<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Security Power Play</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=571" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=571</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=571&#038;cpage=1#comment-861</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Tue, 09 Aug 2005 12:47:29 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=571#comment-861</guid>
		<description><![CDATA[This is a reference to the FACT that the probability of a white hat and a black hat finding the same vulnerability is very, very low within the random world of every vuln that exists everywhere, and of course black hats are motivated to actively reduce even this number. We all are pretty certain that, on average, about 10 NEW vulns will be found by good guys tomorrow, the next day, etc. And yet we do nothing about them today, even though those are the vulns we claim to care about.

(I shouldn&#039;t have said &quot;there is nothing [we] are doing...&quot; I meant that statement wrt white hat vulnerability research.)
]]></description>
		<content:encoded><![CDATA[<p>This is a reference to the FACT that the probability of a white hat and a black hat finding the same vulnerability is very, very low within the random world of every vuln that exists everywhere, and of course black hats are motivated to actively reduce even this number. We all are pretty certain that, on average, about 10 NEW vulns will be found by good guys tomorrow, the next day, etc. And yet we do nothing about them today, even though those are the vulns we claim to care about.</p>
<p>(I shouldn&#8217;t have said &#8220;there is nothing [we] are doing&#8230;&#8221; I meant that statement wrt white hat vulnerability research.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Axel Eble</title>
		<link>http://spiresecurity.com/?p=571&#038;cpage=1#comment-860</link>
		<dc:creator>Axel Eble</dc:creator>
		<pubDate>Tue, 09 Aug 2005 06:52:37 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=571#comment-860</guid>
		<description><![CDATA[&quot;If the risk is there, there is nothing the &quot;good guys&quot; are doing that will eliminate it (this is a key point - I suggest reading it over and over until its meaning actually dawns on you). Even reducing it is pretty unlikely, based on current research.&quot;

Can you elaborate a bit on that? I agree with &quot;If it isn&#039;t there, we are just proving how geeky security people can be and forcing everyone else to live on our terms, and ultimately ruining the online experience for many people.&quot; but not necessarily with the former statement.
]]></description>
		<content:encoded><![CDATA[<p>&#8220;If the risk is there, there is nothing the &#8220;good guys&#8221; are doing that will eliminate it (this is a key point &#8211; I suggest reading it over and over until its meaning actually dawns on you). Even reducing it is pretty unlikely, based on current research.&#8221;</p>
<p>Can you elaborate a bit on that? I agree with &#8220;If it isn&#8217;t there, we are just proving how geeky security people can be and forcing everyone else to live on our terms, and ultimately ruining the online experience for many people.&#8221; but not necessarily with the former statement.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
