<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Shame</title>
	<atom:link href="http://shame.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://shame.wordpress.com</link>
	<description>Naming and shaming sites that ought to know better</description>
	<lastBuildDate>Mon, 28 Aug 2006 06:23:43 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='shame.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/ac86dd478b2834d8e5826967102f6b1e?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Shame</title>
		<link>http://shame.wordpress.com</link>
	</image>
			<item>
		<title>NRMA insures Internet Explorer users</title>
		<link>http://shame.wordpress.com/2006/08/28/nrma-insures-internet-explorer-users/</link>
		<comments>http://shame.wordpress.com/2006/08/28/nrma-insures-internet-explorer-users/#comments</comments>
		<pubDate>Mon, 28 Aug 2006 06:21:43 +0000</pubDate>
		<dc:creator>Shame</dc:creator>
				<category><![CDATA[Shamed]]></category>
		<category><![CDATA[User Unfriendly]]></category>

		<guid isPermaLink="false">https://shame.wordpress.com/2006/08/28/nrma-insures-internet-explorer-users/</guid>
		<description><![CDATA[It&#8217;s official, NRMA, an Australian insurance company, won&#8217;t give you a quote for travel insurance unless you use Internet Explorer.

Personally, I find this discriminatory. I&#8217;m not sure if there are laws to protect potential customers from discriminatory behaviour (there are if you&#8217;re a potential employee, and might be if you&#8217;re an existing customer).
I did the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=shame.wordpress.com&blog=227323&post=15&subd=shame&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>It&#8217;s official, <a href="http://nrma.com.au/" rel="nofollow">NRMA</a>, an Australian insurance company, won&#8217;t give you a quote for travel insurance unless you use Internet Explorer.</p>
<p><a href="http://shame.files.wordpress.com/2006/08/nrma_explorer.png" class="imagelink" title="NRMA insures Internet Explorer users"><img src="http://shame.files.wordpress.com/2006/08/nrma_explorer.thumbnail.png" alt="NRMA insures Internet Explorer users" /></a></p>
<p>Personally, I find this discriminatory. I&#8217;m not sure if there are laws to protect potential customers from discriminatory behaviour (there are if you&#8217;re a potential employee, and might be if you&#8217;re an existing customer).</p>
<p>I did the neighbourly thing and sent a message to them using their feedback form and will update this site if I hear back from them.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/shame.wordpress.com/15/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/shame.wordpress.com/15/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/shame.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/shame.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/shame.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/shame.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/shame.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/shame.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/shame.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/shame.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/shame.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/shame.wordpress.com/15/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=shame.wordpress.com&blog=227323&post=15&subd=shame&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://shame.wordpress.com/2006/08/28/nrma-insures-internet-explorer-users/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f6032248b9ef52f5aed96781a848f65f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">Shame</media:title>
		</media:content>

		<media:content url="http://shame.files.wordpress.com/2006/08/nrma_explorer.thumbnail.png" medium="image">
			<media:title type="html">NRMA insures Internet Explorer users</media:title>
		</media:content>
	</item>
		<item>
		<title>WebEx takes credit cards insecurely!</title>
		<link>http://shame.wordpress.com/2006/07/13/webex-takes-credit-cards-insecurely/</link>
		<comments>http://shame.wordpress.com/2006/07/13/webex-takes-credit-cards-insecurely/#comments</comments>
		<pubDate>Thu, 13 Jul 2006 04:40:43 +0000</pubDate>
		<dc:creator>Shame</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Shamed]]></category>

		<guid isPermaLink="false">https://shame.wordpress.com/2006/07/13/webex-takes-credit-cards-insecurely/</guid>
		<description><![CDATA[A colleague of mine just tried signing up for a WebEx service. When he got to the &#8220;Please enter billing and credit card information&#8221; section, he noticed a funny symbol in the bottom of FireFox: 
This symbol means &#8220;partially secure&#8221; and we got to wondering why this came up. Now I&#8217;m not sure this is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=shame.wordpress.com&blog=227323&post=12&subd=shame&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>A colleague of mine just tried signing up for a WebEx service. When he got to the &#8220;Please enter billing and credit card information&#8221; section, he noticed a funny symbol in the bottom of FireFox: <img src="http://shame.files.wordpress.com/2006/07/firefox_partially_secure.png" alt="firefox_partially_secure.png" /></p>
<p>This symbol means &#8220;partially secure&#8221; and we got to wondering why this came up. Now I&#8217;m not sure this is the reason, but here&#8217;s the worrying thing we discovered:</p>
<p><a href="http://shame.files.wordpress.com/2006/07/webex_insecure_cc.png" class="imagelink" title="webex_insecure_cc.png"><img src="http://shame.files.wordpress.com/2006/07/webex_insecure_cc.thumbnail.png" alt="webex_insecure_cc.png" /></a><br />
Click the image for the big picture. What you can see there is the form information as displayed by the Web Developer Toolbar, and if you look at the top left of the form, you&#8217;ll see it&#8217;s submitting to http, which means your credit card details are being sent without encryption!<br />
Needless to say, my colleague did not complete the process and WebEx may have lost a sale.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/shame.wordpress.com/12/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/shame.wordpress.com/12/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/shame.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/shame.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/shame.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/shame.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/shame.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/shame.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/shame.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/shame.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/shame.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/shame.wordpress.com/12/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=shame.wordpress.com&blog=227323&post=12&subd=shame&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://shame.wordpress.com/2006/07/13/webex-takes-credit-cards-insecurely/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f6032248b9ef52f5aed96781a848f65f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">Shame</media:title>
		</media:content>

