<?xml version="1.0" encoding="utf-8"?>
<feed xml:lang="en-us" xmlns="http://www.w3.org/2005/Atom"><title>Simon Willison's Weblog: tunisia</title><link href="http://simonwillison.net/" rel="alternate"/><link href="http://simonwillison.net/tags/tunisia.atom" rel="self"/><id>http://simonwillison.net/</id><updated>2011-01-24T18:45:00+00:00</updated><author><name>Simon Willison</name></author><entry><title>The code injected to steal passwords in Tunisia</title><link href="https://simonwillison.net/2011/Jan/24/code/#atom-tag" rel="alternate"/><published>2011-01-24T18:45:00+00:00</published><updated>2011-01-24T18:45:00+00:00</updated><id>https://simonwillison.net/2011/Jan/24/code/#atom-tag</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="http://blog.jgc.org/2011/01/code-injected-to-steal-passwords-in.html"&gt;The code injected to steal passwords in Tunisia&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
Here’s the JavaScript that (presumably) the Tunisian government were injecting in to login pages that were served over HTTP.


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/javascript"&gt;javascript&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/security"&gt;security&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/recovered"&gt;recovered&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/tunisia"&gt;tunisia&lt;/a&gt;&lt;/p&gt;



</summary><category term="javascript"/><category term="security"/><category term="recovered"/><category term="tunisia"/></entry><entry><title>Quoting Nat Torkington</title><link href="https://simonwillison.net/2011/Jan/24/torkington/#atom-tag" rel="alternate"/><published>2011-01-24T18:11:00+00:00</published><updated>2011-01-24T18:11:00+00:00</updated><id>https://simonwillison.net/2011/Jan/24/torkington/#atom-tag</id><summary type="html">
    &lt;blockquote cite="http://radar.oreilly.com/2011/01/four-short-links-24-january-20.html"&gt;&lt;p&gt;National politics of snoopiness vs corporate ethic of not being evil aren’t directly compatible, and the solution here only works because (let’s face it) Tunisia is not a rising economic force. If you’re selling ads in China, you don’t get to pretend that the Great Firewall of China is a security issue.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p class="cite"&gt;&amp;mdash; &lt;a href="http://radar.oreilly.com/2011/01/four-short-links-24-january-20.html"&gt;Nat Torkington&lt;/a&gt;&lt;/p&gt;

    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/china"&gt;china&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/nat-torkington"&gt;nat-torkington&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/security"&gt;security&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/recovered"&gt;recovered&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/tunisia"&gt;tunisia&lt;/a&gt;&lt;/p&gt;



</summary><category term="china"/><category term="nat-torkington"/><category term="security"/><category term="recovered"/><category term="tunisia"/></entry><entry><title>The Inside Story of How Facebook Responded to Tunisian Hacks</title><link href="https://simonwillison.net/2011/Jan/24/tunisia/#atom-tag" rel="alternate"/><published>2011-01-24T18:06:00+00:00</published><updated>2011-01-24T18:06:00+00:00</updated><id>https://simonwillison.net/2011/Jan/24/tunisia/#atom-tag</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="http://www.theatlantic.com/technology/archive/2011/01/the-inside-story-of-how-facebook-responded-to-tunisian-hacks/70044/"&gt;The Inside Story of How Facebook Responded to Tunisian Hacks&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
“By January 5, it was clear that an entire country’s worth of passwords were in the process of being stolen right in the midst of the greatest political upheaval in two decades.”—which is why you shouldn’t serve your login form over HTTP even though it POSTs over HTTPS.

    &lt;p&gt;&lt;small&gt;&lt;/small&gt;Via &lt;a href="http://radar.oreilly.com/2011/01/four-short-links-24-january-20.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A oreilly%2Fradar%2Fatom %28O%27Reilly Radar%29"&gt;O&amp;#x27;Reilly Radar&lt;/a&gt;&lt;/small&gt;&lt;/p&gt;


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/facebook"&gt;facebook&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/http"&gt;http&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/https"&gt;https&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/security"&gt;security&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/recovered"&gt;recovered&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/tunisia"&gt;tunisia&lt;/a&gt;&lt;/p&gt;



</summary><category term="facebook"/><category term="http"/><category term="https"/><category term="security"/><category term="recovered"/><category term="tunisia"/></entry></feed>