<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Huh-huh!  I said &#8220;phuc&#8221;!</title>
	<atom:link href="http://www.macalope.com/2006/11/07/huh-huh-i-said-phuc/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.macalope.com/2006/11/07/huh-huh-i-said-phuc/</link>
	<description>Apple news and analysis from everyone's favorite mythical Mac user</description>
	<pubDate>Wed, 07 Jan 2009 05:24:43 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: fudo</title>
		<link>http://www.macalope.com/2006/11/07/huh-huh-i-said-phuc/comment-page-1/#comment-1265</link>
		<dc:creator>fudo</dc:creator>
		<pubDate>Tue, 14 Nov 2006 02:17:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=95#comment-1265</guid>
		<description>Unfortunately for Geoffrey, the "threat of legal action by Apple" is, just like the original "exploit", so much vapor. No convincing evidence that it exists anywhere outside of Maynor and Ellch's imaginations. And no, the fact that now, months later, Ellch has come up with a completely unrelated flaw proves, once again, nothing.

And as for "See what happens when companies get involved?" conveniently ignores the fact that security researchers who provide evidence of real exploits to Apple are routinely credited by Apple when patches are released.</description>
		<content:encoded><![CDATA[<p>Unfortunately for Geoffrey, the &#8220;threat of legal action by Apple&#8221; is, just like the original &#8220;exploit&#8221;, so much vapor. No convincing evidence that it exists anywhere outside of Maynor and Ellch&#8217;s imaginations. And no, the fact that now, months later, Ellch has come up with a completely unrelated flaw proves, once again, nothing.</p>
<p>And as for &#8220;See what happens when companies get involved?&#8221; conveniently ignores the fact that security researchers who provide evidence of real exploits to Apple are routinely credited by Apple when patches are released.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: geoffrey</title>
		<link>http://www.macalope.com/2006/11/07/huh-huh-i-said-phuc/comment-page-1/#comment-1255</link>
		<dc:creator>geoffrey</dc:creator>
		<pubDate>Sun, 12 Nov 2006 21:09:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=95#comment-1255</guid>
		<description>Happy? The month of kernel bugs has delivered a broadcom chip flaw from Ellch.

