<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Angels of security</title>
	<atom:link href="http://angelsofsecurity.com/blog/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://angelsofsecurity.com/blog</link>
	<description>Musings of an infosec renegade</description>
	<lastBuildDate>Tue, 20 Oct 2009 16:18:46 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>Comment on Nigerian scammers go up a notch by chaim</title>
		<link>http://angelsofsecurity.com/blog/2009/10/20/nigerian-scammers-go-up-a-notch/comment-page-1/#comment-10603</link>
		<dc:creator>chaim</dc:creator>
		<pubDate>Tue, 20 Oct 2009 16:18:46 +0000</pubDate>
		<guid isPermaLink="false">http://angelsofsecurity.com/blog/?p=526#comment-10603</guid>
		<description>wow, that&#039;s just sick.

in other news, it amazes me that I can still catch 99% of what the spam filter misses without even opening the email. Yahoo&#039;s spam filter doesn&#039;t even catch spoofs purporting to be from Yahoo account services! ...we&#039;ve got a long way to go to the singularity...</description>
		<content:encoded><![CDATA[<p>wow, that&#8217;s just sick.</p>
<p>in other news, it amazes me that I can still catch 99% of what the spam filter misses without even opening the email. Yahoo&#8217;s spam filter doesn&#8217;t even catch spoofs purporting to be from Yahoo account services! &#8230;we&#8217;ve got a long way to go to the singularity&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Blackberry surveillance by Nym</title>
		<link>http://angelsofsecurity.com/blog/2009/07/16/blackberry-surveillance/comment-page-1/#comment-10485</link>
		<dc:creator>Nym</dc:creator>
		<pubDate>Thu, 16 Jul 2009 21:22:32 +0000</pubDate>
		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2009/07/16/blackberry-surveillance/#comment-10485</guid>
		<description>http://www.veracode.com/blog/2009/07/blackberry-spyware-dissected/ has the gory details on the &quot;patch.&quot;  Thank you Weld Pond!</description>
		<content:encoded><![CDATA[<p><a href="http://www.veracode.com/blog/2009/07/blackberry-spyware-dissected/" rel="nofollow">http://www.veracode.com/blog/2009/07/blackberry-spyware-dissected/</a> has the gory details on the &#8220;patch.&#8221;  Thank you Weld Pond!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Drug smuggling codes by Sara</title>
		<link>http://angelsofsecurity.com/blog/2009/06/23/drug-smuggling-codes/comment-page-1/#comment-10390</link>
		<dc:creator>Sara</dc:creator>
		<pubDate>Wed, 24 Jun 2009 05:36:03 +0000</pubDate>
		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2009/06/23/drug-smuggling-codes/#comment-10390</guid>
		<description>Pretty nice post. I just stumbled upon your site and wanted to say 
that I&#039;ve really liked reading your blog posts. In any case 
I&#039;ll be subscribing to your blog and I hope you post again soon!</description>
		<content:encoded><![CDATA[<p>Pretty nice post. I just stumbled upon your site and wanted to say<br />
that I&#8217;ve really liked reading your blog posts. In any case<br />
I&#8217;ll be subscribing to your blog and I hope you post again soon!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Fannie Mae logic bomb by Trio (band) &#187; Computer surveillance</title>
		<link>http://angelsofsecurity.com/blog/2009/02/04/fannie-mae-logic-bomb/comment-page-1/#comment-8139</link>
		<dc:creator>Trio (band) &#187; Computer surveillance</dc:creator>
		<pubDate>Mon, 04 May 2009 23:23:55 +0000</pubDate>
		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2009/02/04/fannie-mae-logic-bomb/#comment-8139</guid>
		<description>[...] Angels of security » Blog Archive » Fannie Mae logic bomb [...]</description>
		<content:encoded><![CDATA[<p>[...] Angels of security » Blog Archive » Fannie Mae logic bomb [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 7 habits of highly effective infosec profesionals by SXSW: The Perils of Being Internet Famous [Voices] &#124; Hobby Cash: Make Cash Blogging About the Things You Love</title>
		<link>http://angelsofsecurity.com/blog/2009/03/09/7/comment-page-1/#comment-7352</link>
		<dc:creator>SXSW: The Perils of Being Internet Famous [Voices] &#124; Hobby Cash: Make Cash Blogging About the Things You Love</dc:creator>
		<pubDate>Tue, 17 Mar 2009 23:00:06 +0000</pubDate>
		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2009/03/09/7/#comment-7352</guid>
		<description>[...] Angels of security » Blog Archive » 7 habits of highly effective &#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] Angels of security » Blog Archive » 7 habits of highly effective &#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on vulnerability disclosure response time by Matt</title>
