<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Security and usability - Google Chrome&#8217;s Incognito mode</title>
	<atom:link href="http://paheli.net/blog/2008/09/11/security-and-usability-google-chromes-incognito-mode/feed/" rel="self" type="application/rss+xml" />
	<link>http://paheli.net/blog/2008/09/11/security-and-usability-google-chromes-incognito-mode/</link>
	<description>Everything is a Puzzle waiting to be solved!</description>
	<pubDate>Wed, 07 Jan 2009 18:10:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Firefox Incognito / Private Browsing Mode - Part II &#124; Shantanu's Technophilic Musings</title>
		<link>http://paheli.net/blog/2008/09/11/security-and-usability-google-chromes-incognito-mode/#comment-26</link>
		<dc:creator>Firefox Incognito / Private Browsing Mode - Part II &#124; Shantanu's Technophilic Musings</dc:creator>
		<pubDate>Thu, 11 Sep 2008 19:16:50 +0000</pubDate>
		<guid isPermaLink="false">http://paheli.net/blog/?p=31#comment-26</guid>
		<description>[...] Add comments    My Sites:  My Blog &#124;  My Tech Blog &#124; Follow me on Twitter&#8212;-A few people (e.g. Varun) told me my previous post differed from the way how google chrome / Microsoft IE8 handle Incognito [...]</description>
		<content:encoded><![CDATA[<p>[...] Add comments    My Sites:  My Blog |  My Tech Blog | Follow me on Twitter&#8212;-A few people (e.g. Varun) told me my previous post differed from the way how google chrome / Microsoft IE8 handle Incognito [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shantanu Goel</title>
		<link>http://paheli.net/blog/2008/09/11/security-and-usability-google-chromes-incognito-mode/#comment-25</link>
		<dc:creator>Shantanu Goel</dc:creator>
		<pubDate>Thu, 11 Sep 2008 04:50:40 +0000</pubDate>
		<guid isPermaLink="false">http://paheli.net/blog/?p=31#comment-25</guid>
		<description>BTW just thought of a way to do the "not saving to disk" method for firefox as well. Completely hypothetical (and might work only in linux), but maybe i can do it. Wait till weekend, will try and let you know
Thanks for pointing this out, gives me something better to ponder about and do a real hack than just clicking around making a new profile and checking a few boxes... :)</description>
		<content:encoded><![CDATA[<p>BTW just thought of a way to do the &#8220;not saving to disk&#8221; method for firefox as well. Completely hypothetical (and might work only in linux), but maybe i can do it. Wait till weekend, will try and let you know<br />
Thanks for pointing this out, gives me something better to ponder about and do a real hack than just clicking around making a new profile and checking a few boxes&#8230; <img src='http://paheli.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shantanu Goel</title>
		<link>http://paheli.net/blog/2008/09/11/security-and-usability-google-chromes-incognito-mode/#comment-24</link>
		<dc:creator>Shantanu Goel</dc:creator>
		<pubDate>Thu, 11 Sep 2008 04:42:30 +0000</pubDate>
		<guid isPermaLink="false">http://paheli.net/blog/?p=31#comment-24</guid>
		<description>Yes, you are right about the usability part. Actually that should be fixable easily. I had earlier thought of doing all the above steps in a script that someone could just download and double click and be "incognito" before being able to say "voila!" :)
Or maybe firefox guys should make it more prominent. Moreover, once the "setup" is done then there is no extra efforts after that. 
Well, abt the extra options, I did check the boxes for my use but forgot to write about them :), maybe subconciously assumed that people would know about that, but yes that counts as an oversight and you are right again that usability takes a step back when there is an "extra" step involved.
About the writing to disk part, Google says that the cookies are cleared only after you close the windows and read at some places while googling that it is not, infact, clearing everything up. So, cookies definitely go to hard disk. Not sure about rest of the things going to hdd or not. Any links?
About the rest of the stuff, XSS prevention etc, I completely agree its better in chrome (though I use NoScript extension to prevent myself in firefox but its obviously better if its not needed at all).
One more thing, I'm not too well-versed with web technologies, but do you know if/what would be "legal/positive" use cases for XSS?</description>
		<content:encoded><![CDATA[<p>Yes, you are right about the usability part. Actually that should be fixable easily. I had earlier thought of doing all the above steps in a script that someone could just download and double click and be &#8220;incognito&#8221; before being able to say &#8220;voila!&#8221; <img src='http://paheli.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
Or maybe firefox guys should make it more prominent. Moreover, once the &#8220;setup&#8221; is done then there is no extra efforts after that.<br />
Well, abt the extra options, I did check the boxes for my use but forgot to write about them :), maybe subconciously assumed that people would know about that, but yes that counts as an oversight and you are right again that usability takes a step back when there is an &#8220;extra&#8221; step involved.<br />
About the writing to disk part, Google says that the cookies are cleared only after you close the windows and read at some places while googling that it is not, infact, clearing everything up. So, cookies definitely go to hard disk. Not sure about rest of the things going to hdd or not. Any links?<br />
About the rest of the stuff, XSS prevention etc, I completely agree its better in chrome (though I use NoScript extension to prevent myself in firefox but its obviously better if its not needed at all).<br />
One more thing, I&#8217;m not too well-versed with web technologies, but do you know if/what would be &#8220;legal/positive&#8221; use cases for XSS?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
