<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: A Great Example of Bugfinder Nirvana</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=173" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=173</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Pete Lindstrom</title>
		<link>http://spiresecurity.com/?p=173&#038;cpage=1#comment-234</link>
		<dc:creator>Pete Lindstrom</dc:creator>
		<pubDate>Wed, 08 Oct 2008 01:11:09 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=173#comment-234</guid>
		<description><![CDATA[@hellNbak -

&quot;That alone is proof that SDL does in fact work.&quot;

That is a gross misunderstanding of either 1) proof; 2) SDL; or 3) fact. At best, it may provide some information that seems to support your hypothesis, but that is it.

Here&#039;s a simple alternative notion - if the amount of external bugfinding effort on Microsoft products has been reduced to 1/10th the effort involved prior to SDL, then it will take 10 times as long to find bugs and the software would have the same level of vulnerability.
]]></description>
		<content:encoded><![CDATA[<p>@hellNbak -</p>
<p>&#8220;That alone is proof that SDL does in fact work.&#8221;</p>
<p>That is a gross misunderstanding of either 1) proof; 2) SDL; or 3) fact. At best, it may provide some information that seems to support your hypothesis, but that is it.</p>
<p>Here&#8217;s a simple alternative notion &#8211; if the amount of external bugfinding effort on Microsoft products has been reduced to 1/10th the effort involved prior to SDL, then it will take 10 times as long to find bugs and the software would have the same level of vulnerability.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hellNbak</title>
		<link>http://spiresecurity.com/?p=173&#038;cpage=1#comment-233</link>
		<dc:creator>hellNbak</dc:creator>
		<pubDate>Tue, 07 Oct 2008 22:18:40 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=173#comment-233</guid>
		<description><![CDATA[At least spell my name right Ryan.   ;-)

Name one remote system vulnerability found in the last 12 months in a Microsoft operating system.  That alone is proof that SDL does in fact work.  When I say work, I do not mean it is the silver bullet solution but it does improve the security of code.

So this has nothing to do with making me feel good because there are still many improvements that can be made and obviously any process like SDL is only as good as those following it.
]]></description>
		<content:encoded><![CDATA[<p>At least spell my name right Ryan.   <img src='http://spiresecurity.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Name one remote system vulnerability found in the last 12 months in a Microsoft operating system.  That alone is proof that SDL does in fact work.  When I say work, I do not mean it is the silver bullet solution but it does improve the security of code.</p>
<p>So this has nothing to do with making me feel good because there are still many improvements that can be made and obviously any process like SDL is only as good as those following it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan Naraine</title>
		<link>http://spiresecurity.com/?p=173&#038;cpage=1#comment-232</link>
		<dc:creator>Ryan Naraine</dc:creator>
		<pubDate>Mon, 21 Apr 2008 15:03:07 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=173#comment-232</guid>
		<description><![CDATA[hellnback is steve manzuik, formerly of eeye, now at juniper.

_ryan
]]></description>
		<content:encoded><![CDATA[<p>hellnback is steve manzuik, formerly of eeye, now at juniper.</p>
<p>_ryan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=173&#038;cpage=1#comment-231</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Mon, 21 Apr 2008 15:00:35 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=173#comment-231</guid>
		<description><![CDATA[@Patrick -

That&#039;s just it, that paragraph *is* his evidence. Which demonstrates my point that this whole issue is about faith and not evidence.

Yeah, couldn&#039;t resist the fanboy comment.. ;-)

Pete
]]></description>
		<content:encoded><![CDATA[<p>@Patrick -</p>
<p>That&#8217;s just it, that paragraph *is* his evidence. Which demonstrates my point that this whole issue is about faith and not evidence.</p>
<p>Yeah, couldn&#8217;t resist the fanboy comment.. <img src='http://spiresecurity.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Pete</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Boyd</title>
		<link>http://spiresecurity.com/?p=173&#038;cpage=1#comment-230</link>
		<dc:creator>Patrick Boyd</dc:creator>
		<pubDate>Mon, 21 Apr 2008 14:50:24 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=173#comment-230</guid>
		<description><![CDATA[So because he hasn&#039;t posted the evidence he is a fan boy?

Let me rephrase, by your logic you didn&#039;t prove that he is a fan boy therefore you have some sort of vendetta against HellnBak. :)
]]></description>
		<content:encoded><![CDATA[<p>So because he hasn&#8217;t posted the evidence he is a fan boy?</p>
<p>Let me rephrase, by your logic you didn&#8217;t prove that he is a fan boy therefore you have some sort of vendetta against HellnBak. <img src='http://spiresecurity.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
