<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Is Privacy Rights Clearinghouse Purposely Lying?</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=349" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=349</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=349&#038;cpage=1#comment-505</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Tue, 23 Jan 2007 15:47:12 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=349#comment-505</guid>
		<description><![CDATA[@Dan -

An interesting point, but then all credit card numbers and SSNs should be the operative upper bound for the threat assessment - they are used too often not to be.

In addition, after scanning the PRC chronology, I don&#039;t believe they adhere to your process. In fact, they are fairly conservative in what numbers they include in the total, and use the most accurate estimates that exist, except in this case.

It is easy to see why - dropping the 100 million by 40 million (about) would significantly impact their ability to get back to that 100 million number any time soon.
]]></description>
		<content:encoded><![CDATA[<p>@Dan -</p>
<p>An interesting point, but then all credit card numbers and SSNs should be the operative upper bound for the threat assessment &#8211; they are used too often not to be.</p>
<p>In addition, after scanning the PRC chronology, I don&#8217;t believe they adhere to your process. In fact, they are fairly conservative in what numbers they include in the total, and use the most accurate estimates that exist, except in this case.</p>
<p>It is easy to see why &#8211; dropping the 100 million by 40 million (about) would significantly impact their ability to get back to that 100 million number any time soon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spire Security Viewpoint</title>
		<link>http://spiresecurity.com/?p=349&#038;cpage=1#comment-506</link>
		<dc:creator>Spire Security Viewpoint</dc:creator>
		<pubDate>Tue, 23 Jan 2007 15:43:57 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=349#comment-506</guid>
		<description><![CDATA[&lt;strong&gt;Compromise, Loss, Exposure, and Disclosure&lt;/strong&gt;

Does Chris Walsh need a trim for all his hairsplitting? ;-) I have been taken to task by Emergent Chaos for my use of the term lost instead of compromised with respect to Privacy Rights Clearinghouse&#039;s tally for data breaches. [It is particularly telli...
]]></description>
		<content:encoded><![CDATA[<p><strong>Compromise, Loss, Exposure, and Disclosure</strong></p>
<p>Does Chris Walsh need a trim for all his hairsplitting? <img src='http://spiresecurity.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  I have been taken to task by Emergent Chaos for my use of the term lost instead of compromised with respect to Privacy Rights Clearinghouse&#8217;s tally for data breaches. [It is particularly telli&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Riley</title>
		<link>http://spiresecurity.com/?p=349&#038;cpage=1#comment-504</link>
		<dc:creator>Dan Riley</dc:creator>
		<pubDate>Tue, 23 Jan 2007 12:20:53 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=349#comment-504</guid>
		<description><![CDATA[263,000 is the number of records &quot;confirmed to have left the CardSystems platform&quot;--a lower bound on the number of records &quot;lost&quot;.  In threat assessment it is the upper bound that matters.  While Perry&#039;s testimony tries hard to make it sound like only those records were shipped offsite, he doesn&#039;t actually say so.  Unless there&#039;s a more convincing statement out there, the 40 million records reported to have been exposed remains the operative upper bound for that security breach.
]]></description>
		<content:encoded><![CDATA[<p>263,000 is the number of records &#8220;confirmed to have left the CardSystems platform&#8221;&#8211;a lower bound on the number of records &#8220;lost&#8221;.  In threat assessment it is the upper bound that matters.  While Perry&#8217;s testimony tries hard to make it sound like only those records were shipped offsite, he doesn&#8217;t actually say so.  Unless there&#8217;s a more convincing statement out there, the 40 million records reported to have been exposed remains the operative upper bound for that security breach.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spire Security Viewpoint</title>
		<link>http://spiresecurity.com/?p=349&#038;cpage=1#comment-507</link>
		<dc:creator>Spire Security Viewpoint</dc:creator>
		<pubDate>Mon, 22 Jan 2007 04:12:31 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=349#comment-507</guid>
		<description><![CDATA[&lt;strong&gt;Compromise, Loss, Exposure, and Disclosure&lt;/strong&gt;

Does Chris Walsh need a trim for all his hairsplitting? ;-) I have been taken to task by Emergent Chaos for my use of the term lost instead of compromised with respect to Privacy Rights Clearinghouse&#039;s tally for data breaches. [It is particularly telli...
]]></description>
		<content:encoded><![CDATA[<p><strong>Compromise, Loss, Exposure, and Disclosure</strong></p>
<p>Does Chris Walsh need a trim for all his hairsplitting? <img src='http://spiresecurity.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  I have been taken to task by Emergent Chaos for my use of the term lost instead of compromised with respect to Privacy Rights Clearinghouse&#8217;s tally for data breaches. [It is particularly telli&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
