<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Jazoon &#8217;09: RIA and Security</title>
	<atom:link href="http://www.canoo.com/blog/2009/06/23/jazoon-09-ria-and-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.canoo.com/blog/2009/06/23/jazoon-09-ria-and-security/</link>
	<description></description>
	<lastBuildDate>Tue, 20 Dec 2011 10:26:36 +0100</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: M</title>
		<link>http://www.canoo.com/blog/2009/06/23/jazoon-09-ria-and-security/comment-page-1/#comment-97601</link>
		<dc:creator>M</dc:creator>
		<pubDate>Thu, 02 Jul 2009 10:08:13 +0000</pubDate>
		<guid isPermaLink="false">http://canoo.com/blog/?p=451#comment-97601</guid>
		<description>&quot; A secure transaction in this technical setting will operate under HTTPS, which in most instances will deal with this kind of attack.&quot;

HTTPS wont deal with that kind of attacks at all.

If connection is secure it only means that attack is taking place on encrypted connection. Encryption only secures man-in-the-middle type attacks.</description>
		<content:encoded><![CDATA[<p>&#8221; A secure transaction in this technical setting will operate under HTTPS, which in most instances will deal with this kind of attack.&#8221;</p>
<p>HTTPS wont deal with that kind of attacks at all.</p>
<p>If connection is secure it only means that attack is taking place on encrypted connection. Encryption only secures man-in-the-middle type attacks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joonas Lehtinen</title>
		<link>http://www.canoo.com/blog/2009/06/23/jazoon-09-ria-and-security/comment-page-1/#comment-97045</link>
		<dc:creator>Joonas Lehtinen</dc:creator>
		<pubDate>Tue, 23 Jun 2009 15:42:45 +0000</pubDate>
		<guid isPermaLink="false">http://canoo.com/blog/?p=451#comment-97045</guid>
		<description>I only gave some examples of frameworks. For server driven frameworks, only ICEFaces and Vaadin were mentioned. Canoos framework is also server driven and thus should have the same architectural security benefits as Vaadin does. The fundamental differences being that Canoo requires Java runtime on client-side  and is commercial, while as Vaadin doesn\&#039;t require any plugins and is free and open source (Apache 2.0).

From the security point of view server driven frameworks (including Canoo) are just superior to client side frameworks. Client side frameworks have other benefits that server driven doesn\&#039;t. Still the presentation was about security.  

I\&#039;ll be around for the whole week - come to discuss more about the security on our booth.

- Joonas</description>
		<content:encoded><![CDATA[<p>I only gave some examples of frameworks. For server driven frameworks, only ICEFaces and Vaadin were mentioned. Canoos framework is also server driven and thus should have the same architectural security benefits as Vaadin does. The fundamental differences being that Canoo requires Java runtime on client-side  and is commercial, while as Vaadin doesn\&#8217;t require any plugins and is free and open source (Apache 2.0).</p>
<p>From the security point of view server driven frameworks (including Canoo) are just superior to client side frameworks. Client side frameworks have other benefits that server driven doesn\&#8217;t. Still the presentation was about security.  </p>
<p>I\&#8217;ll be around for the whole week &#8211; come to discuss more about the security on our booth.</p>
<p>- Joonas</p>
]]></content:encoded>
	</item>
</channel>
</rss>

