<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Bursting security bubble</title>
	<atom:link href="http://www.rarst.net/web/bursting-security-bubble/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rarst.net/web/bursting-security-bubble/</link>
	<description>cynical thoughts on software and web</description>
	<lastBuildDate>Wed, 08 Feb 2012 23:03:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Rarst</title>
		<link>http://www.rarst.net/web/bursting-security-bubble/#comment-7524</link>
		<dc:creator>Rarst</dc:creator>
		<pubDate>Wed, 01 Apr 2009 20:20:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.rarst.net/?p=339#comment-7524</guid>
		<description>@Nick

Yeah, it really shakes brain and suddenly &quot;install antivirus, install firewall, feel safe&quot; doesn&#039;t feel so smart and smug anymore. :)</description>
		<content:encoded><![CDATA[<p>@Nick</p>
<p>Yeah, it really shakes brain and suddenly &#8220;install antivirus, install firewall, feel safe&#8221; doesn&#8217;t feel so smart and smug anymore. :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick Staroba</title>
		<link>http://www.rarst.net/web/bursting-security-bubble/#comment-7523</link>
		<dc:creator>Nick Staroba</dc:creator>
		<pubDate>Wed, 01 Apr 2009 20:17:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.rarst.net/?p=339#comment-7523</guid>
		<description>Wow it&#039;s been a long time since I&#039;ve read an article all the way through down to the very last word AND the fine print at the bottom.

Thanks for pointing this article out. I&#039;ve got a whole different perspective on computer security now. Makes me want to learn more actually...</description>
		<content:encoded><![CDATA[<p>Wow it&#8217;s been a long time since I&#8217;ve read an article all the way through down to the very last word AND the fine print at the bottom.</p>
<p>Thanks for pointing this article out. I&#8217;ve got a whole different perspective on computer security now. Makes me want to learn more actually&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rarst</title>
		<link>http://www.rarst.net/web/bursting-security-bubble/#comment-7512</link>
		<dc:creator>Rarst</dc:creator>
		<pubDate>Tue, 31 Mar 2009 21:18:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.rarst.net/?p=339#comment-7512</guid>
		<description>@Paul

Yeah, article is timeless and priceless. Years since it was written and not much changed - bit sad.

And there is nothing wrong with solutions that are &quot;good enough&quot;. As long as we are aware about flaws and can balance them out.</description>
		<content:encoded><![CDATA[<p>@Paul</p>
<p>Yeah, article is timeless and priceless. Years since it was written and not much changed &#8211; bit sad.</p>
<p>And there is nothing wrong with solutions that are &#8220;good enough&#8221;. As long as we are aware about flaws and can balance them out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: techpaul</title>
		<link>http://www.rarst.net/web/bursting-security-bubble/#comment-7510</link>
		<dc:creator>techpaul</dc:creator>
		<pubDate>Tue, 31 Mar 2009 21:10:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.rarst.net/?p=339#comment-7510</guid>
		<description>Rarst--
Thank you for posting a link to this article. I had not found it before in the course of my studies.
The author does an excellent job.

BTW.. I too have advocated the WOT toolbar/plug-in to my readers, yet I have always had the same belief that you do -- the model has quite serious flaws. 
Yes.. that&#039;s contradictory.. I know. But I believe that its &quot;good&quot; outweighs its &quot;bad&quot; and I don&#039;t advise relying on it either. Personally, I combine it with SiteAdvisor or LinkScanner..</description>
		<content:encoded><![CDATA[<p>Rarst&#8211;<br />
Thank you for posting a link to this article. I had not found it before in the course of my studies.<br />
The author does an excellent job.</p>
<p>BTW.. I too have advocated the WOT toolbar/plug-in to my readers, yet I have always had the same belief that you do &#8212; the model has quite serious flaws.<br />
Yes.. that&#8217;s contradictory.. I know. But I believe that its &#8220;good&#8221; outweighs its &#8220;bad&#8221; and I don&#8217;t advise relying on it either. Personally, I combine it with SiteAdvisor or LinkScanner..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rarst</title>
		<link>http://www.rarst.net/web/bursting-security-bubble/#comment-7508</link>
		<dc:creator>Rarst</dc:creator>
		<pubDate>Tue, 31 Mar 2009 17:25:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.rarst.net/?p=339#comment-7508</guid>
		<description>@Rick

Isn&#039;t WOT exactly one of those dumb security ideas? Enumerating badness? :) And resorting to crowd wisdom - which ranks high on my personal list of dumb ideas.