http://www.eweek.com/article2/0,1895,2056023,00.asp

Besides paying to defend yourself, if your employer has a lucrative contract with Apple or Intel, and they threaten to kill the contract, that is a threatening action as well.</description>
		<content:encoded><![CDATA[<p>Happy? The month of kernel bugs has delivered a broadcom chip flaw from Ellch.</p>
<p><a href="http://www.eweek.com/article2/0,1895,2056023,00.asp" rel="nofollow">http://www.eweek.com/article2/0,1895,2056023,00.asp</a></p>
<p>Besides paying to defend yourself, if your employer has a lucrative contract with Apple or Intel, and they threaten to kill the contract, that is a threatening action as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: geoffrey</title>
		<link>http://www.macalope.com/2006/11/07/huh-huh-i-said-phuc/comment-page-1/#comment-1254</link>
		<dc:creator>geoffrey</dc:creator>
		<pubDate>Sun, 12 Nov 2006 21:01:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=95#comment-1254</guid>
		<description>Ned, even if you win a lawsuit, it costs money to defend yourself. ;)</description>
		<content:encoded><![CDATA[<p>Ned, even if you win a lawsuit, it costs money to defend yourself. ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ned Harwick</title>
		<link>http://www.macalope.com/2006/11/07/huh-huh-i-said-phuc/comment-page-1/#comment-1252</link>
		<dc:creator>Ned Harwick</dc:creator>
		<pubDate>Sun, 12 Nov 2006 18:38:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=95#comment-1252</guid>
		<description>What is with this vogue of citing technopunditbabble to sidestep simple comments? “Grab a copy of the Metasploit 3 framework and look through the wifi payloads,” or, dare I mention, “Code execution at ring-0.” Sigh... I’m too dumb to understand, so I better got buy a nice, safe Dellpaqway PC. Oh, btw, Geophrey: you can’t suffer “legal action” for disclosure unless (a) you signed a NDA, or (2) you are lying. (seriously, there just aren’t any Apple-logo’d Black Helicopters...)</description>
		<content:encoded><![CDATA[<p>What is with this vogue of citing technopunditbabble to sidestep simple comments? “Grab a copy of the Metasploit 3 framework and look through the wifi payloads,” or, dare I mention, “Code execution at ring-0.” Sigh&#8230; I’m too dumb to understand, so I better got buy a nice, safe Dellpaqway PC. Oh, btw, Geophrey: you can’t suffer “legal action” for disclosure unless (a) you signed a NDA, or (2) you are lying. (seriously, there just aren’t any Apple-logo’d Black Helicopters&#8230;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: geoffrey</title>
		<link>http://www.macalope.com/2006/11/07/huh-huh-i-said-phuc/comment-page-1/#comment-1251</link>
		<dc:creator>geoffrey</dc:creator>
		<pubDate>Sun, 12 Nov 2006 16:22:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=95#comment-1251</guid>
		<description>From what I understand,Maynor and Ellch have been told they will encounter legal action from Apple if they disclose more than they have already. If you do, as a respected voice in the Mac community, wish to verify the problem for yourself, come to the next AHA gathering. I'm sure HD will be happy to run a demo. Some of the specifics of the exploit are still in a sort of legal purgatory, so everyone seems uncomfortable discussing them. See what happens when companies get involved? This is a great argument for Open Source systems. The BSDs and Linux distros would just fix the problem and move on, not threaten researchers in hopes of delaying an embarrassing public disclosure.</description>
		<content:encoded><![CDATA[<p>From what I understand,Maynor and Ellch have been told they will encounter legal action from Apple if they disclose more than they have already. If you do, as a respected voice in the Mac community, wish to verify the problem for yourself, come to the next AHA gathering. I&#8217;m sure HD will be happy to run a demo. Some of the specifics of the exploit are still in a sort of legal purgatory, so everyone seems uncomfortable discussing them. See what happens when companies get involved? This is a great argument for Open Source systems. The BSDs and Linux distros would just fix the problem and move on, not threaten researchers in hopes of delaying an embarrassing public disclosure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Macalope</title>
		<link>http://www.macalope.com/2006/11/07/huh-huh-i-said-phuc/comment-page-1/#comment-1250</link>
		<dc:creator>Macalope</dc:creator>
		<pubDate>Sun, 12 Nov 2006 15:36:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=95#comment-1250</guid>
		<description>If you read the post, the Macalope doesn't have a problem believing the Metasploit exploit.  He released it, so those more knowledgeable than the Macalope can verify his claim (exactly what Maynor and Ellch didn't do).  But HD said it was unrelated to Maynor's exploit.

