<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Whaddaya Know? The Need for Evidence-based Security</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=142" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=142</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Pete Lindstrom</title>
		<link>http://spiresecurity.com/?p=142&#038;cpage=1#comment-159</link>
		<dc:creator>Pete Lindstrom</dc:creator>
		<pubDate>Thu, 21 Aug 2008 04:17:06 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=142#comment-159</guid>
		<description><![CDATA[@Dean -

You&#039;ve highlighted the insidious part of this problem. Unless you&#039;re going to tell me that everyone who doesn&#039;t get compromised is invulnerable, we are simply cherry-picking vulnerabilities in hindsight.

There are almost certainly other entities that didn&#039;t get compromised yet have the exact same problems. And there are plenty of other problems to go along.

If everyone is some level of &quot;insecure&quot; then what level of insecurity is reasonable?
]]></description>
		<content:encoded><![CDATA[<p>@Dean -</p>
<p>You&#8217;ve highlighted the insidious part of this problem. Unless you&#8217;re going to tell me that everyone who doesn&#8217;t get compromised is invulnerable, we are simply cherry-picking vulnerabilities in hindsight.</p>
<p>There are almost certainly other entities that didn&#8217;t get compromised yet have the exact same problems. And there are plenty of other problems to go along.</p>
<p>If everyone is some level of &#8220;insecure&#8221; then what level of insecurity is reasonable?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dean Loomis</title>
		<link>http://spiresecurity.com/?p=142&#038;cpage=1#comment-158</link>
		<dc:creator>Dean Loomis</dc:creator>
		<pubDate>Thu, 21 Aug 2008 00:35:26 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=142#comment-158</guid>
		<description><![CDATA[&quot;T.J. Maxx, ChoicePoint, NextOnTheList Inc.? We know their programs were poor because they had an incident. Hogwash, pure hogwash.&quot; Hogwash indeed, but not for the reasons you say.  We know TJX was insecure because we know that they failed to remediate well-known weaknesses -- they used WEP security on their wireless LANs and didn&#039;t separate store networks from the HQ datacenter networks.  We know that Choicepoint was insecure because they didn&#039;t validate need to know for sensitive customer data.

Evidenced-based security will fail because the evidence is kept secret. It works in healthcare because the criteria for morbidity and mortality are well-defined, and there are penalties imposed on doctors ranging up to loss of license for failure to report critical cases.  The best that even Dan Geer can suggest for improving reporting is for the FASB to change accounting standards to require valuation of intangible assets.  Not gonna happen...
]]></description>
		<content:encoded><![CDATA[<p>&#8220;T.J. Maxx, ChoicePoint, NextOnTheList Inc.? We know their programs were poor because they had an incident. Hogwash, pure hogwash.&#8221; Hogwash indeed, but not for the reasons you say.  We know TJX was insecure because we know that they failed to remediate well-known weaknesses &#8212; they used WEP security on their wireless LANs and didn&#8217;t separate store networks from the HQ datacenter networks.  We know that Choicepoint was insecure because they didn&#8217;t validate need to know for sensitive customer data.</p>
<p>Evidenced-based security will fail because the evidence is kept secret. It works in healthcare because the criteria for morbidity and mortality are well-defined, and there are penalties imposed on doctors ranging up to loss of license for failure to report critical cases.  The best that even Dan Geer can suggest for improving reporting is for the FASB to change accounting standards to require valuation of intangible assets.  Not gonna happen&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