		<media:content url="http://shame.files.wordpress.com/2006/07/firefox_partially_secure.png" medium="image">
			<media:title type="html">firefox_partially_secure.png</media:title>
		</media:content>

		<media:content url="http://shame.files.wordpress.com/2006/07/webex_insecure_cc.thumbnail.png" medium="image">
			<media:title type="html">webex_insecure_cc.png</media:title>
		</media:content>
	</item>
		<item>
		<title>Queensland Holidays</title>
		<link>http://shame.wordpress.com/2006/06/19/queensland-holidays/</link>
		<comments>http://shame.wordpress.com/2006/06/19/queensland-holidays/#comments</comments>
		<pubDate>Mon, 19 Jun 2006 04:44:44 +0000</pubDate>
		<dc:creator>Shame</dc:creator>
				<category><![CDATA[Shamed]]></category>
		<category><![CDATA[User Unfriendly]]></category>

		<guid isPermaLink="false">https://shame.wordpress.com/2006/06/19/queensland-holidays/</guid>
		<description><![CDATA[I entered a comp to win a holiday in Queensland a few months ago and got a promo email today. At the end of the email was a &#34;follow this link to unsubscribe&#34; link, and I did just that.
Now usually, that will take you to a page that says &#34;You&#39;re unsubscribed&#34;. At worst, it might [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=shame.wordpress.com&blog=227323&post=9&subd=shame&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I entered a comp to win a holiday in Queensland a few months ago and got a promo email today. At the end of the email was a &quot;follow this link to unsubscribe&quot; link, and I did just that.</p>
<p>Now usually, that will take you to a page that says &quot;You&#39;re unsubscribed&quot;. At worst, it might ask for my email address (although that information could have been passed to the page from the link in the email).</p>
<p>This site, however, decided that it would ask for an email address, and then send me an email with instruction on how to unsubscribe!</p>
<p>I just got this email:</p>
<blockquote><p>Hi Ben,</p>
<p>You have requested to remove your subscription from the Queensland Holidays mailing list.</p>
<p>To confirm your request, please visit <u>this link</u> within 14 days.</p>
<p>This message was automatically generated by the Queensland Holidays mailing list.</p></blockquote>
<p>I was half expecting to follow the link and be asked for my email address again, but luckily it just told me my subscription has been removed. Phew!</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/shame.wordpress.com/9/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/shame.wordpress.com/9/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/shame.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/shame.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/shame.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/shame.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/shame.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/shame.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/shame.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/shame.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/shame.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/shame.wordpress.com/9/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=shame.wordpress.com&blog=227323&post=9&subd=shame&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://shame.wordpress.com/2006/06/19/queensland-holidays/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f6032248b9ef52f5aed96781a848f65f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">Shame</media:title>
		</media:content>
	</item>
		<item>
		<title>Friends Reunited</title>
		<link>http://shame.wordpress.com/2006/05/17/friends-reunited/</link>
		<comments>http://shame.wordpress.com/2006/05/17/friends-reunited/#comments</comments>
		<pubDate>Wed, 17 May 2006 01:23:44 +0000</pubDate>
		<dc:creator>Shame</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Shamed]]></category>

