<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: IBM sees influx in zero-day exploits</title>
	<atom:link href="http://hackaday.com/2008/08/26/ibm-sees-influx-in-zero-day-exploits/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com/2008/08/26/ibm-sees-influx-in-zero-day-exploits/</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Mon, 23 Nov 2009 07:33:39 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: srilyk</title>
		<link>http://hackaday.com/2008/08/26/ibm-sees-influx-in-zero-day-exploits/comment-page-1/#comment-41270</link>
		<dc:creator>srilyk</dc:creator>
		<pubDate>Fri, 05 Sep 2008 12:59:58 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/26/ibm-sees-influx-in-zero-day-exploits/#comment-41270</guid>
		<description>Kris Lamb is apparently an idiot. Why would any sane person suggest

that exploits *not* be published? Sure there may not be a central

authority (that would be a good thing), but not publishing exploits

would be akin to saying &quot;You know what? Exploit all you want, nobody

will realize what you&#039;re doing until it&#039;s too late.&quot;



In addition, publishing exploits forces consumers and publishers alike

to either wake up or get screwed. And if you&#039;re too stupid to secure

your browser, do we *really* want you to have any more money/power than

you already do?</description>
		<content:encoded><![CDATA[<p>Kris Lamb is apparently an idiot. Why would any sane person suggest</p>
<p>that exploits *not* be published? Sure there may not be a central</p>
<p>authority (that would be a good thing), but not publishing exploits</p>
<p>would be akin to saying &#8220;You know what? Exploit all you want, nobody</p>
<p>will realize what you&#8217;re doing until it&#8217;s too late.&#8221;</p>
<p>In addition, publishing exploits forces consumers and publishers alike</p>
<p>to either wake up or get screwed. And if you&#8217;re too stupid to secure</p>
<p>your browser, do we *really* want you to have any more money/power than</p>
<p>you already do?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Heliosphan</title>
		<link>http://hackaday.com/2008/08/26/ibm-sees-influx-in-zero-day-exploits/comment-page-1/#comment-41269</link>
		<dc:creator>Heliosphan</dc:creator>
		<pubDate>Wed, 27 Aug 2008 22:58:51 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/26/ibm-sees-influx-in-zero-day-exploits/#comment-41269</guid>
		<description>Agreed with previous comments - &lt;br&gt;Zero Day was referred to by a certain Mark Russinovich of SysInternals, now Microsoft (who revealed the Sony Rootkit fiasco) that actually means any vulnerabilities not even discovered/reported by official legitimate security firms.&lt;br&gt;If a single immoral hacker finds a vulnerability in a system and develops an exploit, making money from it or not, and the world knows nothing of it, its a Zero Day exploit.&lt;br&gt;Wheres this 24 hour from disclosure crap come from!?&lt;br&gt;</description>
		<content:encoded><![CDATA[<p>Agreed with previous comments &#8211; <br />Zero Day was referred to by a certain Mark Russinovich of SysInternals, now Microsoft (who revealed the Sony Rootkit fiasco) that actually means any vulnerabilities not even discovered/reported by official legitimate security firms.<br />If a single immoral hacker finds a vulnerability in a system and develops an exploit, making money from it or not, and the world knows nothing of it, its a Zero Day exploit.<br />Wheres this 24 hour from disclosure crap come from!?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric</title>
		<link>http://hackaday.com/2008/08/26/ibm-sees-influx-in-zero-day-exploits/comment-page-1/#comment-41268</link>
		<dc:creator>Eric</dc:creator>
		<pubDate>Wed, 27 Aug 2008 06:08:30 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/26/ibm-sees-influx-in-zero-day-exploits/#comment-41268</guid>
		<description>Bit of a &quot;duh&quot; in the Windows world, if I&#039;m reading this correctly. The whole problem with Microsoft going on a set schedule for patches (Patch Tuesday, as it is so called) is that malicious individuals realize the best time to release is just AFTER patch Tuesday, eliminating the possibility of even a last-minute patch. And Microsoft&#039;s stand is that they will not release patches outside of that day unless it is very severe. *shrug*</description>
