<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Analytical Engine</title>
	<atom:link href="http://www.analyticalengine.net/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.analyticalengine.net</link>
	<description>Application Security, General Technology, and Geek Ramblings</description>
	<lastBuildDate>Wed, 09 Dec 2009 17:47:13 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on Do as I Say&#8230; by Joshbw</title>
		<link>http://www.analyticalengine.net/2009/12/do-as-i-say/comment-page-1/#comment-1317</link>
		<dc:creator>Joshbw</dc:creator>
		<pubDate>Wed, 09 Dec 2009 17:47:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.analyticalengine.net/?p=205#comment-1317</guid>
		<description>Incidentally, to further blemish myself, one thing correctly pointed out in the mediawiki bugzilla discussion that I *should* have thought about myself was that in terms of the verbose login messages, a change is pointless.  There are numerous ways to discover valid user accounts, intentionally in the design of the application, so when it comes down to it it matters little that you can do so on the login page.  

Thus my complaints in that regard appear quite silly.</description>
		<content:encoded><![CDATA[<p>Incidentally, to further blemish myself, one thing correctly pointed out in the mediawiki bugzilla discussion that I *should* have thought about myself was that in terms of the verbose login messages, a change is pointless.  There are numerous ways to discover valid user accounts, intentionally in the design of the application, so when it comes down to it it matters little that you can do so on the login page.  </p>
<p>Thus my complaints in that regard appear quite silly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Do as I Say&#8230; by Joshbw</title>
		<link>http://www.analyticalengine.net/2009/12/do-as-i-say/comment-page-1/#comment-1316</link>
		<dc:creator>Joshbw</dc:creator>
		<pubDate>Wed, 09 Dec 2009 17:38:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.analyticalengine.net/?p=205#comment-1316</guid>
		<description>Hey guys, do as I say, not as I do... and indeed, casual hypocracy is hard to combat.  As I was writing this I certainly realized I was passing the buck.  The security edge open source has over proprietary is that anyone who notices a problem can fix it (I think that is balanced by the fact that blackhats who have no intention of fixing a problem have a bit easier time finding them with access to the source), and indeed since I notice the problem I could certainly fix it myself.  I plead hardware failure as an excuse, as my personal dev box is toast at the moment (come on generous tax return, Daddy needs a new computer) but I have gone and open bugs with the MediaWiki Project.  In general though, as a consumer of multiple OSS projects myself I should do a better job giving back - they may be free of cost, but I really should recognize a level of obligation as a result of my use regardless.  

In terms of OWASP, the resources the organization provides are ones I have refered a multitude of developers to, and have in turn contributed to several pages, but certainly considering the utility it has provided me I owe some more back its way. 

&lt;blockquote&gt;In the early years of OWASP, we spent almost all of our time working on building an uber-secure CMS, at a *serious* cost to actually achieving our mission. So I think there’s an important lesson for developers here that security is not black-and-white. You always have to balance the cost to the business against the investment in security…and if that’s what developers take away from the OWASP site then I think we’ve done something good. &lt;/blockquote&gt;

Indeed that is something I fully understand.  Security is just one business need among many, and the business needs to balance competing needs.  I think an underlying message to my post is that security teams need to be reasonable in their security pronouncements - all to often security professionals like to speak in absolutes as if security considerations are on a higher pedistol when at the same time they implicitely understand that they themselves are weighing the security of their own properties relative to the other business considerations of their proprerties.  In general I think those of us in the enterprise are obligated to live our examples - in our own projects find the right balance of security versus other considerations (or even security versus security.  Often confidentiality, integrity, and availability are competing rather than complimentary concepts) and use that to inform our educations of the rest of the enterprise.</description>
		<content:encoded><![CDATA[<p>Hey guys, do as I say, not as I do&#8230; and indeed, casual hypocracy is hard to combat.  As I was writing this I certainly realized I was passing the buck.  The security edge open source has over proprietary is that anyone who notices a problem can fix it (I think that is balanced by the fact that blackhats who have no intention of fixing a problem have a bit easier time finding them with access to the source), and indeed since I notice the problem I could certainly fix it myself.  I plead hardware failure as an excuse, as my personal dev box is toast at the moment (come on generous tax return, Daddy needs a new computer) but I have gone and open bugs with the MediaWiki Project.  In general though, as a consumer of multiple OSS projects myself I should do a better job giving back &#8211; they may be free of cost, but I really should recognize a level of obligation as a result of my use regardless.  </p>
<p>In terms of OWASP, the resources the organization provides are ones I have refered a multitude of developers to, and have in turn contributed to several pages, but certainly considering the utility it has provided me I owe some more back its way. </p>
<blockquote><p>In the early years of OWASP, we spent almost all of our time working on building an uber-secure CMS, at a *serious* cost to actually achieving our mission. So I think there’s an important lesson for developers here that security is not black-and-white. You always have to balance the cost to the business against the investment in security…and if that’s what developers take away from the OWASP site then I think we’ve done something good. </p></blockquote>
<p>Indeed that is something I fully understand.  Security is just one business need among many, and the business needs to balance competing needs.  I think an underlying message to my post is that security teams need to be reasonable in their security pronouncements &#8211; all to often security professionals like to speak in absolutes as if security considerations are on a higher pedistol when at the same time they implicitely understand that they themselves are weighing the security of their own properties relative to the other business considerations of their proprerties.  In general I think those of us in the enterprise are obligated to live our examples &#8211; in our own projects find the right balance of security versus other considerations (or even security versus security.  Often confidentiality, integrity, and availability are competing rather than complimentary concepts) and use that to inform our educations of the rest of the enterprise.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Do as I Say&#8230; by Jeff Williams</title>
		<link>http://www.analyticalengine.net/2009/12/do-as-i-say/comment-page-1/#comment-1315</link>
		<dc:creator>Jeff Williams</dc:creator>
		<pubDate>Wed, 09 Dec 2009 15:55:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.analyticalengine.net/?p=205#comment-1315</guid>
		<description>Thanks Josh!  I think your basic point is right, and we should eat our own dogfood.

