<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Philosophically Secure</title>
	<atom:link href="http://eugk.net/wordpress/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://eugk.net/wordpress</link>
	<description>Eugene Kogan&#039;s blog on information security and software engineering</description>
	<lastBuildDate>Fri, 29 Oct 2010 15:12:39 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>Comment on Glimers of hope in OS security by Dave McGuffey</title>
		<link>http://eugk.net/wordpress/2010/04/13/glimers-of-hope-in-os-security/comment-page-1/#comment-56816</link>
		<dc:creator>Dave McGuffey</dc:creator>
		<pubDate>Fri, 29 Oct 2010 15:12:39 +0000</pubDate>
		<guid isPermaLink="false">http://eugk.net/wordpress/?p=278#comment-56816</guid>
		<description><![CDATA[Eugene,

Long time no see. Good to find your blog.

WRT operating systems, many are actually getting better. Red Hat and Apple have continued to make great strides to make their operating systems stronger and more resilient to attack and better able to contain successful attacks. Over time SELinux has spread its wings over an ever larger number of system daemons and user-space applications.  RHEL 6 (beta) extends SELinux to provide MAC protection of the kernel and cover the kvm virtual machines. It also provides some capability to sandbox applications. Oracle/Sun are working to embed an SELinux-like capability into Solaris. Win7 is stronger than its predecessors. I personally think MS is falling behind in the OS realm because of all the legacy code they are dragging around to support legacy apps...but they are moving forward.

When one looks at the successful attacks, almost all are going into the application layer. There are tens of thousands of network-aware apps out there that were built with little to no security, and many are not supported by their developers with patches, preferring to wait for the next version release. Because there is so little incentive to develop apps that are more secure, maybe the only way forward is to consider all of them untrustworthy, and let the OS sandbox them all.

Until we change the software engineer mindset, crappy vulnerable code will continue to hit the market. 

I hate lawyers, but I believe we&#039;ve reached the point where Congress needs to invalidate those worthless software licenses and expose the developers to civil and criminal penalties for failing to do &quot;due diligence&quot; in the development cycle.]]></description>
		<content:encoded><![CDATA[<p>Eugene,</p>
<p>Long time no see. Good to find your blog.</p>
<p>WRT operating systems, many are actually getting better. Red Hat and Apple have continued to make great strides to make their operating systems stronger and more resilient to attack and better able to contain successful attacks. Over time SELinux has spread its wings over an ever larger number of system daemons and user-space applications.  RHEL 6 (beta) extends SELinux to provide MAC protection of the kernel and cover the kvm virtual machines. It also provides some capability to sandbox applications. Oracle/Sun are working to embed an SELinux-like capability into Solaris. Win7 is stronger than its predecessors. I personally think MS is falling behind in the OS realm because of all the legacy code they are dragging around to support legacy apps&#8230;but they are moving forward.</p>
<p>When one looks at the successful attacks, almost all are going into the application layer. There are tens of thousands of network-aware apps out there that were built with little to no security, and many are not supported by their developers with patches, preferring to wait for the next version release. Because there is so little incentive to develop apps that are more secure, maybe the only way forward is to consider all of them untrustworthy, and let the OS sandbox them all.</p>
<p>Until we change the software engineer mindset, crappy vulnerable code will continue to hit the market. </p>
<p>I hate lawyers, but I believe we&#8217;ve reached the point where Congress needs to invalidate those worthless software licenses and expose the developers to civil and criminal penalties for failing to do &#8220;due diligence&#8221; in the development cycle.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Mmm, forever cookies by Daniel Molina</title>
		<link>http://eugk.net/wordpress/2010/09/22/mmm-forever-cookies/comment-page-1/#comment-56341</link>
		<dc:creator>Daniel Molina</dc:creator>
		<pubDate>Tue, 28 Sep 2010 12:09:14 +0000</pubDate>
		<guid isPermaLink="false">http://eugk.net/wordpress/?p=291#comment-56341</guid>
		<description><![CDATA[Looks nice and very useful. I will review the implementation and its codependencies, if any. Thanks for your post. I&#039;ve added the project to my bookmarks. I&#039;m interested on how it works.]]></description>
		<content:encoded><![CDATA[<p>Looks nice and very useful. I will review the implementation and its codependencies, if any. Thanks for your post. I&#8217;ve added the project to my bookmarks. I&#8217;m interested on how it works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hackers for Charity: AOET.org project by Rev.Samson Kayoti Wafula</title>
		<link>http://eugk.net/wordpress/2008/03/05/hackers-for-charity-aoetorg-project/comment-page-1/#comment-55008</link>
		<dc:creator>Rev.Samson Kayoti Wafula</dc:creator>
		<pubDate>Thu, 05 Aug 2010 08:00:48 +0000</pubDate>
		<guid isPermaLink="false">http://eugk.net/wordpress/2008/03/05/hackers-for-charity-aoetorg-project/#comment-55008</guid>
		<description><![CDATA[We have a young christian ministry which has a church, a school for orphans and other vulnerable children and other initiatves meant to reach the rural needy families. What and how can we have a website designed for us?]]></description>
		<content:encoded><![CDATA[<p>We have a young christian ministry which has a church, a school for orphans and other vulnerable children and other initiatves meant to reach the rural needy families. What and how can we have a website designed for us?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Automated Web-Based Malware Behavior Analysis by eugenekogan</title>
		<link>http://eugk.net/wordpress/2008/10/21/automated-web-based-malware-behavior-analysis/comment-page-1/#comment-39195</link>
		<dc:creator>eugenekogan</dc:creator>
		<pubDate>Wed, 22 Oct 2008 23:35:08 +0000</pubDate>
		<guid isPermaLink="false">http://eugk.net/wordpress/?p=166#comment-39195</guid>
		<description><![CDATA[I got this comment from the presenter this morning:

Your name:     Tyler Hudak

Message:        Thanks for watching the video of my presentation! The reason I didn&#039;t show how the info is presented to the user (which comes in both the raw files generated and a tidy little HTML report) was that I was running short on time and OWASP was being VERY strict about going over at the conference (as they should). You are also correct in that its not that pretty, since its an internal-only device at this point. :)]]></description>
		<content:encoded><![CDATA[<p>I got this comment from the presenter this morning:</p>
<p>Your name:     Tyler Hudak</p>
<p>Message:        Thanks for watching the video of my presentation! The reason I didn&#8217;t show how the info is presented to the user (which comes in both the raw files generated and a tidy little HTML report) was that I was running short on time and OWASP was being VERY strict about going over at the conference (as they should). You are also correct in that its not that pretty, since its an internal-only device at this point. <img src='http://eugk.net/wordpress/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Django from the ground up by kevin</title>
		<link>http://eugk.net/wordpress/2008/09/26/django-from-the-ground-up/comment-page-1/#comment-31069</link>
		<dc:creator>kevin</dc:creator>
		<pubDate>Sat, 27 Sep 2008 00:30:51 +0000</pubDate>
		<guid isPermaLink="false">http://eugk.net/wordpress/?p=131#comment-31069</guid>
		<description><![CDATA[Thanks so much for the kind words about This Week in Django. Eric did an amazing job and has a few more casts lined up in the future. If you have any feedback regarding the site, just let us know!]]></description>
		<content:encoded><![CDATA[<p>Thanks so much for the kind words about This Week in Django. Eric did an amazing job and has a few more casts lined up in the future. If you have any feedback regarding the site, just let us know!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
