<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: A month of browser bugs</title>
	<atom:link href="http://securitymusings.com/article/42/a-month-of-browser-bugs/feed" rel="self" type="application/rss+xml" />
	<link>http://securitymusings.com/article/42/a-month-of-browser-bugs</link>
	<description>Rants and raves from information security professionals</description>
	<lastBuildDate>Sat, 19 May 2012 23:32:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Anil</title>
		<link>http://securitymusings.com/article/42/a-month-of-browser-bugs/comment-page-1#comment-13</link>
		<dc:creator>Anil</dc:creator>
		<pubDate>Fri, 07 Jul 2006 20:12:39 +0000</pubDate>
		<guid isPermaLink="false">http://securitymusings.com/article/42/a-month-of-browser-bugs#comment-13</guid>
		<description>&lt;p&gt;I don&#8217;t think that this is responsible disclosure.&lt;/p&gt;

	&lt;p&gt;It is like saying,&lt;/p&gt;

	&lt;p&gt;&#8220;I&#8217;m fed up with so many cars being stolen ever year (unhappy with poor browser security).&lt;/p&gt;

	&lt;p&gt;So, I&#8217;m just going to announce how to break in to cars. Honda &#8211; well, they have a latch mechanism so&#8230;(making people &#8220;aware.&#8221;)&lt;/p&gt;

	&lt;p&gt;Oh yea, and I&#8217;m going to hand out crow bars, lock picks, and whatever else you need to break in (exploit code).&#8221;&lt;/p&gt;

	&lt;p&gt;All in the hopes that car manufacturers start making cars harder to break into. Hmmm&#8230;doubt that will happen as a result of creating more criminals. People will still buy cars, just as people will still use browsers with swiss cheese security. The only people who care about vulnerability disclosures and exploit code are security &#8220;people&#8221; and hackers both good and bad.&lt;/p&gt;

	&lt;p&gt;Eventually security will get better, but I bet more cars will be stolen in the mean time.&lt;/p&gt;

	&lt;p&gt;So, does giving Lex Luthor kryptonite make Superman stronger? I don&#8217;t know either, but it sure makes for a better movie&#8230;&lt;/p&gt;</description>
		<content:encoded><![CDATA[<p>I don&#8217;t think that this is responsible disclosure.</p>
<p>It is like saying,</p>
<p>&#8220;I&#8217;m fed up with so many cars being stolen ever year (unhappy with poor browser security).</p>
<p>So, I&#8217;m just going to announce how to break in to cars. Honda &#8211; well, they have a latch mechanism so&#8230;(making people &#8220;aware.&#8221;)</p>
<p>Oh yea, and I&#8217;m going to hand out crow bars, lock picks, and whatever else you need to break in (exploit code).&#8221;</p>
<p>All in the hopes that car manufacturers start making cars harder to break into. Hmmm&#8230;doubt that will happen as a result of creating more criminals. People will still buy cars, just as people will still use browsers with swiss cheese security. The only people who care about vulnerability disclosures and exploit code are security &#8220;people&#8221; and hackers both good and bad.</p>
<p>Eventually security will get better, but I bet more cars will be stolen in the mean time.</p>
<p>So, does giving Lex Luthor kryptonite make Superman stronger? I don&#8217;t know either, but it sure makes for a better movie&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

