<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Good thing he didn&#039;t double-dog dare</title>
	<atom:link href="http://www.macalope.com/2007/02/12/good-thing-he-didnt-double-dog-dare/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.macalope.com/2007/02/12/good-thing-he-didnt-double-dog-dare/</link>
	<description>Full of sound and furry</description>
	<lastBuildDate>Mon, 19 Dec 2011 18:20:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Cam</title>
		<link>http://www.macalope.com/2007/02/12/good-thing-he-didnt-double-dog-dare/#comment-1529</link>
		<dc:creator>Cam</dc:creator>
		<pubDate>Wed, 14 Feb 2007 06:47:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=172#comment-1529</guid>
		<description>@HUXLEY--

From that article it looks like all some hacker has to do is program an installer for his attack and trick someone into installing it.  :)</description>
		<content:encoded><![CDATA[<p>@HUXLEY&#8211;</p>
<p>From that article it looks like all some hacker has to do is program an installer for his attack and trick someone into installing it.  <img src='http://www.macalope.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dogfriend</title>
		<link>http://www.macalope.com/2007/02/12/good-thing-he-didnt-double-dog-dare/#comment-1528</link>
		<dc:creator>dogfriend</dc:creator>
		<pubDate>Tue, 13 Feb 2007 20:01:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=172#comment-1528</guid>
		<description>&quot;This won’t happen to Vista&quot;

I have seen some people arguing this, the basis of their argument being UAC and Random Memory Management to make buffer overflow attacks more difficult or impossible.

However, it seems to me that the sheer size and complexity of Windows is now working against it. They may have patched some of the previous holes, but that does not mean that new holes won&#039;t be found.

Let&#039;s discuss this a year from now.</description>
		<content:encoded><![CDATA[<p>&#8220;This won’t happen to Vista&#8221;</p>
<p>I have seen some people arguing this, the basis of their argument being UAC and Random Memory Management to make buffer overflow attacks more difficult or impossible.</p>
<p>However, it seems to me that the sheer size and complexity of Windows is now working against it. They may have patched some of the previous holes, but that does not mean that new holes won&#8217;t be found.</p>
<p>Let&#8217;s discuss this a year from now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: huxley</title>
		<link>http://www.macalope.com/2007/02/12/good-thing-he-didnt-double-dog-dare/#comment-1527</link>
		<dc:creator>huxley</dc:creator>
		<pubDate>Tue, 13 Feb 2007 18:52:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=172#comment-1527</guid>
		<description>This looks interesting:

Hacker, Microsoft duke it out over Vista design flaw (ZDnet Zero Day blog)
  http://blogs.zdnet.com/security/?p=29</description>
		<content:encoded><![CDATA[<p>This looks interesting:</p>
<p>Hacker, Microsoft duke it out over Vista design flaw (ZDnet Zero Day blog)<br />
  <a href="http://blogs.zdnet.com/security/?p=29" rel="nofollow">http://blogs.zdnet.com/security/?p=29</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: one.miguel</title>
		<link>http://www.macalope.com/2007/02/12/good-thing-he-didnt-double-dog-dare/#comment-1526</link>
		<dc:creator>one.miguel</dc:creator>
		<pubDate>Tue, 13 Feb 2007 18:51:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=172#comment-1526</guid>
		<description>812 Windows vulnerabilities, huh?  Including these?

Apple Darwin Streaming Server Denial of Service
Apple iTunes Arbitrary Code Execution
Apple QuickTime for Windows Denial of Service Vulnerability
Apple &#039;quicktime.qts&#039; Error in Parsing &#039;qtif&#039; Images Remote Denial of Service

US-CERT&#039;s list is bogus, since it includes many non-Microsoft products that simply RUN on Windows.  If you apply this logic, then you have to accept that every MOAB finding was an OS X vulnerability.</description>
		<content:encoded><![CDATA[<p>812 Windows vulnerabilities, huh?  Including these?</p>
<p>Apple Darwin Streaming Server Denial of Service<br />
Apple iTunes Arbitrary Code Execution<br />
Apple QuickTime for Windows Denial of Service Vulnerability<br />
Apple &#8216;quicktime.qts&#8217; Error in Parsing &#8216;qtif&#8217; Images Remote Denial of Service</p>
<p>US-CERT&#8217;s list is bogus, since it includes many non-Microsoft products that simply RUN on Windows.  If you apply this logic, then you have to accept that every MOAB finding was an OS X vulnerability.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bergamot</title>
		<link>http://www.macalope.com/2007/02/12/good-thing-he-didnt-double-dog-dare/#comment-1525</link>
		<dc:creator>Bergamot</dc:creator>
		<pubDate>Tue, 13 Feb 2007 18:14:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=172#comment-1525</guid>
		<description>Vista is certainly more secure than XP, but the important question is whether it is secure *enough*.

