<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The French and German governments agree&#8230; And they are both wrong.</title>
	<atom:link href="http://www.coretraceblogs.com/2010-01/the-french-and-german-governments-agree-and-they-are-both-wrong/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.coretraceblogs.com/2010-01/the-french-and-german-governments-agree-and-they-are-both-wrong/</link>
	<description>The Application Whitelisting and Security Weblog</description>
	<lastBuildDate>Thu, 29 Jul 2010 14:53:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Doug Finley @ Naknan</title>
		<link>http://www.coretraceblogs.com/2010-01/the-french-and-german-governments-agree-and-they-are-both-wrong/#comment-767</link>
		<dc:creator>Doug Finley @ Naknan</dc:creator>
		<pubDate>Fri, 29 Jan 2010 19:21:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1089#comment-767</guid>
		<description>Maybe the Europeans should take it one step further. If problems with IE is good cause for banning IE, then we should ban technicians and SysAdmins because they sometimes misconfigure systems, making them vulnerable. And what about users who, no matter how much we train them, still click on sucker links which download malware. If we ban software that has vulnerabilities (that&#039;s almost all software), and techs and SysAdmins, and users, we&#039;d probably have a pretty secure environment.</description>
		<content:encoded><![CDATA[<p>Maybe the Europeans should take it one step further. If problems with IE is good cause for banning IE, then we should ban technicians and SysAdmins because they sometimes misconfigure systems, making them vulnerable. And what about users who, no matter how much we train them, still click on sucker links which download malware. If we ban software that has vulnerabilities (that&#8217;s almost all software), and techs and SysAdmins, and users, we&#8217;d probably have a pretty secure environment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Operation Aurora illustrates greater need for effective preventative endpoint security — CoreTrace WhiteSpace</title>
		<link>http://www.coretraceblogs.com/2010-01/the-french-and-german-governments-agree-and-they-are-both-wrong/#comment-762</link>
		<dc:creator>Operation Aurora illustrates greater need for effective preventative endpoint security — CoreTrace WhiteSpace</dc:creator>
		<pubDate>Thu, 28 Jan 2010 16:25:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1089#comment-762</guid>
		<description>[...] detection of weaknesses, patching and signatures. We posted a blog on this topic last week titled: &#8220;The French and German governments agree… And they are both wrong” that has generated a lot of discussion between security [...]</description>
		<content:encoded><![CDATA[<p>[...] detection of weaknesses, patching and signatures. We posted a blog on this topic last week titled: &#8220;The French and German governments agree… And they are both wrong” that has generated a lot of discussion between security [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: himanshu</title>
		<link>http://www.coretraceblogs.com/2010-01/the-french-and-german-governments-agree-and-they-are-both-wrong/#comment-760</link>
		<dc:creator>himanshu</dc:creator>
		<pubDate>Thu, 28 Jan 2010 12:05:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1089#comment-760</guid>
		<description>I am really amazed at people&#039;s way of thinking. If IE is getting attacked they are telling to stop the use of it. Now hackers know that you might using firefox and they will exploit the new browser, then?