I am not saying it is bad, quite opposite. But it is definitely not approach I am willing to rely on.</description>
		<content:encoded><![CDATA[<p>@Rick</p>
<p>Isn&#8217;t WOT exactly one of those dumb security ideas? Enumerating badness? :) And resorting to crowd wisdom &#8211; which ranks high on my personal list of dumb ideas.</p>
<p>I am not saying it is bad, quite opposite. But it is definitely not approach I am willing to rely on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rick</title>
		<link>http://www.rarst.net/web/bursting-security-bubble/#comment-7507</link>
		<dc:creator>Rick</dc:creator>
		<pubDate>Tue, 31 Mar 2009 17:15:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.rarst.net/?p=339#comment-7507</guid>
		<description>Great article...  Best tool out there is &quot;common sense&quot;!  

One product I endorse to greet the bad guy at the front door is Web of Trust (WOT) - browser add on.</description>
		<content:encoded><![CDATA[<p>Great article&#8230;  Best tool out there is &#8220;common sense&#8221;!  </p>
<p>One product I endorse to greet the bad guy at the front door is Web of Trust (WOT) &#8211; browser add on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rarst</title>
		<link>http://www.rarst.net/web/bursting-security-bubble/#comment-7505</link>
		<dc:creator>Rarst</dc:creator>
		<pubDate>Mon, 30 Mar 2009 19:52:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.rarst.net/?p=339#comment-7505</guid>
		<description>@Jonny

Comodo can be educated and is pretty flexible at that. :) But in paranoid mode it can drive users nuts even faster than UAC.</description>
		<content:encoded><![CDATA[<p>@Jonny</p>
<p>Comodo can be educated and is pretty flexible at that. :) But in paranoid mode it can drive users nuts even faster than UAC.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonny</title>
		<link>http://www.rarst.net/web/bursting-security-bubble/#comment-7504</link>
		<dc:creator>Jonny</dc:creator>
		<pubDate>Mon, 30 Mar 2009 19:47:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.rarst.net/?p=339#comment-7504</guid>
		<description>Ha Ha yeah, I disabled mine ages ago and rely on comodo defence + which is just as annoying but picks up more.</description>
		<content:encoded><![CDATA[<p>Ha Ha yeah, I disabled mine ages ago and rely on comodo defence + which is just as annoying but picks up more.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rarst</title>
		<link>http://www.rarst.net/web/bursting-security-bubble/#comment-7503</link>
		<dc:creator>Rarst</dc:creator>
		<pubDate>Mon, 30 Mar 2009 19:34:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.rarst.net/?p=339#comment-7503</guid>
		<description>@Jonny

Yeah, Vista got UAC terribly wrong. It&#039;s actually standard Linux approach - want to do something advanced, get asked about admin credentials. How complex was to copy that?..

Vista managed to educate users that first thing they must do is to go and disable part of security so it stops interfering every minute.</description>
		<content:encoded><![CDATA[<p>@Jonny</p>
<p>Yeah, Vista got UAC terribly wrong. It&#8217;s actually standard Linux approach &#8211; want to do something advanced, get asked about admin credentials. How complex was to copy that?..</p>
<p>Vista managed to educate users that first thing they must do is to go and disable part of security so it stops interfering every minute.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonny</title>
		<link>http://www.rarst.net/web/bursting-security-bubble/#comment-7502</link>
		<dc:creator>Jonny</dc:creator>
		<pubDate>Mon, 30 Mar 2009 19:28:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.rarst.net/?p=339#comment-7502</guid>
		<description>&quot;Six Dumbest ideas&quot; was a great read and I have to agree with a lot that was said. This &quot;allow all&quot; and blacklist  approach to security hasn&#039;t been working which is why we now have the different approaches of white listing and behaviour blocking. 

Vista UAC is a great idea - don&#039;t allow things to run without explicit consent - but ends up being really annoying. UAC is more turd polishing though. Hopefully windows 7 may have some better answers.</description>
		<content:encoded><![CDATA[<p>&#8220;Six Dumbest ideas&#8221; was a great read and I have to agree with a lot that was said. This &#8220;allow all&#8221; and blacklist  approach to security hasn&#8217;t been working which is why we now have the different approaches of white listing and behaviour blocking. </p>
<p>Vista UAC is a great idea &#8211; don&#8217;t allow things to run without explicit consent &#8211; but ends up being really annoying. UAC is more turd polishing though. Hopefully windows 7 may have some better answers.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

