached the conclusion that "private" RSS feeds that require authentication is a bad...
Julian Bond
jbond23uk
Offline Send Email
Mar 6, 2006
12:57 pm

... I disagree. ... Automated apps wouldn't have the auth keys. Thus the feed would never get seen by them. ... The existance of the RSS feed URL can't be...
Bill Kearney
wkearney99
Offline Send Email
Mar 11, 2006
12:39 pm

Jeremy Zawodny is asking for suggestions on how to bring Yahoo Groups up to date on his blog. http://jeremy.zawodny.com/blog/archives/006541.html ... never get...
Nick Dynice
nsputnik
Offline Send Email
Mar 31, 2006
7:25 pm
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help