<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Another Doomsday Scenario</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=517" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=517</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Chris Q</title>
		<link>http://spiresecurity.com/?p=517&#038;cpage=1#comment-804</link>
		<dc:creator>Chris Q</dc:creator>
		<pubDate>Thu, 03 Nov 2005 03:42:09 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=517#comment-804</guid>
		<description><![CDATA[All it takes to turn a black hat into a white hat is a big company offering them lots of money.  If there are no volunteers looking for holes, corporations will have to buy the services of someone who can keep their site up and running.
]]></description>
		<content:encoded><![CDATA[<p>All it takes to turn a black hat into a white hat is a big company offering them lots of money.  If there are no volunteers looking for holes, corporations will have to buy the services of someone who can keep their site up and running.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=517&#038;cpage=1#comment-803</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Wed, 02 Nov 2005 18:58:33 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=517#comment-803</guid>
		<description><![CDATA[@Chris - I do think the Rescorla paper is interesting, though there was an attempt to refute it by Andy Ozment.

@Anton -

re: your assumption that vuln researchers &quot;squash&quot; the bugs of black hats - isn&#039;t that a big assumption? The only related research on software rediscovery that I&#039;ve seen suggests that may 6-8% are rediscovered. Wouldn&#039;t you need to take away all an attacker&#039;s &quot;guns&quot; or &quot;bullets&quot; in order to protect against being shot? (I only need one).

re: being 0wned - I think you indicate that people would be 0wned over and over. Do you really think they would just all accept their fate forever?
]]></description>
		<content:encoded><![CDATA[<p>@Chris &#8211; I do think the Rescorla paper is interesting, though there was an attempt to refute it by Andy Ozment.</p>
<p>@Anton -</p>
<p>re: your assumption that vuln researchers &#8220;squash&#8221; the bugs of black hats &#8211; isn&#8217;t that a big assumption? The only related research on software rediscovery that I&#8217;ve seen suggests that may 6-8% are rediscovered. Wouldn&#8217;t you need to take away all an attacker&#8217;s &#8220;guns&#8221; or &#8220;bullets&#8221; in order to protect against being shot? (I only need one).</p>
<p>re: being 0wned &#8211; I think you indicate that people would be 0wned over and over. Do you really think they would just all accept their fate forever?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anton Chuvakin</title>
		<link>http://spiresecurity.com/?p=517&#038;cpage=1#comment-802</link>
		<dc:creator>Anton Chuvakin</dc:creator>
		<pubDate>Wed, 02 Nov 2005 16:39:31 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=517#comment-802</guid>
		<description><![CDATA[Fine, I&#039;ll bite! This is fun discussion.

&gt;1. What characteristics about our current
&gt;situation preclude this exact thing from
&gt;happening today?

On the positive side and assuming that vuln research &#039;squashes bugs&#039; that are possessed by blackhats (at least part of the time), there is a chance of fixing the problems before they are exploited

On the negative side, current situation has too much &#039;fighting noise&#039;

&gt;2. How come people won&#039;t be able to figure out
&gt;that they are 0wned?

Well, if a novel approach was used to attack you (new vuln or even a new class of vulns), you are left with a heap of evidence and a need for a bunch of skilled forensic investigators. You might be able to figure out that &#039;yes, indeed you got owned&#039; and possibly &#039;what they took&#039; but might be left in the dark about &#039;how they did it&#039;. At least, the latter is not a certainty.


]]></description>
		<content:encoded><![CDATA[<p>Fine, I&#8217;ll bite! This is fun discussion.</p>
<p>>1. What characteristics about our current<br />
>situation preclude this exact thing from<br />
>happening today?</p>
<p>On the positive side and assuming that vuln research &#8216;squashes bugs&#8217; that are possessed by blackhats (at least part of the time), there is a chance of fixing the problems before they are exploited</p>
<p>On the negative side, current situation has too much &#8216;fighting noise&#8217;</p>
<p>>2. How come people won&#8217;t be able to figure out<br />
>that they are 0wned?</p>
<p>Well, if a novel approach was used to attack you (new vuln or even a new class of vulns), you are left with a heap of evidence and a need for a bunch of skilled forensic investigators. You might be able to figure out that &#8216;yes, indeed you got owned&#8217; and possibly &#8216;what they took&#8217; but might be left in the dark about &#8216;how they did it&#8217;. At least, the latter is not a certainty.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Walsh</title>
		<link>http://spiresecurity.com/?p=517&#038;cpage=1#comment-801</link>
		<dc:creator>Chris Walsh</dc:creator>
		<pubDate>Wed, 02 Nov 2005 15:53:16 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=517#comment-801</guid>
		<description><![CDATA[Funny you should ask:

http://www.interesting-people.org/archives/interesting-people/200406/msg00035.html


]]></description>
		<content:encoded><![CDATA[<p>Funny you should ask:</p>
<p><a href="http://www.interesting-people.org/archives/interesting-people/200406/msg00035.html" rel="nofollow">http://www.interesting-people.org/archives/interesting-people/200406/msg00035.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anton Chuvakin</title>
		<link>http://spiresecurity.com/?p=517&#038;cpage=1#comment-800</link>
		<dc:creator>Anton Chuvakin</dc:creator>
		<pubDate>Wed, 02 Nov 2005 14:23:25 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=517#comment-800</guid>
		<description><![CDATA[Hmm, I never meant to project an impression that it is a &#039;doomsday scenario&#039; - see my comment in the end about the overall risk...
]]></description>
		<content:encoded><![CDATA[<p>Hmm, I never meant to project an impression that it is a &#8216;doomsday scenario&#8217; &#8211; see my comment in the end about the overall risk&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas H. Ptacek</title>
		<link>http://spiresecurity.com/?p=517&#038;cpage=1#comment-799</link>
		<dc:creator>Thomas H. Ptacek</dc:creator>
		<pubDate>Wed, 02 Nov 2005 12:25:17 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=517#comment-799</guid>
		<description><![CDATA[They&#039;ll be about as effective at knowing they&#039;re owned as they are today, which would be the problem. Don&#039;t even need lots of experience to know the answer to that question: it&#039;s why everyone&#039;s so concerned about Windows rootkits, not to mention the reason rootkits were invented (around 1992) in the first place.


]]></description>
		<content:encoded><![CDATA[<p>They&#8217;ll be about as effective at knowing they&#8217;re owned as they are today, which would be the problem. Don&#8217;t even need lots of experience to know the answer to that question: it&#8217;s why everyone&#8217;s so concerned about Windows rootkits, not to mention the reason rootkits were invented (around 1992) in the first place.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
