<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in How To Hide^H^H^Handle Security Problems in Your Products</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Mon, 30 Jun 2008 19:12:48 -0000</lastBuildDate><item><title>Re: How To Hide^H^H^Handle Security Problems in Your Products</title><link>http://www.matasano.com/log/1078/how-to-hidehhhandle-security-problems-in-your-products/#comment-2324172</link><description>I heard --- from an absolutely huge vendor, of mission-critical IT infrastructure --- that buffer overflows weren't exploitable *because* they weren't Windows.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Mon, 30 Jun 2008 19:12:48 -0000</pubDate></item><item><title>Re: How To Hide^H^H^Handle Security Problems in Your Products</title><link>http://www.matasano.com/log/1078/how-to-hidehhhandle-security-problems-in-your-products/#comment-2324173</link><description>I'm not surprised to hear that in 1997.  But even recently, you still see people arguing about exploitable overflows (Check Smail's last heap overflow) and try to utilize lawyers.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave G.</dc:creator><pubDate>Mon, 30 Jun 2008 16:17:07 -0000</pubDate></item><item><title>Re: How To Hide^H^H^Handle Security Problems in Your Products</title><link>http://www.matasano.com/log/1078/how-to-hidehhhandle-security-problems-in-your-products/#comment-2324174</link><description>I once (around 1997) had a vendor tell me that buffer overruns in Windows were not exploitable. Really, not kidding. Only time I ever went public without a fix. It's in BUGTRAQ archives. I then got a nasty-gram from their lawyer in overnight mail.&lt;br&gt;&lt;br&gt;In comparison, Microsoft ('96 through '99) fixed everything I ever reported - about 50 or so issues - without arm-twisting (there was some debate, but that's OK). That played a major part in my decision to work at MS. (YMMV)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David LeBlanc</dc:creator><pubDate>Mon, 30 Jun 2008 15:40:35 -0000</pubDate></item><item><title>Re: How To Hide^H^H^Handle Security Problems in Your Products</title><link>http://www.matasano.com/log/1078/how-to-hidehhhandle-security-problems-in-your-products/#comment-2324171</link><description>Great essay.  Thanks for reposting.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Chris</dc:creator><pubDate>Mon, 30 Jun 2008 13:49:42 -0000</pubDate></item><item><title>Re: How To Hide^H^H^Handle Security Problems in Your Products</title><link>http://www.matasano.com/log/1078/how-to-hidehhhandle-security-problems-in-your-products/#comment-2324177</link><description>In 2002 I printed this off from &lt;a href="http://sockpuppet.org" rel="nofollow"&gt;sockpuppet.org&lt;/a&gt; and hung it in my cube.  It was funny then.  Today it feels tragically obvious.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">PaulM</dc:creator><pubDate>Fri, 27 Jun 2008 11:21:36 -0000</pubDate></item><item><title>Re: How To Hide^H^H^Handle Security Problems in Your Products</title><link>http://www.matasano.com/log/1078/how-to-hidehhhandle-security-problems-in-your-products/#comment-2324178</link><description>Ten rules which my employer loves</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">anonymous</dc:creator><pubDate>Fri, 27 Jun 2008 08:44:42 -0000</pubDate></item><item><title>Re: How To Hide^H^H^Handle Security Problems in Your Products</title><link>http://www.matasano.com/log/1078/how-to-hidehhhandle-security-problems-in-your-products/#comment-2324176</link><description>Must be true. I seem to hear about one of these a week in my weekly security podcast subscriptions.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Stephen</dc:creator><pubDate>Thu, 26 Jun 2008 19:29:49 -0000</pubDate></item><item><title>Re: How To Hide^H^H^Handle Security Problems in Your Products</title><link>http://www.matasano.com/log/1078/how-to-hidehhhandle-security-problems-in-your-products/#comment-2324175</link><description>Mike Lynn's rules are pretty awesome.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Thu, 26 Jun 2008 15:16:04 -0000</pubDate></item><item><title>Re: How To Hide^H^H^Handle Security Problems in Your Products</title><link>http://www.matasano.com/log/1078/how-to-hidehhhandle-security-problems-in-your-products/#comment-2324180</link><description>This only thing that is *almost* as good as "How to Hide^H^H^Handle Security Problems in Your Products" is Michael Lynn's "programming rules 2.2":&lt;br&gt;&lt;br&gt;&lt;a href="http://www.memestreams.net/users/abaddon/blogid782712" rel="nofollow"&gt;http://www.memestreams.net/users/abaddon/blogid...&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Andre Gironda</dc:creator><pubDate>Thu, 26 Jun 2008 15:12:41 -0000</pubDate></item><item><title>Re: How To Hide^H^H^Handle Security Problems in Your Products</title><link>http://www.matasano.com/log/1078/how-to-hidehhhandle-security-problems-in-your-products/#comment-2324179</link><description>Tried and true.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">tb</dc:creator><pubDate>Thu, 26 Jun 2008 14:42:51 -0000</pubDate></item></channel></rss>