<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: False sense of security</title>
	<atom:link href="http://akahele.org/2009/09/false-sense-of-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://akahele.org/2009/09/false-sense-of-security/</link>
	<description>Cautious web criticism</description>
	<lastBuildDate>Mon, 14 Jun 2010 09:36:44 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Prashanth</title>
		<link>http://akahele.org/2009/09/false-sense-of-security/comment-page-1/#comment-2117</link>
		<dc:creator>Prashanth</dc:creator>
		<pubDate>Sat, 19 Sep 2009 15:18:52 +0000</pubDate>
		<guid isPermaLink="false">http://akahele.org/?p=1125#comment-2117</guid>
		<description>Give me one bugless software, and I shall give you Web 3.0.</description>
		<content:encoded><![CDATA[<p>Give me one bugless software, and I shall give you Web 3.0.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nihiltres</title>
		<link>http://akahele.org/2009/09/false-sense-of-security/comment-page-1/#comment-2106</link>
		<dc:creator>Nihiltres</dc:creator>
		<pubDate>Wed, 16 Sep 2009 02:29:28 +0000</pubDate>
		<guid isPermaLink="false">http://akahele.org/?p=1125#comment-2106</guid>
		<description>@Gregory Kohs: while &quot;All software has bugs&quot; is logically false, the only reason that that&#039;s the case is because the version of the statement there is so overgeneral. Perhaps a more strictly accurate way of saying it would be &quot;Software which takes significant open-ended input and configuration and has a reasonable degree of complexity is highly likely to have bugs unforseeable by anyone of human-level intelligence, assuming for simplicity that they understand the programming language(s) at hand.&quot; Your Bethlehem program, for example, presumably didn&#039;t require input or configuration—making its programming vastly simpler—imperative programs are extremely less complex than their conditional counterparts.

Of course, that&#039;s beside the point, seeing as the report mentioned doesn&#039;t identify any extant vulnerabilities in MediaWiki. Perhaps Judd Bagley should be more worried about, say, &lt;a href=&quot;http://www.computerworld.com/s/article/9138007/Microsoft_No_TCP_IP_patches_for_you_XP&quot; rel=&quot;nofollow&quot;&gt;widely-used operating systems&lt;/a&gt;. :)</description>
		<content:encoded><![CDATA[<p>@Gregory Kohs: while &#8220;All software has bugs&#8221; is logically false, the only reason that that&#8217;s the case is because the version of the statement there is so overgeneral. Perhaps a more strictly accurate way of saying it would be &#8220;Software which takes significant open-ended input and configuration and has a reasonable degree of complexity is highly likely to have bugs unforseeable by anyone of human-level intelligence, assuming for simplicity that they understand the programming language(s) at hand.&#8221; Your Bethlehem program, for example, presumably didn&#8217;t require input or configuration—making its programming vastly simpler—imperative programs are extremely less complex than their conditional counterparts.</p>
<p>Of course, that&#8217;s beside the point, seeing as the report mentioned doesn&#8217;t identify any extant vulnerabilities in MediaWiki. Perhaps Judd Bagley should be more worried about, say, <a href="http://www.computerworld.com/s/article/9138007/Microsoft_No_TCP_IP_patches_for_you_XP" rel="nofollow">widely-used operating systems</a>. <img src='http://akahele.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gregory Kohs</title>
		<link>http://akahele.org/2009/09/false-sense-of-security/comment-page-1/#comment-2105</link>
		<dc:creator>Gregory Kohs</dc:creator>
		<pubDate>Wed, 16 Sep 2009 00:15:03 +0000</pubDate>
		<guid isPermaLink="false">http://akahele.org/?p=1125#comment-2105</guid>
		<description>&quot;All software has bugs&quot; is not a true statement.  I wrote a pretty mean Basic program on my TI-99/4A computer when I was about 12 years old -- it was a &quot;music video&quot; to &quot;O Little Town of Bethlehem&quot;.  You should have seen how the Star of David came out at the end and twinkled.  Not a single bug in that program.  Storage medium for this software?  Audio cassette tape.  Those were the days.</description>
		<content:encoded><![CDATA[<p>&#8220;All software has bugs&#8221; is not a true statement.  I wrote a pretty mean Basic program on my TI-99/4A computer when I was about 12 years old &#8212; it was a &#8220;music video&#8221; to &#8220;O Little Town of Bethlehem&#8221;.  You should have seen how the Star of David came out at the end and twinkled.  Not a single bug in that program.  Storage medium for this software?  Audio cassette tape.  Those were the days.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: * (Person gave an asterisk as their identity)</title>
		<link>http://akahele.org/2009/09/false-sense-of-security/comment-page-1/#comment-2104</link>
		<dc:creator>* (Person gave an asterisk as their identity)</dc:creator>
		<pubDate>Tue, 15 Sep 2009 21:39:10 +0000</pubDate>
		<guid isPermaLink="false">http://akahele.org/?p=1125#comment-2104</guid>
		<description>Last mediawiki versions are not vulnerable. See the versions affected but that &quot;most recent vulnerability&quot;. Last version is 1.15.1 (and having the installer accessible is uncommon).

