<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: HeyCraig Goes International!</title>
	<atom:link href="http://www.pointlesscorp.com/heycraig-goes-international/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pointlesscorp.com/heycraig-goes-international/</link>
	<description>Neither pointless nor a corporation.</description>
	<lastBuildDate>Mon, 23 Jan 2012 08:53:42 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Kevin VandeKrol</title>
		<link>http://www.pointlesscorp.com/heycraig-goes-international/comment-page-1/#comment-82</link>
		<dc:creator>Kevin VandeKrol</dc:creator>
		<pubDate>Tue, 11 Aug 2009 14:59:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.pointlesscorp.com/?p=105#comment-82</guid>
		<description>I spent a few minutes this morning transferring all of my Craigslist RSS feeds to your site (16 of them). Over the course of entering them, I found a lot of rather serious bugs:

1. Five different times, I entered a search and clicked &quot;yoink!&quot; only to be taken to the search results for someone else&#039;s search. By clicking &quot;your searches&quot; at the top, I was &quot;returned&quot; to the searches for the account of the person whose search I just intercepted.

2. When I was returned someone else&#039;s search, it would appear in my account&#039;s searches under the name I gave it, but when I clicked on it, it&#039;d be the other person&#039;s search. The only way to get it out of my list was to delete the search from their account... which it let me do.

3. Because of these two issues, my guess is that there are conflicts with the IDs you assign... these users were entering searches at the same time I was, and in many cases it&#039;s possible for the IDs to get mixed up, and the wrong ID can be assigned to the wrong account (or multiple accounts). 

4. Since the user IDs default to sequential numbers, it was easy to just type in other numbers and access the accounts of other users. From here I could see all their searches, add new searches, and delete existing searches.

5. Similar to the previous one: Since the search IDs are sequential as well, just hex instead of decimal, it was easy to type a previous ID and access someone else&#039;s search.</description>
		<content:encoded><![CDATA[<p>I spent a few minutes this morning transferring all of my Craigslist RSS feeds to your site (16 of them). Over the course of entering them, I found a lot of rather serious bugs:</p>
<p>1. Five different times, I entered a search and clicked &#8220;yoink!&#8221; only to be taken to the search results for someone else&#8217;s search. By clicking &#8220;your searches&#8221; at the top, I was &#8220;returned&#8221; to the searches for the account of the person whose search I just intercepted.</p>
<p>2. When I was returned someone else&#8217;s search, it would appear in my account&#8217;s searches under the name I gave it, but when I clicked on it, it&#8217;d be the other person&#8217;s search. The only way to get it out of my list was to delete the search from their account&#8230; which it let me do.</p>
<p>3. Because of these two issues, my guess is that there are conflicts with the IDs you assign&#8230; these users were entering searches at the same time I was, and in many cases it&#8217;s possible for the IDs to get mixed up, and the wrong ID can be assigned to the wrong account (or multiple accounts). </p>
<p>4. Since the user IDs default to sequential numbers, it was easy to just type in other numbers and access the accounts of other users. From here I could see all their searches, add new searches, and delete existing searches.</p>
<p>5. Similar to the previous one: Since the search IDs are sequential as well, just hex instead of decimal, it was easy to type a previous ID and access someone else&#8217;s search.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Pearson</title>
		<link>http://www.pointlesscorp.com/heycraig-goes-international/comment-page-1/#comment-81</link>
		<dc:creator>Michael Pearson</dc:creator>
		<pubDate>Tue, 11 Aug 2009 14:37:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.pointlesscorp.com/?p=105#comment-81</guid>
		<description>Never heard of the UK? I can get London, Canada, but not London, England.</description>
		<content:encoded><![CDATA[<p>Never heard of the UK? I can get London, Canada, but not London, England.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Abhimanyu Ghoshal</title>
		<link>http://www.pointlesscorp.com/heycraig-goes-international/comment-page-1/#comment-67</link>
		<dc:creator>Abhimanyu Ghoshal</dc:creator>
		<pubDate>Fri, 10 Jul 2009 10:24:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.pointlesscorp.com/?p=105#comment-67</guid>
		<description>Awesome way to search on craigslist! However, I&#039;m in Bangalore, India, and my city&#039;s not listed... anything you can do about it?

Keep up the great work, guys!</description>
		<content:encoded><![CDATA[<p>Awesome way to search on craigslist! However, I&#8217;m in Bangalore, India, and my city&#8217;s not listed&#8230; anything you can do about it?</p>
<p>Keep up the great work, guys!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