Please remember that OWASP is an an all volunteer organization operating on a shoestring budget. We *have* given considerable support to a huge range of open source projects, including MediaWiki, Spring, Hudson, and many others. You should know that we have invested pretty heavily in the security of the OWASP site, with hardening, patching, configuration, custom plugins, etc... but there&#039;s obviously more we can do.

In the early years of OWASP, we spent almost all of our time working on building an uber-secure CMS, at a *serious* cost to actually achieving our mission. So I think there&#039;s an important lesson for developers here that security is not black-and-white.  You always have to balance the cost to the business against the investment in security...and if that&#039;s what developers take away from the OWASP site then I think we&#039;ve done something good. Nevertheless, your point about the risk to the integrity of our message is a good one.

So I have to ask - how about working with OWASP and MediaWiki to get the changes you want implemented?

Thanks!</description>
		<content:encoded><![CDATA[<p>Thanks Josh!  I think your basic point is right, and we should eat our own dogfood.</p>
<p>Please remember that OWASP is an an all volunteer organization operating on a shoestring budget. We *have* given considerable support to a huge range of open source projects, including MediaWiki, Spring, Hudson, and many others. You should know that we have invested pretty heavily in the security of the OWASP site, with hardening, patching, configuration, custom plugins, etc&#8230; but there&#8217;s obviously more we can do.</p>
<p>In the early years of OWASP, we spent almost all of our time working on building an uber-secure CMS, at a *serious* cost to actually achieving our mission. So I think there&#8217;s an important lesson for developers here that security is not black-and-white.  You always have to balance the cost to the business against the investment in security&#8230;and if that&#8217;s what developers take away from the OWASP site then I think we&#8217;ve done something good. Nevertheless, your point about the risk to the integrity of our message is a good one.</p>
<p>So I have to ask &#8211; how about working with OWASP and MediaWiki to get the changes you want implemented?</p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Do as I Say&#8230; by Michael Coates</title>
		<link>http://www.analyticalengine.net/2009/12/do-as-i-say/comment-page-1/#comment-1314</link>
		<dc:creator>Michael Coates</dc:creator>
		<pubDate>Tue, 08 Dec 2009 19:44:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.analyticalengine.net/?p=205#comment-1314</guid>
		<description>Joshbw,
OWASP is a non-profit organization completely run by volunteers who have the passion, skill and interest to pursue a particular area of application security for the betterment of everyone. As such, particular areas of OWASP have prospered due to a collaborative effort of generous volunteers.

It sounds like you definitely have the passion and skill in this area and have highlighted an area which could be enhanced. Would you like to take the lead here and help the OWASP mission?  

-Michael</description>
		<content:encoded><![CDATA[<p>Joshbw,<br />
OWASP is a non-profit organization completely run by volunteers who have the passion, skill and interest to pursue a particular area of application security for the betterment of everyone. As such, particular areas of OWASP have prospered due to a collaborative effort of generous volunteers.</p>
<p>It sounds like you definitely have the passion and skill in this area and have highlighted an area which could be enhanced. Would you like to take the lead here and help the OWASP mission?  </p>
<p>-Michael</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Forget Virus Scanners by Anonymous</title>
		<link>http://www.analyticalengine.net/2009/06/forget-virus-scanners/comment-page-1/#comment-1200</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sat, 22 Aug 2009 08:52:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.analyticalengine.net/?p=196#comment-1200</guid>
		<description>Marcus Ranum comes to the same conclusion and plays with some various software here that does just that.

