<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Matasano Chargen - Latest Comments in Alastair Houghton Debunks LMH MOKB Finding</title><link>http://matasanochargen.disqus.com/</link><description></description><atom:link href="https://matasanochargen.disqus.com/alastair_houghton_debunks_lmh_mokb_finding/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Thu, 07 Dec 2006 16:24:17 -0000</lastBuildDate><item><title>Re: Alastair Houghton Debunks LMH MOKB Finding</title><link>http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/#comment-2321194</link><description>&lt;p&gt;Well, from a system administration perspective, disk image containers have a lot of advantages for different usage scenarios.&lt;/p&gt;&lt;p&gt;That’s not to say that there aren’t risks associated with them—because it looks like there’s evidence that there is or will be—but the risk sounds like it’s just simply much worse when they are traded across the ’net. They're now being used for general purposes rather than being confined to local computers for specific purposes.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Histrionic</dc:creator><pubDate>Thu, 07 Dec 2006 16:24:17 -0000</pubDate></item><item><title>Re: Alastair Houghton Debunks LMH MOKB Finding</title><link>http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/#comment-2321193</link><description>&lt;p&gt;I don't know enough about them, but I know enough to say this: the right way to do this is to use a fixed format like ISO9660, and the absolute wrong way to do is is to make disk images a metaformat with client-selectable filesystems.&lt;/p&gt;&lt;p&gt;Downloadable disk images and actual disks have radically different requirements; actual disks have to do all sorts of work to handle constant modification and keep coherent state. This is why I think disk images are dumb idea to begin with.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Thu, 07 Dec 2006 15:29:41 -0000</pubDate></item><item><title>Re: Alastair Houghton Debunks LMH MOKB Finding</title><link>http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/#comment-2321192</link><description>&lt;p&gt;Is it likely that this will be a problem for WIM disk images on Windows Vista, as well?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Histrionic</dc:creator><pubDate>Thu, 07 Dec 2006 12:46:38 -0000</pubDate></item><item><title>Re: Alastair Houghton Debunks LMH MOKB Finding</title><link>http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/#comment-2321190</link><description>&lt;p&gt;Alastair's post is a good commentary on the problem of vulnerability information management, and the amount of trust people put into refined information sources.  If it took 3 days to verify an issue, it shows how resource-intensive (read: impossible) it would be for an information source to personally verify every single claim out there.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Steve Christey</dc:creator><pubDate>Wed, 06 Dec 2006 18:41:48 -0000</pubDate></item><item><title>Re: Alastair Houghton Debunks LMH MOKB Finding</title><link>http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/#comment-2321189</link><description>&lt;p&gt;Here's the link to Alastair's post:&lt;/p&gt;&lt;p&gt;&lt;a href="http://alastairs-place.net/2006/11/dmg-vulnerability/" rel="nofollow noopener" target="_blank" title="http://alastairs-place.net/2006/11/dmg-vulnerability/"&gt;http://alastairs-place.net/...&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">anonymous</dc:creator><pubDate>Thu, 30 Nov 2006 13:23:12 -0000</pubDate></item></channel></rss>