<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: More proof that security isn&#8217;t failing</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=264" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=264</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: 1 Raindrop</title>
		<link>http://spiresecurity.com/?p=264&#038;cpage=1#comment-361</link>
		<dc:creator>1 Raindrop</dc:creator>
		<pubDate>Fri, 19 Oct 2007 14:10:50 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=264#comment-361</guid>
		<description><![CDATA[&lt;strong&gt;Sacred Cow Gored? Check.&lt;/strong&gt;

As only a certified security high priest can do, Gene Spafford has started a linkfest o&#039; love spawning numerous backslapping from some of my favorite people in the blogosphere. I hate enjoy to be the contrarian, so while I agree with the general senitm...
]]></description>
		<content:encoded><![CDATA[<p><strong>Sacred Cow Gored? Check.</strong></p>
<p>As only a certified security high priest can do, Gene Spafford has started a linkfest o&#8217; love spawning numerous backslapping from some of my favorite people in the blogosphere. I hate enjoy to be the contrarian, so while I agree with the general senitm&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 1 Raindrop</title>
		<link>http://spiresecurity.com/?p=264&#038;cpage=1#comment-362</link>
		<dc:creator>1 Raindrop</dc:creator>
		<pubDate>Thu, 18 Oct 2007 20:03:39 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=264#comment-362</guid>
		<description><![CDATA[&lt;strong&gt;Sacred Cow Gored? Check.&lt;/strong&gt;

As only a certified security high priest can do, Gene Spafford has started a linkfest o&#039; love spawning numerous backslapping from some of my favorite people in the blogosphere. I hate enjoy to be the contrarian, so while I agree with the general senitm...
]]></description>
		<content:encoded><![CDATA[<p><strong>Sacred Cow Gored? Check.</strong></p>
<p>As only a certified security high priest can do, Gene Spafford has started a linkfest o&#8217; love spawning numerous backslapping from some of my favorite people in the blogosphere. I hate enjoy to be the contrarian, so while I agree with the general senitm&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=264&#038;cpage=1#comment-360</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Wed, 17 Oct 2007 16:07:34 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=264#comment-360</guid>
		<description><![CDATA[@Tyler -

I didn&#039;t get that message from his blog. I am suggesting that the assertions he makes are excellent evidence that security ISN&#039;T failing.

Pete
]]></description>
		<content:encoded><![CDATA[<p>@Tyler -</p>
<p>I didn&#8217;t get that message from his blog. I am suggesting that the assertions he makes are excellent evidence that security ISN&#8217;T failing.</p>
<p>Pete</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tyler</title>
		<link>http://spiresecurity.com/?p=264&#038;cpage=1#comment-359</link>
		<dc:creator>Tyler</dc:creator>
		<pubDate>Wed, 17 Oct 2007 15:53:01 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=264#comment-359</guid>
		<description><![CDATA[Pete, I don&#039;t know how you got the message that security ISN&#039;T failing out of that blog entry. As far as I understood it, the point is that we&#039;re wasting time and money treating the symptoms, rather than the problem. The point is that we can NEVER succeed if we keep doing what we&#039;re doing.
]]></description>
		<content:encoded><![CDATA[<p>Pete, I don&#8217;t know how you got the message that security ISN&#8217;T failing out of that blog entry. As far as I understood it, the point is that we&#8217;re wasting time and money treating the symptoms, rather than the problem. The point is that we can NEVER succeed if we keep doing what we&#8217;re doing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: shrdlu</title>
		<link>http://spiresecurity.com/?p=264&#038;cpage=1#comment-358</link>
		<dc:creator>shrdlu</dc:creator>
		<pubDate>Wed, 17 Oct 2007 13:49:12 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=264#comment-358</guid>
		<description><![CDATA[Cherchez l&#039;argent, mes amis.  Mix in Spaf&#039;s argument with Pete&#039;s and add Marcus and Bruce, and you&#039;ve got the answer:  people don&#039;t think security is failing enough to spend money doing something about it.  The externalities aren&#039;t intolerable.  The public isn&#039;t up in arms; if anything, security breaches have reached the same level of public semi-awareness as bombing in Iraq -- it happens every day, everyone agrees how awful it is, and then they go back to their lattes.

