<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Market for zero-day vulnerabilities incentivizes programmers to sabotage their own&#160;work</title>
	<atom:link href="http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html/feed" rel="self" type="application/rss+xml" />
	<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html</link>
	<description>Brain candy for Happy Mutants</description>
	<lastBuildDate>Wed, 22 May 2013 08:59:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Antinous / Moderator</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1452719</link>
		<dc:creator>Antinous / Moderator</dc:creator>
		<pubDate>Mon, 18 Jun 2012 20:49:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1452719</guid>
		<description>Incite doesn&#039;t imply an incentive.</description>
		<content:encoded><![CDATA[<p>Incite doesn&#8217;t imply an incentive.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dragonfrog</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1452439</link>
		<dc:creator>dragonfrog</dc:creator>
		<pubDate>Mon, 18 Jun 2012 16:43:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1452439</guid>
		<description>Why inventorificate a new word when &quot;incites&quot; is already there?</description>
		<content:encoded><![CDATA[<p>Why inventorificate a new word when &#8220;incites&#8221; is already there?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JonS</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1452081</link>
		<dc:creator>JonS</dc:creator>
		<pubDate>Mon, 18 Jun 2012 00:09:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1452081</guid>
		<description>Of course they are ... they&#039;re /criminals/. But the Govt - if not businesses - are supposed to be looking out for our interests, not looking for new ways to sell us down the river.</description>
		<content:encoded><![CDATA[<p>Of course they are &#8230; they&#8217;re /criminals/. But the Govt &#8211; if not businesses &#8211; are supposed to be looking out for our interests, not looking for new ways to sell us down the river.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: foobar</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1452065</link>
		<dc:creator>foobar</dc:creator>
		<pubDate>Sun, 17 Jun 2012 23:32:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1452065</guid>
		<description>To take a whack at a bank&#039;s security, you have to actually go there and run the risk of arrest. You can go at whatever server you like from a coffee shop with practically no chance of being identified.

Moreover, you can usually get a copy of software to attack in the privacy of your own network.</description>
		<content:encoded><![CDATA[<p>To take a whack at a bank&#8217;s security, you have to actually go there and run the risk of arrest. You can go at whatever server you like from a coffee shop with practically no chance of being identified.</p>
<p>Moreover, you can usually get a copy of software to attack in the privacy of your own network.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stephenl123</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1452049</link>
		<dc:creator>stephenl123</dc:creator>
		<pubDate>Sun, 17 Jun 2012 22:17:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1452049</guid>
		<description>I notice you mention governments and businesses paying for zero day vulnerabilities.  But you don&#039;t mention criminal organizations doing the same thing.  Is it that you think the black market for vulnerabilities is not a major part of the market?</description>
		<content:encoded><![CDATA[<p>I notice you mention governments and businesses paying for zero day vulnerabilities.  But you don&#8217;t mention criminal organizations doing the same thing.  Is it that you think the black market for vulnerabilities is not a major part of the market?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tré</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1451861</link>
		<dc:creator>tré</dc:creator>
		<pubDate>Sun, 17 Jun 2012 13:50:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1451861</guid>
		<description>Don&#039;t hate the player... 

(but seriously, this whole thing needs to be taken care of by some serious market regulation.)</description>
		<content:encoded><![CDATA[<p>Don&#8217;t hate the player&#8230; </p>
<p>(but seriously, this whole thing needs to be taken care of by some serious market regulation.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Renault</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1451837</link>
		<dc:creator>Paul Renault</dc:creator>
		<pubDate>Sun, 17 Jun 2012 11:27:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1451837</guid>
		<description>Verbing weirds language.
 - Calvin (John?)</description>
		<content:encoded><![CDATA[<p>Verbing weirds language.<br />
 - Calvin (John?)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: devilsdue</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1451802</link>
		<dc:creator>devilsdue</dc:creator>
		<pubDate>Sun, 17 Jun 2012 08:50:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1451802</guid>
		<description>Bank vaults, and for that matter any kind of traditional physical security, are as exposed as any Internet connected computer.  The only reason you perceive them to be less exposed is that vaults tend to be at the center of nested layers of security, and that the difficulty of tackling that security outweighs the benefits of breaking in.  Furthermore, when break-ins do occur, banks are required to inform authorities and the bank&#039;s customers that such a break-in did occur.

