<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for What The Hell? Security</title>
	<atom:link href="http://whatthehellsecurity.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://whatthehellsecurity.com</link>
	<description>startling new ways of thinking about security</description>
	<lastBuildDate>Sat, 17 Jul 2010 06:40:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on about by hell if i know</title>
		<link>http://whatthehellsecurity.com/about2/#comment-294</link>
		<dc:creator><![CDATA[hell if i know]]></dc:creator>
		<pubDate>Sat, 17 Jul 2010 06:40:01 +0000</pubDate>
		<guid isPermaLink="false">http://whatthehellsecurity.com/?page_id=665#comment-294</guid>
		<description><![CDATA[You&#039;re absolutely right.  I have not addressed that. Chalk it up to &quot;lost objectivity.&quot;  My next post will address it.]]></description>
		<content:encoded><![CDATA[<p>You&#8217;re absolutely right.  I have not addressed that. Chalk it up to &#8220;lost objectivity.&#8221;  My next post will address it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on about by Eric Stott</title>
		<link>http://whatthehellsecurity.com/about2/#comment-292</link>
		<dc:creator><![CDATA[Eric Stott]]></dc:creator>
		<pubDate>Fri, 16 Jul 2010 16:52:36 +0000</pubDate>
		<guid isPermaLink="false">http://whatthehellsecurity.com/?page_id=665#comment-292</guid>
		<description><![CDATA[How would you solve the answer to the SSL bribes? I mean, would you put together a new authentication system altogether, or train internet users (that small subset of the world&#039;s population) that the warning when either a company has refused to pay the SSL bribe, or created self signed certificates: should be ignored, or something altogether different?
Or am I missing the point altogether?]]></description>
		<content:encoded><![CDATA[<p>How would you solve the answer to the SSL bribes? I mean, would you put together a new authentication system altogether, or train internet users (that small subset of the world&#8217;s population) that the warning when either a company has refused to pay the SSL bribe, or created self signed certificates: should be ignored, or something altogether different?<br />
Or am I missing the point altogether?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on about by wth</title>
		<link>http://whatthehellsecurity.com/about2/#comment-291</link>
		<dc:creator><![CDATA[wth]]></dc:creator>
		<pubDate>Fri, 16 Jul 2010 08:16:25 +0000</pubDate>
		<guid isPermaLink="false">http://whatthehellsecurity.com/?page_id=665#comment-291</guid>
		<description><![CDATA[This is an outstanding question.   One of my goals is to NEVER ridicule something unless:

(1) I have years of experience with it, AND ...

(2) Those years have led me to conclude there has got to be a better way of accomplishing the goal, AND ...

(3) I&#039;ve invested a great deal of time identifying a better way, where &quot;better&quot; definitely includes &quot;viable&quot; but not necessarily &quot;easy,&quot; AND ...

(4) I&#039;ve persuaded a handful of security pros whom I deeply respect, that my &quot;better&quot; way is indeed better

Naturally I aim not to miss the mark here, so when I do or appears I do, I reckon it&#039;s due to one or more of:

(a) Having so much to say, I have to say it in chunks e.g. The 9 Laws of Phishing, OR ...

(b) I&#039;ve lost objectivity from having thought about it so long, OR ...

(c) I&#039;ve simply missed the mark

It would be helpful for me if you could point out one or two posts that need clarification.]]></description>
		<content:encoded><![CDATA[<p>This is an outstanding question.   One of my goals is to NEVER ridicule something unless:</p>
<p>(1) I have years of experience with it, AND &#8230;</p>
<p>(2) Those years have led me to conclude there has got to be a better way of accomplishing the goal, AND &#8230;</p>
<p>(3) I&#8217;ve invested a great deal of time identifying a better way, where &#8220;better&#8221; definitely includes &#8220;viable&#8221; but not necessarily &#8220;easy,&#8221; AND &#8230;</p>
<p>(4) I&#8217;ve persuaded a handful of security pros whom I deeply respect, that my &#8220;better&#8221; way is indeed better</p>
<p>Naturally I aim not to miss the mark here, so when I do or appears I do, I reckon it&#8217;s due to one or more of:</p>
<p>(a) Having so much to say, I have to say it in chunks e.g. The 9 Laws of Phishing, OR &#8230;</p>
<p>(b) I&#8217;ve lost objectivity from having thought about it so long, OR &#8230;</p>
<p>(c) I&#8217;ve simply missed the mark</p>
<p>It would be helpful for me if you could point out one or two posts that need clarification.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on about by Eric Stott</title>
		<link>http://whatthehellsecurity.com/about2/#comment-286</link>
		<dc:creator><![CDATA[Eric Stott]]></dc:creator>
		<pubDate>Wed, 14 Jul 2010 07:43:17 +0000</pubDate>
		<guid isPermaLink="false">http://whatthehellsecurity.com/?page_id=665#comment-286</guid>
		<description><![CDATA[I have read all of your blog entries: all VERY riveting.
I totally understand where you are coming from and totally agree that security is essentially a SHAM.
I am not a security guy, and so I ask: since you are a security guy -&gt; what would you do different?
It appears to be be a lot of soap-box screaming, but with no suggestions on what to do better, what good is this blog?
Did I just waste an entire night reading every single blog entry searching for answers, only to walk away empty handed?

