<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in Alastair Houghton Debunks LMH MOKB Finding</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Thu, 07 Dec 2006 16:24:17 -0000</lastBuildDate><item><title>Re: Alastair Houghton Debunks LMH MOKB Finding</title><link>http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/#comment-2321194</link><description>Well, from a system administration perspective, disk image containers have a lot of advantages for different usage scenarios.&lt;br&gt;&lt;br&gt;That’s not to say that there aren’t risks associated with them—because it looks like there’s evidence that there is or will be—but the risk sounds like it’s just simply much worse when they are traded across the ’net. They're now being used for general purposes rather than being confined to local computers for specific purposes.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Histrionic</dc:creator><pubDate>Thu, 07 Dec 2006 16:24:17 -0000</pubDate></item><item><title>Re: Alastair Houghton Debunks LMH MOKB Finding</title><link>http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/#comment-2321193</link><description>I don't know enough about them, but I know enough to say this: the right way to do this is to use a fixed format like ISO9660, and the absolute wrong way to do is is to make disk images a metaformat with client-selectable filesystems.&lt;br&gt;&lt;br&gt;Downloadable disk images and actual disks have radically different requirements; actual disks have to do all sorts of work to handle constant modification and keep coherent state. This is why I think disk images are dumb idea to begin with.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Thu, 07 Dec 2006 15:29:41 -0000</pubDate></item><item><title>Re: Alastair Houghton Debunks LMH MOKB Finding</title><link>http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/#comment-2321192</link><description>Is it likely that this will be a problem for WIM disk images on Windows Vista, as well?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Histrionic</dc:creator><pubDate>Thu, 07 Dec 2006 12:46:38 -0000</pubDate></item><item><title>Re: Alastair Houghton Debunks LMH MOKB Finding</title><link>http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/#comment-2321191</link><description>It's worth saying that (I think) it would take me less time now to do the same thing again, and I'd expect someone with significant experience inside the Mac OS X kernel (especially IOKit) wouldn't take so long either.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">alastair</dc:creator><pubDate>Thu, 07 Dec 2006 09:38:36 -0000</pubDate></item><item><title>Re: Alastair Houghton Debunks LMH MOKB Finding</title><link>http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/#comment-2321190</link><description>Alastair's post is a good commentary on the problem of vulnerability information management, and the amount of trust people put into refined information sources.  If it took 3 days to verify an issue, it shows how resource-intensive (read: impossible) it would be for an information source to personally verify every single claim out there.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Steve Christey</dc:creator><pubDate>Wed, 06 Dec 2006 18:41:48 -0000</pubDate></item><item><title>Re: Alastair Houghton Debunks LMH MOKB Finding</title><link>http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/#comment-2321189</link><description>Here's the link to Alastair's post:&lt;br&gt;&lt;br&gt;&lt;a href="http://alastairs-place.net/2006/11/dmg-vulnerability/" rel="nofollow"&gt;http://alastairs-place.net/2006/11/dmg-vulnerab...&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">anonymous</dc:creator><pubDate>Thu, 30 Nov 2006 13:23:12 -0000</pubDate></item><item><title>Re: Alastair Houghton Debunks LMH MOKB Finding</title><link>http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/#comment-2321188</link><description>Apology accepted, thank-you. (It wasn't really necessary; I'm not easily offended.)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">alastair</dc:creator><pubDate>Thu, 30 Nov 2006 13:14:04 -0000</pubDate></item></channel></rss>