<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Secure is, as Secure does.</title>
	<atom:link href="http://thirdpartycode.com/2007/05/secure-is-as-secure-does/feed/" rel="self" type="application/rss+xml" />
	<link>http://thirdpartycode.com/2007/05/secure-is-as-secure-does/</link>
	<description>Linux, PHP 5, Apache Consulting in San Antonio, TX</description>
	<lastBuildDate>Thu, 05 Aug 2010 12:40:23 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Torrential Web Dev</title>
		<link>http://thirdpartycode.com/2007/05/secure-is-as-secure-does/comment-page-1/#comment-78</link>
		<dc:creator>Torrential Web Dev</dc:creator>
		<pubDate>Fri, 25 May 2007 20:37:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.phpcult.com/blog/24/secure-is-as-secure-does/#comment-78</guid>
		<description>&lt;strong&gt;The &quot;I&#039;m Alive&quot; Entry&lt;/strong&gt;

Things have been quiet around here in terms of entries so to keep things rolling here are a few interesting links I&#039;ve discovered over the past few days . . .

Florian posted a comment over on the msn contact grab entry highlighting a warning error...</description>
		<content:encoded><![CDATA[<p><strong>The &#8220;I&#8217;m Alive&#8221; Entry</strong></p>
<p>Things have been quiet around here in terms of entries so to keep things rolling here are a few interesting links I&#8217;ve discovered over the past few days . . .</p>
<p>Florian posted a comment over on the msn contact grab entry highlighting a warning error&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff Dickey</title>
		<link>http://thirdpartycode.com/2007/05/secure-is-as-secure-does/comment-page-1/#comment-79</link>
		<dc:creator>Jeff Dickey</dc:creator>
		<pubDate>Fri, 25 May 2007 15:46:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.phpcult.com/blog/24/secure-is-as-secure-does/#comment-79</guid>
		<description>I think you&#039;re right, both about this being a good-sense way to handle things and about the futility of automagically patching existing installs.

I&#039;m sure, however, that the companies or communities around existing packages with histories of problems in the past (*cough* WordPress *cough*) could throw together a Google mashup to (hypothetically) go find all Google-visible instances of FubarBlog before version X.Y, grab the blogger&#039;s email address (either through metainfo or screen-scrape, since they know what they&#039;re looking at), and slap him upside the electronic head. Of course, that has two problems:
1) it annoys the guy who is just using his host provider&#039;s installed service, over which he has no control;
2) if the Good Guys can do it, the Bad Guys can too - and fully automate defacement of vulnerable blogs. *shudder*

Sticking our heads under the collective sand will NOT do anything for Problem 2. Problem 1 may be beneficial; if Loser-ISP.biz won&#039;t fix their systems after customers complain, then there are always other hosting providers out there, and people will (eventually) vote with their feet and their kopecks.

Wasn&#039;t this sort of how the Morris Worm got started?</description>
		<content:encoded><![CDATA[<p>I think you&#8217;re right, both about this being a good-sense way to handle things and about the futility of automagically patching existing installs.</p>
<p>I&#8217;m sure, however, that the companies or communities around existing packages with histories of problems in the past (*cough* WordPress *cough*) could throw together a Google mashup to (hypothetically) go find all Google-visible instances of FubarBlog before version X.Y, grab the blogger&#8217;s email address (either through metainfo or screen-scrape, since they know what they&#8217;re looking at), and slap him upside the electronic head. Of course, that has two problems:<br />
1) it annoys the guy who is just using his host provider&#8217;s installed service, over which he has no control;<br />
2) if the Good Guys can do it, the Bad Guys can too &#8211; and fully automate defacement of vulnerable blogs. *shudder*</p>
<p>Sticking our heads under the collective sand will NOT do anything for Problem 2. Problem 1 may be beneficial; if Loser-ISP.biz won&#8217;t fix their systems after customers complain, then there are always other hosting providers out there, and people will (eventually) vote with their feet and their kopecks.</p>
<p>Wasn&#8217;t this sort of how the Morris Worm got started?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced)

Served from: thirdpartycode.com @ 2010-09-10 17:43:44 -->