<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Every Time it Comes Up&#8230;</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=344" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=344</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=344&#038;cpage=1#comment-488</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Fri, 16 Feb 2007 15:26:52 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=344#comment-488</guid>
		<description><![CDATA[@Rob -

Well, it&#039;s correct to the extent that he says we will pay more, if that is what you mean. You will pay more for insurance, of course, or will be forced out of the market because nobody will buy uninsured products.

It is interesting to me that you suggest nobody else is doing what you are doing... because they are and your code isn&#039;t as good as you think it is (unless it is a trivially simple program). Btw, who is out there trying to purposely write bad code?

This is the big problem with liability - we are never done and nobody can prove that anyone else is &quot;better&quot; or &quot;worse&quot; and so everyone pays, starting with the big guys and then trickling down to the little guys. Since the big guys can afford it, they weather the storm. You die along with all the other little guys. (By the way, you will also be forced out of any sort of integration attempts with other software.)
]]></description>
		<content:encoded><![CDATA[<p>@Rob -</p>
<p>Well, it&#8217;s correct to the extent that he says we will pay more, if that is what you mean. You will pay more for insurance, of course, or will be forced out of the market because nobody will buy uninsured products.</p>
<p>It is interesting to me that you suggest nobody else is doing what you are doing&#8230; because they are and your code isn&#8217;t as good as you think it is (unless it is a trivially simple program). Btw, who is out there trying to purposely write bad code?</p>
<p>This is the big problem with liability &#8211; we are never done and nobody can prove that anyone else is &#8220;better&#8221; or &#8220;worse&#8221; and so everyone pays, starting with the big guys and then trickling down to the little guys. Since the big guys can afford it, they weather the storm. You die along with all the other little guys. (By the way, you will also be forced out of any sort of integration attempts with other software.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Lewis</title>
		<link>http://spiresecurity.com/?p=344&#038;cpage=1#comment-487</link>
		<dc:creator>Rob Lewis</dc:creator>
		<pubDate>Fri, 16 Feb 2007 14:47:09 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=344#comment-487</guid>
		<description><![CDATA[But is his argument correct in economic terms? Would such a thing put the onus on vendors to release cleaner code?

We have our own Linux distribution (Snaplinux) that features production level code, cleaner than RH or Novell. It is maintained and tested single-handedly through automation. If we can do it, why can&#039;t everyone else?

The whole economic question can be pointed at the industry as a whole though, and is done through by people like Marcus Ranum. Why is there so much emphasis on patching instead of finding ways to prevent threat enablement due to vulnerabilities?
]]></description>
		<content:encoded><![CDATA[<p>But is his argument correct in economic terms? Would such a thing put the onus on vendors to release cleaner code?</p>
<p>We have our own Linux distribution (Snaplinux) that features production level code, cleaner than RH or Novell. It is maintained and tested single-handedly through automation. If we can do it, why can&#8217;t everyone else?</p>
<p>The whole economic question can be pointed at the industry as a whole though, and is done through by people like Marcus Ranum. Why is there so much emphasis on patching instead of finding ways to prevent threat enablement due to vulnerabilities?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