Excitedly waiting for some alternatives to SSL-Bribes.]]></description>
		<content:encoded><![CDATA[<p>I have read all of your blog entries: all VERY riveting.<br />
I totally understand where you are coming from and totally agree that security is essentially a SHAM.<br />
I am not a security guy, and so I ask: since you are a security guy -&gt; what would you do different?<br />
It appears to be be a lot of soap-box screaming, but with no suggestions on what to do better, what good is this blog?<br />
Did I just waste an entire night reading every single blog entry searching for answers, only to walk away empty handed?</p>
<p>Excitedly waiting for some alternatives to SSL-Bribes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Security and the Unforeseen Use Case by Tweets that mention Security and the Unforeseen Use Case « What The Hell? Security -- Topsy.com</title>
		<link>http://whatthehellsecurity.com/2010/03/15/security-and-the-unforeseen-use-case/#comment-210</link>
		<dc:creator><![CDATA[Tweets that mention Security and the Unforeseen Use Case « What The Hell? Security -- Topsy.com]]></dc:creator>
		<pubDate>Thu, 03 Jun 2010 12:49:31 +0000</pubDate>
		<guid isPermaLink="false">http://whatthehellsecurity.com/?p=1372#comment-210</guid>
		<description><![CDATA[[...] This post was mentioned on Twitter by Hart Rossman, Hart Rossman and Joshua Corman, Rugged. Rugged said: &#039;Thank you! Very few [security]/people get this. &quot;Security and the Unforeseen Use Case&quot; http://bit.ly/d3EcLz an interesting piece.&#039; #Rugged [...]]]></description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Hart Rossman, Hart Rossman and Joshua Corman, Rugged. Rugged said: &#039;Thank you! Very few [security]/people get this. &quot;Security and the Unforeseen Use Case&quot; <a href="http://bit.ly/d3EcLz" rel="nofollow">http://bit.ly/d3EcLz</a> an interesting piece.&#039; #Rugged [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Security and the Unforeseen Use Case by joe jackson</title>
		<link>http://whatthehellsecurity.com/2010/03/15/security-and-the-unforeseen-use-case/#comment-209</link>
		<dc:creator><![CDATA[joe jackson]]></dc:creator>
		<pubDate>Thu, 03 Jun 2010 05:43:50 +0000</pubDate>
		<guid isPermaLink="false">http://whatthehellsecurity.com/?p=1372#comment-209</guid>
		<description><![CDATA[Nicely done.  Very much in line with the &lt;a href=&quot;http://ruggedsoftware.org&quot; rel=&quot;nofollow&quot;&gt;rugged software manifesto&lt;/a&gt;.]]></description>
		<content:encoded><![CDATA[<p>Nicely done.  Very much in line with the <a href="http://ruggedsoftware.org" rel="nofollow">rugged software manifesto</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Fishing for Red Herring Phishing Solutions by ljh</title>
		<link>http://whatthehellsecurity.com/2010/04/13/fishing-for-red-herring-phishing-solutions/#comment-136</link>
		<dc:creator><![CDATA[ljh]]></dc:creator>
		<pubDate>Wed, 14 Apr 2010 12:34:48 +0000</pubDate>
		<guid isPermaLink="false">http://whatthehellsecurity.com/?p=1478#comment-136</guid>
		<description><![CDATA[Fair enough.  But since I agree that email is a vector it&#039;s not clear to me where we diverge.  And actually you&#039;re one of a tiny group of people that know anything about phishing who have ever been willing to agree that phishing is not about email, without putting up at least a small fight.