		<link>http://angelsofsecurity.com/blog/2009/03/05/vulnerability-disclosure-response-time/comment-page-1/#comment-7160</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Fri, 06 Mar 2009 17:36:40 +0000</pubDate>
		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2009/03/05/vulnerability-disclosure-response-time/#comment-7160</guid>
		<description>I think that if you publish it, it motivates folks to get the fix out.</description>
		<content:encoded><![CDATA[<p>I think that if you publish it, it motivates folks to get the fix out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Fannie Mae logic bomb by What Should You GoSee? &#187; Blog Archive &#187; For Those Who Forget, How We Got Into This Mortgage Mess</title>
		<link>http://angelsofsecurity.com/blog/2009/02/04/fannie-mae-logic-bomb/comment-page-1/#comment-6829</link>
		<dc:creator>What Should You GoSee? &#187; Blog Archive &#187; For Those Who Forget, How We Got Into This Mortgage Mess</dc:creator>
		<pubDate>Wed, 04 Feb 2009 22:02:35 +0000</pubDate>
		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2009/02/04/fannie-mae-logic-bomb/#comment-6829</guid>
		<description>[...] Angels of security » Blog Archive » Fannie Mae logic bomb [...]</description>
		<content:encoded><![CDATA[<p>[...] Angels of security » Blog Archive » Fannie Mae logic bomb [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on I was right by Ty S.</title>
		<link>http://angelsofsecurity.com/blog/2008/09/18/i-was-right/comment-page-1/#comment-1307</link>
		<dc:creator>Ty S.</dc:creator>
		<pubDate>Fri, 17 Oct 2008 18:29:15 +0000</pubDate>
		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/09/18/i-was-right/#comment-1307</guid>
		<description>Matt&#039;s right you are pretty smart...</description>
		<content:encoded><![CDATA[<p>Matt&#8217;s right you are pretty smart&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Race to zero by kurt wismer</title>
		<link>http://angelsofsecurity.com/blog/2008/08/12/race-to-zero/comment-page-1/#comment-1131</link>
		<dc:creator>kurt wismer</dc:creator>
		<pubDate>Tue, 23 Sep 2008 19:57:54 +0000</pubDate>
		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/08/12/480/#comment-1131</guid>
		<description>sorry for responding a month later - the system i was using to track comment threads flaked out silently...

about your 2 points:
1) you may not be satisfied with whitelists that don&#039;t include all program types but that&#039;s not an implementation defect... it&#039;s theoretically impossible for it to include all program types from a computer science standpoint... there are an infinite number of them because all data has the potential to be interpreted as code...
2) there are similar limitations for everything else you are suggesting, be it API calls, network traffic, etc... there will always be ways to accomplish these things that a filter won&#039;t recognize... this isn&#039;t a matter of implementation, it&#039;s a matter of computation complexity and computability...</description>
		<content:encoded><![CDATA[<p>sorry for responding a month later &#8211; the system i was using to track comment threads flaked out silently&#8230;</p>
<p>about your 2 points:<br />
1) you may not be satisfied with whitelists that don&#8217;t include all program types but that&#8217;s not an implementation defect&#8230; it&#8217;s theoretically impossible for it to include all program types from a computer science standpoint&#8230; there are an infinite number of them because all data has the potential to be interpreted as code&#8230;<br />
2) there are similar limitations for everything else you are suggesting, be it API calls, network traffic, etc&#8230; there will always be ways to accomplish these things that a filter won&#8217;t recognize&#8230; this isn&#8217;t a matter of implementation, it&#8217;s a matter of computation complexity and computability&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on I was right by Matt W</title>
		<link>http://angelsofsecurity.com/blog/2008/09/18/i-was-right/comment-page-1/#comment-1130</link>
		<dc:creator>Matt W</dc:creator>
		<pubDate>Tue, 23 Sep 2008 19:16:15 +0000</pubDate>
		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/09/18/i-was-right/#comment-1130</guid>
		<description>::sarcasm:: Well you are just SOOOO smart now aren&#039;t you Ari? ::sarcasm::</description>
		<content:encoded><![CDATA[<p>::sarcasm:: Well you are just SOOOO smart now aren&#8217;t you Ari? ::sarcasm::</p>
]]></content:encoded>
	</item>
</channel>
</rss>
