<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ISS on its last Legs?</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=634" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=634</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=634&#038;cpage=1#comment-894</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Wed, 25 May 2005 18:08:16 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=634#comment-894</guid>
		<description><![CDATA[Latent vulnerabilities are abundant, it is only when they get &quot;discovered&quot; and notify the world that the vultures start circling.

In a very specific sense, it is extremely worthwhile to perform QA and patch those applications that are important to you.

In this very general sense, this only forces everyone to focus on this particular application rather than the ones that are of most importance to the enterprise.

So the answer to your question is no, I don&#039;t believe that unconstrained public vulnerability discovery simply to patch the holes (or gain market advantage) does anyone any good, and the costs are astronomical.

Regarding peer review and security companies playing together well... I talk to security vendors all the time. There is no love lost among them. I don&#039;t believe they are doing this altruistically.
]]></description>
		<content:encoded><![CDATA[<p>Latent vulnerabilities are abundant, it is only when they get &#8220;discovered&#8221; and notify the world that the vultures start circling.</p>
<p>In a very specific sense, it is extremely worthwhile to perform QA and patch those applications that are important to you.</p>
<p>In this very general sense, this only forces everyone to focus on this particular application rather than the ones that are of most importance to the enterprise.</p>
<p>So the answer to your question is no, I don&#8217;t believe that unconstrained public vulnerability discovery simply to patch the holes (or gain market advantage) does anyone any good, and the costs are astronomical.</p>
<p>Regarding peer review and security companies playing together well&#8230; I talk to security vendors all the time. There is no love lost among them. I don&#8217;t believe they are doing this altruistically.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hari Krishna</title>
		<link>http://spiresecurity.com/?p=634&#038;cpage=1#comment-893</link>
		<dc:creator>Hari Krishna</dc:creator>
		<pubDate>Wed, 25 May 2005 10:44:42 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=634#comment-893</guid>
		<description><![CDATA[Dont you think its actually good for the customers who are using those products. That a competitor is finding faults pushes companies to plug these holes/whatever faster. And often, reliability on a single product is a dangerous issues in security. This kind of finding bugs might be a kind of peer review of others products, benefitting the end user most, who might not have the time nor the expertise to look so deep.
]]></description>
		<content:encoded><![CDATA[<p>Dont you think its actually good for the customers who are using those products. That a competitor is finding faults pushes companies to plug these holes/whatever faster. And often, reliability on a single product is a dangerous issues in security. This kind of finding bugs might be a kind of peer review of others products, benefitting the end user most, who might not have the time nor the expertise to look so deep.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Axel</title>
		<link>http://spiresecurity.com/?p=634&#038;cpage=1#comment-892</link>
		<dc:creator>Axel</dc:creator>
		<pubDate>Thu, 03 Mar 2005 07:00:44 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=634#comment-892</guid>
		<description><![CDATA[I believe that ISS is actually trying to change their business model from software creation to vulnerability assessment. X-Code always was doing this and since the market for IDS and IPS devices and software isn&#039;t as hot as it used to be ISS is somewhat at a loss.

Why should they create new software products? If they don&#039;t want to any more, they&#039;re of course free to seek other venues.

Having said that, I do have to agree with your initial assessment. ISS reeks of a slow death.
]]></description>
		<content:encoded><![CDATA[<p>I believe that ISS is actually trying to change their business model from software creation to vulnerability assessment. X-Code always was doing this and since the market for IDS and IPS devices and software isn&#8217;t as hot as it used to be ISS is somewhat at a loss.</p>
<p>Why should they create new software products? If they don&#8217;t want to any more, they&#8217;re of course free to seek other venues.</p>
<p>Having said that, I do have to agree with your initial assessment. ISS reeks of a slow death.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