http://www.ranum.com/security/computer_security/editorials/antivirus/index.html</description>
		<content:encoded><![CDATA[<p>Marcus Ranum comes to the same conclusion and plays with some various software here that does just that.</p>
<p><a href="http://www.ranum.com/security/computer_security/editorials/antivirus/index.html" rel="nofollow">http://www.ranum.com/security/computer_security/editorials/antivirus/index.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on I really hope this is a joke by fuzion</title>
		<link>http://www.analyticalengine.net/2009/05/i-really-hope-this-is-a-joke/comment-page-1/#comment-1040</link>
		<dc:creator>fuzion</dc:creator>
		<pubDate>Sat, 23 May 2009 03:07:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.analyticalengine.net/?p=184#comment-1040</guid>
		<description>Of course its a joke... they&#039;re making fun of Netragard. Here&#039;s the template they used:
http://www.netragard.com/pdfs/research/NETRAGARD-20090506-AIRCELL.txt</description>
		<content:encoded><![CDATA[<p>Of course its a joke&#8230; they&#8217;re making fun of Netragard. Here&#8217;s the template they used:<br />
<a href="http://www.netragard.com/pdfs/research/NETRAGARD-20090506-AIRCELL.txt" rel="nofollow">http://www.netragard.com/pdfs/research/NETRAGARD-20090506-AIRCELL.txt</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on I really hope this is a joke by Jim Manico</title>
		<link>http://www.analyticalengine.net/2009/05/i-really-hope-this-is-a-joke/comment-page-1/#comment-1039</link>
		<dc:creator>Jim Manico</dc:creator>
		<pubDate>Sat, 23 May 2009 00:46:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.analyticalengine.net/?p=184#comment-1039</guid>
		<description>You got to read it, it really IS a joke:

- Cookie stealing
- Cookie harassing
- Cookie tampering
- Tampering of harassed cookie
- Harassing the thief tampering with cookies</description>
		<content:encoded><![CDATA[<p>You got to read it, it really IS a joke:</p>
<p>- Cookie stealing<br />
- Cookie harassing<br />
- Cookie tampering<br />
- Tampering of harassed cookie<br />
- Harassing the thief tampering with cookies</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on I really hope this is a joke by Jim Manico</title>
		<link>http://www.analyticalengine.net/2009/05/i-really-hope-this-is-a-joke/comment-page-1/#comment-1038</link>
		<dc:creator>Jim Manico</dc:creator>
		<pubDate>Sat, 23 May 2009 00:43:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.analyticalengine.net/?p=184#comment-1038</guid>
		<description>Comon man, just slap a little VA+WAF on top of that Webgoat mess and you will be 100% secure.</description>
		<content:encoded><![CDATA[<p>Comon man, just slap a little VA+WAF on top of that Webgoat mess and you will be 100% secure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Bad Practices #412 by Pat Cahalan</title>
		<link>http://www.analyticalengine.net/2009/04/bad-practices-412/comment-page-1/#comment-1035</link>
		<dc:creator>Pat Cahalan</dc:creator>
		<pubDate>Wed, 06 May 2009 17:56:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.analyticalengine.net/?p=119#comment-1035</guid>
		<description>&gt; So Please, quit asking for credentials to other sites- 
&gt; don’t do what attackers do, otherwise you don’t give
&gt; people an easy way to distinguish between the two.

... amen, Brother Josh.  Amen.</description>
		<content:encoded><![CDATA[<p>&gt; So Please, quit asking for credentials to other sites-<br />
&gt; don’t do what attackers do, otherwise you don’t give<br />
&gt; people an easy way to distinguish between the two.</p>
<p>&#8230; amen, Brother Josh.  Amen.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Quest for the perfect Geek Bag Part 1: Criteria by Analytical Engine » Blog Archive &#187; Quest for the Perfect Geek Bag Part 5: Ogio Metro</title>
		<link>http://www.analyticalengine.net/2009/04/quest-for-the-perfect-geek-bag-part-1-criteria/comment-page-1/#comment-1033</link>
		<dc:creator>Analytical Engine » Blog Archive &#187; Quest for the Perfect Geek Bag Part 5: Ogio Metro</dc:creator>
		<pubDate>Thu, 23 Apr 2009 21:10:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.analyticalengine.net/?p=128#comment-1033</guid>
		<description>[...] and all I can find very little to complain about. Almost all of my criteria are met by this beast, however I did stop using it. It is a heck of a thing to complain about, but [...]</description>
		<content:encoded><![CDATA[<p>[...] and all I can find very little to complain about. Almost all of my criteria are met by this beast, however I did stop using it. It is a heck of a thing to complain about, but [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

