<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Securing web services in a world with few options</title>
	<atom:link href="http://cemerick.com/2010/02/19/securing-web-services-in-a-world-with-few-options/feed/" rel="self" type="application/rss+xml" />
	<link>http://cemerick.com/2010/02/19/securing-web-services-in-a-world-with-few-options/</link>
	<description>Against all odds.</description>
	<lastBuildDate>Wed, 08 Feb 2012 21:48:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Securing web services in a world with few options (via cemerick) &#171; BOINK</title>
		<link>http://cemerick.com/2010/02/19/securing-web-services-in-a-world-with-few-options/#comment-459</link>
		<dc:creator><![CDATA[Securing web services in a world with few options (via cemerick) &#171; BOINK]]></dc:creator>
		<pubDate>Sun, 20 Mar 2011 01:41:35 +0000</pubDate>
		<guid isPermaLink="false">http://cemerick.com/?p=318#comment-459</guid>
		<description><![CDATA[[...] Thanks cemerick. Maybe HTTP authentication (basic or digest) over SSL is good enough. Especially to avoid wasting resources and to just get it done.  Assuming I can avoid an ugly browser authentication dialog, which is what I&#8217;m going to look into next&#8230; Prelude We&#8217;re building a web service for which we aim to charge money. Further, the data being pushed around may be confidential or otherwise of a sensitive nature. We have good reasons to do everything we can to ensure that the service is secured &#8220;properly&#8221;: We don&#8217;t want to have customers charged for work that is requested by a bad actor exploiting a security hole (of course, we&#8217;d issue a refund and an apology in such a case, but the impact to … Read More [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Thanks cemerick. Maybe HTTP authentication (basic or digest) over SSL is good enough. Especially to avoid wasting resources and to just get it done.  Assuming I can avoid an ugly browser authentication dialog, which is what I&#8217;m going to look into next&#8230; Prelude We&#8217;re building a web service for which we aim to charge money. Further, the data being pushed around may be confidential or otherwise of a sensitive nature. We have good reasons to do everything we can to ensure that the service is secured &#8220;properly&#8221;: We don&#8217;t want to have customers charged for work that is requested by a bad actor exploiting a security hole (of course, we&#8217;d issue a refund and an apology in such a case, but the impact to … Read More [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