I agree that Netflix credentials are boring in the grand scheme of things.  But if I were a phisher that&#039;s not what I&#039;d be after if I sent a Netflix phish.  I would just want you to click on the link and drop some malware your way before redirecting you to Netflix.  Then I&#039;d own you.

Anyway, I&#039;ve spent half of ecommerce history working for an ecommerce powerhouse.  We processed nowhere near the trillions that pass through a bank like yours each year, but it was plenty of billions.  And PII is PII even if you can&#039;t milk cash from it the minute you reel it in.]]></description>
		<content:encoded><![CDATA[<p>Fair enough.  But since I agree that email is a vector it&#8217;s not clear to me where we diverge.  And actually you&#8217;re one of a tiny group of people that know anything about phishing who have ever been willing to agree that phishing is not about email, without putting up at least a small fight.</p>
<p>I agree that Netflix credentials are boring in the grand scheme of things.  But if I were a phisher that&#8217;s not what I&#8217;d be after if I sent a Netflix phish.  I would just want you to click on the link and drop some malware your way before redirecting you to Netflix.  Then I&#8217;d own you.</p>
<p>Anyway, I&#8217;ve spent half of ecommerce history working for an ecommerce powerhouse.  We processed nowhere near the trillions that pass through a bank like yours each year, but it was plenty of billions.  And PII is PII even if you can&#8217;t milk cash from it the minute you reel it in.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Fishing for Red Herring Phishing Solutions by Phishing dude</title>
		<link>http://whatthehellsecurity.com/2010/04/13/fishing-for-red-herring-phishing-solutions/#comment-134</link>
		<dc:creator><![CDATA[Phishing dude]]></dc:creator>
		<pubDate>Wed, 14 Apr 2010 02:49:37 +0000</pubDate>
		<guid isPermaLink="false">http://whatthehellsecurity.com/?p=1478#comment-134</guid>
		<description><![CDATA[So, phishing is not about e-mail? Um, DUH.

Phishing is about USING e-mail as a channel to dupe people into forking over their banking credentials. Sears.com credentials? Nope. Netflix credentials? LOL. Wells Fargo credentials? You betcha. 

Tell you what -- how about you go work for any company that stores other people&#039;s money as a business, and then come talk to us about phishing, ok?]]></description>
		<content:encoded><![CDATA[<p>So, phishing is not about e-mail? Um, DUH.</p>
<p>Phishing is about USING e-mail as a channel to dupe people into forking over their banking credentials. Sears.com credentials? Nope. Netflix credentials? LOL. Wells Fargo credentials? You betcha. </p>
<p>Tell you what &#8212; how about you go work for any company that stores other people&#8217;s money as a business, and then come talk to us about phishing, ok?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on about by Cormac Herley</title>
		<link>http://whatthehellsecurity.com/about2/#comment-130</link>
		<dc:creator><![CDATA[Cormac Herley]]></dc:creator>
		<pubDate>Sat, 10 Apr 2010 00:16:52 +0000</pubDate>
		<guid isPermaLink="false">http://whatthehellsecurity.com/?page_id=665#comment-130</guid>
		<description><![CDATA[I&#039;m privileged then to know the Scarlet Pimpernel of security? Best of luck as you try to save sanity from the clutches of Madame Guillotine. Will this Reign of Terror never end?]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m privileged then to know the Scarlet Pimpernel of security? Best of luck as you try to save sanity from the clutches of Madame Guillotine. Will this Reign of Terror never end?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on about by whatthehe11</title>
		<link>http://whatthehellsecurity.com/about2/#comment-127</link>
		<dc:creator><![CDATA[whatthehe11]]></dc:creator>
		<pubDate>Wed, 07 Apr 2010 02:23:56 +0000</pubDate>
		<guid isPermaLink="false">http://whatthehellsecurity.com/?page_id=665#comment-127</guid>
		<description><![CDATA[Thank you for the high compliment Cormac.  To add to the mystery: We actually know each other.  :)]]></description>
		<content:encoded><![CDATA[<p>Thank you for the high compliment Cormac.  To add to the mystery: We actually know each other.  :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