As for finding closure, it wasn't the Macalope who rekindled this by putting a dirty-sounding word in the file name.</description>
		<content:encoded><![CDATA[<p>If you read the post, the Macalope doesn&#8217;t have a problem believing the Metasploit exploit.  He released it, so those more knowledgeable than the Macalope can verify his claim (exactly what Maynor and Ellch didn&#8217;t do).  But HD said it was unrelated to Maynor&#8217;s exploit.</p>
<p>As for finding closure, it wasn&#8217;t the Macalope who rekindled this by putting a dirty-sounding word in the file name.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: geoffrey</title>
		<link>http://www.macalope.com/2006/11/07/huh-huh-i-said-phuc/comment-page-1/#comment-1246</link>
		<dc:creator>geoffrey</dc:creator>
		<pubDate>Sun, 12 Nov 2006 06:16:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=95#comment-1246</guid>
		<description>That's correct. *You* don't know me. So, my word isn't worth much to you. Providing my "bona fides" to you is worthless. Grab a copy of the Metasploit 3 framework and look through the wifi payloads. Or, if you're willing to travel to Austin, grab a flight down here for the 20th. Anyone is welcome to attend the AHA gatherings, and you can speak to HD personally about your problems with him. All the info you need to know about the AHA meeting for this month can be found here: http://wiki.austinhackers.org/2006-11-20-0x0003 Hope you find yourself some closure.</description>
		<content:encoded><![CDATA[<p>That&#8217;s correct. *You* don&#8217;t know me. So, my word isn&#8217;t worth much to you. Providing my &#8220;bona fides&#8221; to you is worthless. Grab a copy of the Metasploit 3 framework and look through the wifi payloads. Or, if you&#8217;re willing to travel to Austin, grab a flight down here for the 20th. Anyone is welcome to attend the AHA gatherings, and you can speak to HD personally about your problems with him. All the info you need to know about the AHA meeting for this month can be found here: <a href="http://wiki.austinhackers.org/2006-11-20-0x0003" rel="nofollow">http://wiki.austinhackers.org/2006-11-20-0&#215;0003</a> Hope you find yourself some closure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Macalope</title>
		<link>http://www.macalope.com/2006/11/07/huh-huh-i-said-phuc/comment-page-1/#comment-1245</link>
		<dc:creator>Macalope</dc:creator>
		<pubDate>Sun, 12 Nov 2006 04:50:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=95#comment-1245</guid>
		<description>Well, that's great for &lt;i&gt;you&lt;/i&gt;, but we don't know you.

There are so many people these guys could have shown the exploit to - Glenn Fleishman, Jim Thompson, John Gruber, &lt;i&gt;Sam Leffler&lt;/i&gt; for chrissake - but who did they show it to?

Brian Krebs, HD Moore, you - whoever you are - and George fricking Ou (by appearances anyway).</description>
		<content:encoded><![CDATA[<p>Well, that&#8217;s great for <i>you</i>, but we don&#8217;t know you.</p>
<p>There are so many people these guys could have shown the exploit to - Glenn Fleishman, Jim Thompson, John Gruber, <i>Sam Leffler</i> for chrissake - but who did they show it to?</p>
<p>Brian Krebs, HD Moore, you - whoever you are - and George fricking Ou (by appearances anyway).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: geoffrey</title>
		<link>http://www.macalope.com/2006/11/07/huh-huh-i-said-phuc/comment-page-1/#comment-1244</link>
		<dc:creator>geoffrey</dc:creator>
		<pubDate>Sun, 12 Nov 2006 04:01:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=95#comment-1244</guid>
		<description>Actually, HD's giggly manner about phonetic curses aside, I can confirm that the exploits he discusses (his and Johnny Cache's) are, indeed, real. You don't have to believe him, but HD is an extremely intelligent guy. He gets more done (pun intended) in an hour of coding than most of us do in a week. Trust him, or not, it's up to you. I, on the other hand, have witnessed, firsthand, the Apple wifi exploits.</description>
		<content:encoded><![CDATA[<p>Actually, HD&#8217;s giggly manner about phonetic curses aside, I can confirm that the exploits he discusses (his and Johnny Cache&#8217;s) are, indeed, real. You don&#8217;t have to believe him, but HD is an extremely intelligent guy. He gets more done (pun intended) in an hour of coding than most of us do in a week. Trust him, or not, it&#8217;s up to you. I, on the other hand, have witnessed, firsthand, the Apple wifi exploits.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan Russell</title>
		<link>http://www.macalope.com/2006/11/07/huh-huh-i-said-phuc/comment-page-1/#comment-1200</link>
		<dc:creator>Ryan Russell</dc:creator>
		<pubDate>Fri, 10 Nov 2006 04:01:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=95#comment-1200</guid>
		<description>"Put up or shut up!  Put up or shut up!

What?

Ok, fine then.  quit gloating.

asshole."</description>
		<content:encoded><![CDATA[<p>&#8220;Put up or shut up!  Put up or shut up!</p>
<p>What?</p>
<p>Ok, fine then.  quit gloating.</p>
<p>asshole.&#8221;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