We&#039;re not going to fire or retrain a generation of cheap programming labor to Do the Right Thing and redesign systems.  Not until it hurts enough, and let&#039;s face it, it doesn&#039;t.  All the FUD and hand-wringing is within the security industry.   We&#039;re doing our jobs just well enough to keep things from melting down, so why should anyone pay more attention and money to something that&#039;s  mediocre but not a disaster?


]]></description>
		<content:encoded><![CDATA[<p>Cherchez l&#8217;argent, mes amis.  Mix in Spaf&#8217;s argument with Pete&#8217;s and add Marcus and Bruce, and you&#8217;ve got the answer:  people don&#8217;t think security is failing enough to spend money doing something about it.  The externalities aren&#8217;t intolerable.  The public isn&#8217;t up in arms; if anything, security breaches have reached the same level of public semi-awareness as bombing in Iraq &#8212; it happens every day, everyone agrees how awful it is, and then they go back to their lattes.</p>
<p>We&#8217;re not going to fire or retrain a generation of cheap programming labor to Do the Right Thing and redesign systems.  Not until it hurts enough, and let&#8217;s face it, it doesn&#8217;t.  All the FUD and hand-wringing is within the security industry.   We&#8217;re doing our jobs just well enough to keep things from melting down, so why should anyone pay more attention and money to something that&#8217;s  mediocre but not a disaster?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christofer Hoff</title>
		<link>http://spiresecurity.com/?p=264&#038;cpage=1#comment-357</link>
		<dc:creator>Christofer Hoff</dc:creator>
		<pubDate>Wed, 17 Oct 2007 12:58:54 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=264#comment-357</guid>
		<description><![CDATA[In a rare moment of synchronicity, I saw Spaf&#039;s post in my Google Reader prior to yours and I despite your choice of words (not like mine on my blog did me any favors) I think I understand and agree with your idea.

/Hoff
]]></description>
		<content:encoded><![CDATA[<p>In a rare moment of synchronicity, I saw Spaf&#8217;s post in my Google Reader prior to yours and I despite your choice of words (not like mine on my blog did me any favors) I think I understand and agree with your idea.</p>
<p>/Hoff</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=264&#038;cpage=1#comment-356</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Wed, 17 Oct 2007 02:13:44 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=264#comment-356</guid>
		<description><![CDATA[@Chris -

My not-so-clearly made point is - since there are no significant obstacles to adding more security, then people/organizations are explicitly deciding against stronger protection. If that is the case, then security  can&#039;t be &quot;failing&quot; in their eyes (or they would spend more / do more).

Remember that whether or not security is failing can have multiple interpretations to individuals.

Hope this helps! ;-)
]]></description>
		<content:encoded><![CDATA[<p>@Chris -</p>
<p>My not-so-clearly made point is &#8211; since there are no significant obstacles to adding more security, then people/organizations are explicitly deciding against stronger protection. If that is the case, then security  can&#8217;t be &#8220;failing&#8221; in their eyes (or they would spend more / do more).</p>
<p>Remember that whether or not security is failing can have multiple interpretations to individuals.</p>
<p>Hope this helps! <img src='http://spiresecurity.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christofer Hoff</title>
		<link>http://spiresecurity.com/?p=264&#038;cpage=1#comment-355</link>
		<dc:creator>Christofer Hoff</dc:creator>
		<pubDate>Wed, 17 Oct 2007 01:40:37 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=264#comment-355</guid>
		<description><![CDATA[Pete:

I&#039;m just a plain ol&#039; country boy so I don&#039;t get how you got to the last sentence; I&#039;d suggest that preceding sentences suggest that since we&#039;re not doing what we&#039;re either capable of or *should* be doing, we&#039;re failing.

Certainly not doing the right things is not cause for celebrating success.
]]></description>
		<content:encoded><![CDATA[<p>Pete:</p>
<p>I&#8217;m just a plain ol&#8217; country boy so I don&#8217;t get how you got to the last sentence; I&#8217;d suggest that preceding sentences suggest that since we&#8217;re not doing what we&#8217;re either capable of or *should* be doing, we&#8217;re failing.</p>
<p>Certainly not doing the right things is not cause for celebrating success.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