Does this mean it&#039;s completely safe? Of course not. All software has bugs.

A more interesting measure would be the time taken to fix the vulnerabilities, not just the number of bugs which were identified over time.

Open Source usually performs better on this side.</description>
		<content:encoded><![CDATA[<p>Last mediawiki versions are not vulnerable. See the versions affected but that &#8220;most recent vulnerability&#8221;. Last version is 1.15.1 (and having the installer accessible is uncommon).</p>
<p>Does this mean it&#8217;s completely safe? Of course not. All software has bugs.</p>
<p>A more interesting measure would be the time taken to fix the vulnerabilities, not just the number of bugs which were identified over time.</p>
<p>Open Source usually performs better on this side.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Awbrey</title>
		<link>http://akahele.org/2009/09/false-sense-of-security/comment-page-1/#comment-2103</link>
		<dc:creator>Jon Awbrey</dc:creator>
		<pubDate>Tue, 15 Sep 2009 18:15:55 +0000</pubDate>
		<guid isPermaLink="false">http://akahele.org/?p=1125#comment-2103</guid>
		<description>Φui!  I can&#039;t φunction without a preview button! 

Ja Ja </description>
		<content:encoded><![CDATA[<p>Φui!  I can&#8217;t φunction without a preview button! </p>
<p>Ja Ja</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Awbrey</title>
		<link>http://akahele.org/2009/09/false-sense-of-security/comment-page-1/#comment-2102</link>
		<dc:creator>Jon Awbrey</dc:creator>
		<pubDate>Tue, 15 Sep 2009 18:08:28 +0000</pubDate>
		<guid isPermaLink="false">http://akahele.org/?p=1125#comment-2102</guid>
		<description>Your Friendly &lt;a href=&quot;http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0737&quot; rel=&quot;nofollow&quot;&gt;Nøøberhøød VD Advisor&lt;/a&gt; Says:

&lt;b&gt;&lt;i&gt;Access Vector:  Network exploitable;  Victim must voluntarily interact with attack mechanism&lt;/i&gt;&lt;/b&gt;

There&#039;s a lesson in that …

Ja Ja http://wikipediareview.com/smilys0b23ax56/default/boing.gif</description>
		<content:encoded><![CDATA[<p>Your Friendly <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0737" rel="nofollow">Nøøberhøød VD Advisor</a> Says:</p>
<p><b><i>Access Vector:  Network exploitable;  Victim must voluntarily interact with attack mechanism</i></b></p>
<p>There&#8217;s a lesson in that …</p>
<p>Ja Ja <a href="http://wikipediareview.com/smilys0b23ax56/default/boing.gif" rel="nofollow">http://wikipediareview.com/smilys0b23ax56/default/boing.gif</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