		<guid isPermaLink="false">https://shame.wordpress.com/2006/05/17/friends-reunited/</guid>
		<description><![CDATA[
Friends Reunited show your password in clear text on an insecure (HTTP) page.
I emailed them to tell them I was concerned, and was reassured (unfortunately I can&#8217;t find the email any more) that the page was perfectly safe, as you&#8217;d need my password to get there in the first place.
I replied to tell them that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=shame.wordpress.com&blog=227323&post=8&subd=shame&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://shame.files.wordpress.com/2006/05/friends_reunited_clear_password.png" class="imagelink" title="Friends Reunited Password"><img src="http://shame.files.wordpress.com/2006/05/friends_reunited_clear_password.thumbnail.png" alt="Friends Reunited Password" /></a></p>
<p>Friends Reunited show your password in clear text on an insecure (HTTP) page.</p>
<p>I emailed them to tell them I was concerned, and was reassured (unfortunately I can&#8217;t find the email any more) that the page was perfectly safe, as you&#8217;d need my password to get there in the first place.</p>
<p>I replied to tell them that the password was being displayed clear text on a page that had not been secured with an SSL certificate, and hence the whole HTML page was probably cached on a number of servers in-between (such as my ISP&#8217;s). No further response was forthcoming.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/shame.wordpress.com/8/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/shame.wordpress.com/8/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/shame.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/shame.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/shame.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/shame.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/shame.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/shame.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/shame.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/shame.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/shame.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/shame.wordpress.com/8/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=shame.wordpress.com&blog=227323&post=8&subd=shame&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://shame.wordpress.com/2006/05/17/friends-reunited/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f6032248b9ef52f5aed96781a848f65f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">Shame</media:title>
		</media:content>

		<media:content url="http://shame.files.wordpress.com/2006/05/friends_reunited_clear_password.thumbnail.png" medium="image">
			<media:title type="html">Friends Reunited Password</media:title>
		</media:content>
	</item>
		<item>
		<title>A new site was born</title>
		<link>http://shame.wordpress.com/2006/05/17/a-new-site-was-born/</link>
		<comments>http://shame.wordpress.com/2006/05/17/a-new-site-was-born/#comments</comments>
		<pubDate>Wed, 17 May 2006 00:48:16 +0000</pubDate>
		<dc:creator>Shame</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">https://shame.wordpress.com/2006/05/17/a-new-site-was-born/</guid>
		<description><![CDATA[I&#8217;ve been seeing a few too many sites that annoy me recently. I&#8217;m not talking about ones that don&#8217;t render properly in my browser of choice or have awful design elements. I&#8217;m talking about those that use, or have applied for, software patents. I&#8217;m talking about sites that don&#8217;t have stong security mechanisms in place.
Software [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=shame.wordpress.com&blog=227323&post=3&subd=shame&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I&#8217;ve been seeing a few too many sites that annoy me recently. I&#8217;m not talking about ones that don&#8217;t render properly in my browser of choice or have awful design elements. I&#8217;m talking about those that use, or have applied for, software patents. I&#8217;m talking about sites that don&#8217;t have stong security mechanisms in place.</p>
<p>Software Patents</p>
<p>I&#8217;ll probably write a more detailed description of what they are, why they&#8217;re bad and just don&#8217;t work later. For now, suffice it to say that they are bad, and I won&#8217;t use anyone&#8217;s system if they entertain ideas to the contrary.</p>
<p>There is only one way I could accept software patents, and that is if they are applied for and then released to the public domainfor anyone to use. This would stop someone else from applying for a software patent and using it for evil.<br />
Security</p>
<p>This is a real pain in the neck. My first example shows <a href="/shamed/friends-reunited/" title="Friends Reunited show your password in clear text on an insecure (HTTP) page.">my password in plain text on a web page that isn&#8217;t secure</a>.</p>
<p>Other security issues are sites that send you your username and password in the same email. Or those that email you a password, and your email address is your login name. Passwords should never be sent in clear text. Ever!</p>
<p>Am I perfect?</p>
<p>Hell no &#8211; I&#8217;ve done these things, and they&#8217;ve come back to bite me. This is why I&#8217;m so aware of why they are bad things to do. Everyone makes mistakes and hopefully learns from them. I hope to pass this knowledge on to you, the reader, and hopefully also the owners of the websites concerned.</p>
<p>I&#8217;ve not stopped learning, and hope to learn more through running this site. I welcome submissions from anyone &#8211; check out the <a href="/submit/" title="Submit a Shameful Site">Submit a Shameful Site</a> page for more details.</p>
<p>That&#8217;s all for the first post&#8230;</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/shame.wordpress.com/3/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/shame.wordpress.com/3/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/shame.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/shame.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/shame.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/shame.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/shame.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/shame.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/shame.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/shame.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/shame.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/shame.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=shame.wordpress.com&blog=227323&post=3&subd=shame&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://shame.wordpress.com/2006/05/17/a-new-site-was-born/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f6032248b9ef52f5aed96781a848f65f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">Shame</media:title>
		</media:content>
	</item>
	</channel>
</rss>