<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Is Adgregate Insecure?</title>
	<atom:link href="http://blog.redfin.com/blog/2008/09/is_adgregate_insecure.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.redfin.com/blog/2008/09/is_adgregate_insecure.html</link>
	<description>Redfin Corporate Blog</description>
	<lastBuildDate>Fri, 10 Feb 2012 02:35:37 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Matthew Dempsky</title>
		<link>http://blog.redfin.com/blog/2008/09/is_adgregate_insecure.html/comment-page-1#comment-5630</link>
		<dc:creator>Matthew Dempsky</dc:creator>
		<pubDate>Sun, 12 Apr 2009 00:49:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.redfin.com/blog/2008/09/is_adgregate_insecure.html#comment-5630</guid>
		<description>As an update to Henry&#039;s last post, their &quot;verification&quot; process is ridiculously insecure.  A coworker of mine first pointed out to me how insecure it was, and for the past week, I&#039;ve been able to break every change they&#039;ve made within half an hour of effort.

I&#039;ve tried emailing them three times now to open a direct means of communication to explain how they can actually do this verification process securely, but they keep ignoring me.  It seems they&#039;re not genuinely interested in protecting their users from phishing attacks.</description>
		<content:encoded><![CDATA[<p>As an update to Henry&#8217;s last post, their &#8220;verification&#8221; process is ridiculously insecure.  A coworker of mine first pointed out to me how insecure it was, and for the past week, I&#8217;ve been able to break every change they&#8217;ve made within half an hour of effort.</p>
<p>I&#8217;ve tried emailing them three times now to open a direct means of communication to explain how they can actually do this verification process securely, but they keep ignoring me.  It seems they&#8217;re not genuinely interested in protecting their users from phishing attacks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Henry, CEO of Adgregate</title>
		<link>http://blog.redfin.com/blog/2008/09/is_adgregate_insecure.html/comment-page-1#comment-5234</link>
		<dc:creator>Henry, CEO of Adgregate</dc:creator>
		<pubDate>Mon, 09 Feb 2009 14:54:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.redfin.com/blog/2008/09/is_adgregate_insecure.html#comment-5234</guid>
		<description>Thanks for your interest in ShopAds. I want to update your readers that each ShopAd now has a unique ID verification which consumers may click on to ‘verify’ it is an authentic ShopAd. The authentication message is hosted on our secure https server, which cannot be duped. To see this work, go to http://www.adgregate.com, click on “Showcase” and roll over any ShopAds icon on bottom left corner of the ShopAd to validate the ShopAd.</description>
		<content:encoded><![CDATA[<p>Thanks for your interest in ShopAds. I want to update your readers that each ShopAd now has a unique ID verification which consumers may click on to ‘verify’ it is an authentic ShopAd. The authentication message is hosted on our secure https server, which cannot be duped. To see this work, go to <a href="http://www.adgregate.com" rel="nofollow">http://www.adgregate.com</a>, click on “Showcase” and roll over any ShopAds icon on bottom left corner of the ShopAd to validate the ShopAd.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Henry, CEO of Adgregate</title>
		<link>http://blog.redfin.com/blog/2008/09/is_adgregate_insecure.html/comment-page-1#comment-3755</link>
		<dc:creator>Henry, CEO of Adgregate</dc:creator>
		<pubDate>Thu, 11 Sep 2008 14:39:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.redfin.com/blog/2008/09/is_adgregate_insecure.html#comment-3755</guid>
		<description>very good points by sasha, and all correct of course. while it is true we are securing the transamission of data, there are a number of things mr. evil can still do if they are intent on stealing info from users. our solution has been tested to be a commercially reasonable solution for our major partners who are using it today. and i think our biz model is preconditioned that there is reasonability w/the user/scenario as well.  our model is based on working with trusted advertiser brands and publishers. if a user encounters our ad on a publisher site they don&#039;t trust, or from a merchant they don&#039;t trust, then we believe consumers will not transact in those instances. thus, our ads are overwhelmingly succesfful when they are distributed in a targeted fashion and not a blind network purchase. to address the potential problem of users still mistaking a copy cat ShopAd for ours, however, we are working on a click thru on the ShopAd which leads the user to a verification on our secure site which will include a unique identifier for each ShopAd. much like the way you click thru a verisign logo today. we will launch this added security feature very soon. for the advertisers and publishers we work with today, this has been a commercially reasonable solution for their customers, and they are seeing positive results (actual product sell thru) because of it. we continue to add to our advertiser base weekly, so stay tuned for more exciting announcements on our end!</description>
		<content:encoded><![CDATA[<p>very good points by sasha, and all correct of course. while it is true we are securing the transamission of data, there are a number of things mr. evil can still do if they are intent on stealing info from users. our solution has been tested to be a commercially reasonable solution for our major partners who are using it today. and i think our biz model is preconditioned that there is reasonability w/the user/scenario as well.  our model is based on working with trusted advertiser brands and publishers. if a user encounters our ad on a publisher site they don&#8217;t trust, or from a merchant they don&#8217;t trust, then we believe consumers will not transact in those instances. thus, our ads are overwhelmingly succesfful when they are distributed in a targeted fashion and not a blind network purchase. to address the potential problem of users still mistaking a copy cat ShopAd for ours, however, we are working on a click thru on the ShopAd which leads the user to a verification on our secure site which will include a unique identifier for each ShopAd. much like the way you click thru a verisign logo today. we will launch this added security feature very soon. for the advertisers and publishers we work with today, this has been a commercially reasonable solution for their customers, and they are seeing positive results (actual product sell thru) because of it. we continue to add to our advertiser base weekly, so stay tuned for more exciting announcements on our end!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