And If they believe that by stopping the use of IE they will be safe then they should say such things for PDF Reader also. Stop Adobe PDF Reader and use something else like Foxit etc..</description>
		<content:encoded><![CDATA[<p>I am really amazed at people&#8217;s way of thinking. If IE is getting attacked they are telling to stop the use of it. Now hackers know that you might using firefox and they will exploit the new browser, then?</p>
<p>And If they believe that by stopping the use of IE they will be safe then they should say such things for PDF Reader also. Stop Adobe PDF Reader and use something else like Foxit etc..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Thomason</title>
		<link>http://www.coretraceblogs.com/2010-01/the-french-and-german-governments-agree-and-they-are-both-wrong/#comment-752</link>
		<dc:creator>David Thomason</dc:creator>
		<pubDate>Tue, 26 Jan 2010 16:31:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1089#comment-752</guid>
		<description>While realizing that the referenced articles were referring to the typical home user, my comments regarding APT were not. Having said that, I believe there has to be a shift in the way a typical user thinks about security even their home PC. Antivirus, anti-spam and every other &quot;signature-based&quot; technology has failed and will continue to fail as long as the effort to create malware outpaces it. We didn&#039;t think we needed AV until we viruses became a part of everyday life. Do you really think there won&#039;t be a technology like Application Whitelisting that can change the game and the mindset of the typical user to at least have extreme visibility, particularly when it is as simple as notifying a user when unauthorized code wants to execute? My 64 year-old mother with no technology experience seemed to understand that concept. It&#039;s a change in thinking... but that&#039;s marketing&#039;s job. I hope they can get it done.</description>
		<content:encoded><![CDATA[<p>While realizing that the referenced articles were referring to the typical home user, my comments regarding APT were not. Having said that, I believe there has to be a shift in the way a typical user thinks about security even their home PC. Antivirus, anti-spam and every other &#8220;signature-based&#8221; technology has failed and will continue to fail as long as the effort to create malware outpaces it. We didn&#8217;t think we needed AV until we viruses became a part of everyday life. Do you really think there won&#8217;t be a technology like Application Whitelisting that can change the game and the mindset of the typical user to at least have extreme visibility, particularly when it is as simple as notifying a user when unauthorized code wants to execute? My 64 year-old mother with no technology experience seemed to understand that concept. It&#8217;s a change in thinking&#8230; but that&#8217;s marketing&#8217;s job. I hope they can get it done.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Moorman</title>
		<link>http://www.coretraceblogs.com/2010-01/the-french-and-german-governments-agree-and-they-are-both-wrong/#comment-751</link>
		<dc:creator>Paul Moorman</dc:creator>
		<pubDate>Tue, 26 Jan 2010 14:30:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1089#comment-751</guid>
		<description>So the proposed solution is to get a few billion people on this planet who have no clue what this all means, and simply want to use the Internet, to participate in some manner in an &quot;extreme visibility and intelligence&quot; campaign?  We can&#039;t get them to pick strong passwords.  

The fact of the matter is no platform will ever be perfectly safe.  And it&#039;s a fact that Windows, with its origins in DOS and non-networked PCs, is simply riddled with holes that appear, after 10+ years of trying to fix, to be never-ending.  My belief is that platforms conceived in a shared environment will be secure (e.g. MPLS networks) because they are designed that way from the beginning.  Conversely, platforms conceived in a non-shared environment will rarely achieve a high level of security as they are retrofitted later on.

Recommending to users to begin using a more secure browser is decent idea.  Maybe that changes from time to time.  So what.  If you found a new anti-virus vendor that would reduce your exposure by 95%, would you dismiss it simply because it doesn&#039;t tackle the core problem.  I hope not.

But you&#039;re right that the browser is not the core problem.  Neither is Acrobat or whatever the current vulnerable application.  Windows is.  Since it appears to be impossible to fix, it needs to be replaced.  Unfortunately that&#039;s not as easy as changing a browser.  But it is the answer, whether we like it or not.</description>
		<content:encoded><![CDATA[<p>So the proposed solution is to get a few billion people on this planet who have no clue what this all means, and simply want to use the Internet, to participate in some manner in an &#8220;extreme visibility and intelligence&#8221; campaign?  We can&#8217;t get them to pick strong passwords.  </p>
<p>The fact of the matter is no platform will ever be perfectly safe.  And it&#8217;s a fact that Windows, with its origins in DOS and non-networked PCs, is simply riddled with holes that appear, after 10+ years of trying to fix, to be never-ending.  My belief is that platforms conceived in a shared environment will be secure (e.g. MPLS networks) because they are designed that way from the beginning.  Conversely, platforms conceived in a non-shared environment will rarely achieve a high level of security as they are retrofitted later on.</p>
<p>Recommending to users to begin using a more secure browser is decent idea.  Maybe that changes from time to time.  So what.  If you found a new anti-virus vendor that would reduce your exposure by 95%, would you dismiss it simply because it doesn&#8217;t tackle the core problem.  I hope not.</p>
<p>But you&#8217;re right that the browser is not the core problem.  Neither is Acrobat or whatever the current vulnerable application.  Windows is.  Since it appears to be impossible to fix, it needs to be replaced.  Unfortunately that&#8217;s not as easy as changing a browser.  But it is the answer, whether we like it or not.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