Instead, you have systems where single-point vulnerabilities lay open entire networks to outside access.  Worse, now the developers of those systems (and the software the systems run) have an incentive to ensure they are insecure.  Allowing those developers to limit their legal liabilities to customers only increases that incentive to sell out those same customers.</description>
		<content:encoded><![CDATA[<p>Bank vaults, and for that matter any kind of traditional physical security, are as exposed as any Internet connected computer.  The only reason you perceive them to be less exposed is that vaults tend to be at the center of nested layers of security, and that the difficulty of tackling that security outweighs the benefits of breaking in.  Furthermore, when break-ins do occur, banks are required to inform authorities and the bank&#8217;s customers that such a break-in did occur.</p>
<p>Instead, you have systems where single-point vulnerabilities lay open entire networks to outside access.  Worse, now the developers of those systems (and the software the systems run) have an incentive to ensure they are insecure.  Allowing those developers to limit their legal liabilities to customers only increases that incentive to sell out those same customers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: foobar</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1451766</link>
		<dc:creator>foobar</dc:creator>
		<pubDate>Sun, 17 Jun 2012 05:47:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1451766</guid>
		<description>Bank vaults are pretty simple compared to software, yet if they were exposed to everyone on the internet I&#039;d imagine they&#039;d get opened pretty quickly.</description>
		<content:encoded><![CDATA[<p>Bank vaults are pretty simple compared to software, yet if they were exposed to everyone on the internet I&#8217;d imagine they&#8217;d get opened pretty quickly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Antinous / Moderator</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1451758</link>
		<dc:creator>Antinous / Moderator</dc:creator>
		<pubDate>Sun, 17 Jun 2012 05:25:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1451758</guid>
		<description>Verb too radical?</description>
		<content:encoded><![CDATA[<p>Verb too radical?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fettemama</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1451739</link>
		<dc:creator>fettemama</dc:creator>
		<pubDate>Sun, 17 Jun 2012 04:36:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1451739</guid>
		<description>That&#039;s disgusting! Developers should be prosecuted!</description>
		<content:encoded><![CDATA[<p>That&#8217;s disgusting! Developers should be prosecuted!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Moriarty</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1451727</link>
		<dc:creator>Moriarty</dc:creator>
		<pubDate>Sun, 17 Jun 2012 04:20:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1451727</guid>
		<description> Well, that and the fact that nobody wants to buy a crappy bank vault.</description>
		<content:encoded><![CDATA[<p> Well, that and the fact that nobody wants to buy a crappy bank vault.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: devilsdue</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1451706</link>
		<dc:creator>devilsdue</dc:creator>
		<pubDate>Sun, 17 Jun 2012 03:25:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1451706</guid>
		<description>One of the underlying problems is those EULAs we all click through that absolve developers of any and all damages that may come from using their software.   Ask yourself: If money can be made by putting intentional faults into security products, why aren&#039;t bank vaults broken into all the time?  The answer is in the liability, as well as the licensing and bonding process that vault makers and locksmiths must go through in order to sell their products and services.

Of course, that would require regulation.  A naughty word in politics today.</description>
		<content:encoded><![CDATA[<p>One of the underlying problems is those EULAs we all click through that absolve developers of any and all damages that may come from using their software.   Ask yourself: If money can be made by putting intentional faults into security products, why aren&#8217;t bank vaults broken into all the time?  The answer is in the liability, as well as the licensing and bonding process that vault makers and locksmiths must go through in order to sell their products and services.</p>
<p>Of course, that would require regulation.  A naughty word in politics today.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Avram Grumer</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1451682</link>
		<dc:creator>Avram Grumer</dc:creator>
		<pubDate>Sun, 17 Jun 2012 02:24:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1451682</guid>
		<description>It&#039;s a bad day when the tech industry follows in the footsteps of &lt;a href=&quot;http://dilbert.com/strips/comic/1995-11-13/&quot; rel=&quot;nofollow&quot;&gt;an almost-20-year-old &lt;i&gt;Dilbert&lt;/i&gt; cartoon&lt;/a&gt;. </description>
		<content:encoded><![CDATA[<p>It&#8217;s a bad day when the tech industry follows in the footsteps of <a href="http://dilbert.com/strips/comic/1995-11-13/" rel="nofollow">an almost-20-year-old <i>Dilbert</i> cartoon</a>. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vanwall Green</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1451656</link>
		<dc:creator>Vanwall Green</dc:creator>
		<pubDate>Sun, 17 Jun 2012 01:48:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1451656</guid>
		<description>Like making zip guns for a coupla bucks apiece, and selling them to the Cops for $300.00 each, and keeping the real guns on the street.  </description>
		<content:encoded><![CDATA[<p>Like making zip guns for a coupla bucks apiece, and selling them to the Cops for $300.00 each, and keeping the real guns on the street.  </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: checht</title>
		<link>http://boingboing.net/2012/06/16/market-for-zero-day-vulnerabil.html#comment-1451654</link>
		<dc:creator>checht</dc:creator>
		<pubDate>Sun, 17 Jun 2012 01:46:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=166607#comment-1451654</guid>
		<description>&quot;Incentivizes&quot; - ouch. &quot;Provides Incentive&quot; too old school? </description>
		<content:encoded><![CDATA[<p>&#8220;Incentivizes&#8221; &#8211; ouch. &#8220;Provides Incentive&#8221; too old school? </p>
]]></content:encoded>
	</item>
</channel>
</rss>