Personally, I find XP to be reasonably secure when using Firefox, so I would imagine that Vista + Sandboxed IE7 is probably good enough for most people. Other stuff, like moving some drivers to user-space, and not running as an admin in the default install, probably help too. There will be vulnerabilities, and there will be exploits, but hopefully they&#039;ll be minor and easily-patched. I am an eternal optimist.

That said, saying stuff like “Vista users now have a system that is ’secure by design’ to a greater degree than Mac OSX.” is idiotic.</description>
		<content:encoded><![CDATA[<p>Vista is certainly more secure than XP, but the important question is whether it is secure *enough*.</p>
<p>Personally, I find XP to be reasonably secure when using Firefox, so I would imagine that Vista + Sandboxed IE7 is probably good enough for most people. Other stuff, like moving some drivers to user-space, and not running as an admin in the default install, probably help too. There will be vulnerabilities, and there will be exploits, but hopefully they&#8217;ll be minor and easily-patched. I am an eternal optimist.</p>
<p>That said, saying stuff like “Vista users now have a system that is ’secure by design’ to a greater degree than Mac OSX.” is idiotic.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Emily</title>
		<link>http://www.macalope.com/2007/02/12/good-thing-he-didnt-double-dog-dare/#comment-1524</link>
		<dc:creator>Emily</dc:creator>
		<pubDate>Tue, 13 Feb 2007 17:40:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=172#comment-1524</guid>
		<description>&quot;Vista users now have a system that is ’secure by design’ to a greater degree than Mac OSX.&quot;

I am pretty clueless when it comes to Vista. Can you explain that further? Provide citations?</description>
		<content:encoded><![CDATA[<p>&#8220;Vista users now have a system that is ’secure by design’ to a greater degree than Mac OSX.&#8221;</p>
<p>I am pretty clueless when it comes to Vista. Can you explain that further? Provide citations?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JD</title>
		<link>http://www.macalope.com/2007/02/12/good-thing-he-didnt-double-dog-dare/#comment-1523</link>
		<dc:creator>JD</dc:creator>
		<pubDate>Tue, 13 Feb 2007 06:11:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=172#comment-1523</guid>
		<description>Daniel &quot;This won’t happen to Vista.&quot;

Didn&#039;t they say that about XP, comparing it to the security of earlier Windows versions?

&quot;Secure by design&quot; is only as good as: 1) the design, 2) the implementation, 3) the way people use it.  If users end up turning off the security features, then it doesn&#039;t matter one bit that it&#039;s secure by design.  The human element is the hardest to control for.</description>
		<content:encoded><![CDATA[<p>Daniel &#8220;This won’t happen to Vista.&#8221;</p>
<p>Didn&#8217;t they say that about XP, comparing it to the security of earlier Windows versions?</p>
<p>&#8220;Secure by design&#8221; is only as good as: 1) the design, 2) the implementation, 3) the way people use it.  If users end up turning off the security features, then it doesn&#8217;t matter one bit that it&#8217;s secure by design.  The human element is the hardest to control for.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: blattapus</title>
		<link>http://www.macalope.com/2007/02/12/good-thing-he-didnt-double-dog-dare/#comment-1522</link>
		<dc:creator>blattapus</dc:creator>
		<pubDate>Tue, 13 Feb 2007 01:50:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=172#comment-1522</guid>
		<description>I think that the biggest publicly announced security hack was something that was done first on a PC then done as a proof of concept on a Mac using everything third party.

Microsoft&#039;s software is the biggest ssecurity threat on an Apple computer, either in the form of Office for Mac or the potential disaster of installing the dreaded XP or Vista on an Intel Mac.</description>
		<content:encoded><![CDATA[<p>I think that the biggest publicly announced security hack was something that was done first on a PC then done as a proof of concept on a Mac using everything third party.</p>
<p>Microsoft&#8217;s software is the biggest ssecurity threat on an Apple computer, either in the form of Office for Mac or the potential disaster of installing the dreaded XP or Vista on an Intel Mac.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: huxley</title>
		<link>http://www.macalope.com/2007/02/12/good-thing-he-didnt-double-dog-dare/#comment-1521</link>
		<dc:creator>huxley</dc:creator>
		<pubDate>Tue, 13 Feb 2007 01:38:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=172#comment-1521</guid>
		<description>No, not the other one. It actually was the one and only one.</description>
		<content:encoded><![CDATA[<p>No, not the other one. It actually was the one and only one.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: iheartbeer</title>
		<link>http://www.macalope.com/2007/02/12/good-thing-he-didnt-double-dog-dare/#comment-1520</link>
		<dc:creator>iheartbeer</dc:creator>
		<pubDate>Mon, 12 Feb 2007 21:30:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.macalope.com/?p=172#comment-1520</guid>
		<description>No, no, the other one.</description>
		<content:encoded><![CDATA[<p>No, no, the other one.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