		<content:encoded><![CDATA[<p>Bit of a &#8220;duh&#8221; in the Windows world, if I&#8217;m reading this correctly. The whole problem with Microsoft going on a set schedule for patches (Patch Tuesday, as it is so called) is that malicious individuals realize the best time to release is just AFTER patch Tuesday, eliminating the possibility of even a last-minute patch. And Microsoft&#8217;s stand is that they will not release patches outside of that day unless it is very severe. *shrug*</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: miked</title>
		<link>http://hackaday.com/2008/08/26/ibm-sees-influx-in-zero-day-exploits/comment-page-1/#comment-41267</link>
		<dc:creator>miked</dc:creator>
		<pubDate>Wed, 27 Aug 2008 05:59:20 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/26/ibm-sees-influx-in-zero-day-exploits/#comment-41267</guid>
		<description>&gt;Anyone know of a blog that is &lt;br&gt;&gt;like what hack a day used to be? &lt;br&gt;&gt;Hardware hacks without this &lt;br&gt;&gt;bullshit wanna be slashdot drivel?&lt;br&gt;&lt;br&gt;I know one ;)</description>
		<content:encoded><![CDATA[<p>>Anyone know of a blog that is <br />>like what hack a day used to be? <br />>Hardware hacks without this <br />>bullshit wanna be slashdot drivel?</p>
<p>I know one ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rivetgeek</title>
		<link>http://hackaday.com/2008/08/26/ibm-sees-influx-in-zero-day-exploits/comment-page-1/#comment-41266</link>
		<dc:creator>rivetgeek</dc:creator>
		<pubDate>Wed, 27 Aug 2008 04:30:51 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/26/ibm-sees-influx-in-zero-day-exploits/#comment-41266</guid>
		<description>Jesus christ. 0-day is not what you think it is.  Anyone know of a blog that is like what hack a day used to be?  Hardware hacks without this bullshit wanna be slashdot drivel?</description>
		<content:encoded><![CDATA[<p>Jesus christ. 0-day is not what you think it is.  Anyone know of a blog that is like what hack a day used to be?  Hardware hacks without this bullshit wanna be slashdot drivel?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: holycrap</title>
		<link>http://hackaday.com/2008/08/26/ibm-sees-influx-in-zero-day-exploits/comment-page-1/#comment-41265</link>
		<dc:creator>holycrap</dc:creator>
		<pubDate>Wed, 27 Aug 2008 04:16:11 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/26/ibm-sees-influx-in-zero-day-exploits/#comment-41265</guid>
		<description>You link a Wikipedia article that you didn&#039;t even read? That&#039;s not what 0day is, even Wikipedia knows that: &quot;A zero-day (or zero-hour) attack or threat is a computer threat that tries to exploit unknown, undisclosed or unpatched computer application vulnerabilities.&quot;&lt;br&gt;&lt;br&gt;UNKNOWN. UNDISCLOSED. UNPATCHED.&lt;br&gt;&lt;br&gt;Keep making up definitions!</description>
		<content:encoded><![CDATA[<p>You link a Wikipedia article that you didn&#8217;t even read? That&#8217;s not what 0day is, even Wikipedia knows that: &#8220;A zero-day (or zero-hour) attack or threat is a computer threat that tries to exploit unknown, undisclosed or unpatched computer application vulnerabilities.&#8221;</p>
<p>UNKNOWN. UNDISCLOSED. UNPATCHED.</p>
<p>Keep making up definitions!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: G</title>
		<link>http://hackaday.com/2008/08/26/ibm-sees-influx-in-zero-day-exploits/comment-page-1/#comment-41264</link>
		<dc:creator>G</dc:creator>
		<pubDate>Wed, 27 Aug 2008 01:47:21 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/26/ibm-sees-influx-in-zero-day-exploits/#comment-41264</guid>
		<description>I thought it&#039;d be common practice for the employees of security companies to be members of exploit rls sites? As they say, you can be whoever you want on the internet.</description>
		<content:encoded><![CDATA[<p>I thought it&#8217;d be common practice for the employees of security companies to be members of exploit rls sites? As they say, you can be whoever you want on the internet.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
