<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Sorry CharlieCard, Your Security Model Is Broken</title>
	<atom:link href="http://www.veracode.com/blog/2008/08/sorry-charliecard-your-security-model-is-broken/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog/2008/08/sorry-charliecard-your-security-model-is-broken/</link>
	<description>Application security testing, analysis, and metrics</description>
	<pubDate>Tue, 06 Jan 2009 18:56:28 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: MBTA Put Profit Before Security? &#124; theReformed</title>
		<link>http://www.veracode.com/blog/2008/08/sorry-charliecard-your-security-model-is-broken/#comment-2028</link>
		<dc:creator>MBTA Put Profit Before Security? &#124; theReformed</dc:creator>
		<pubDate>Mon, 25 Aug 2008 12:54:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=189#comment-2028</guid>
		<description>[...] Chris stated in his own article, &#8220;&#8230;Doesn’t this seem backwards to you? Shouldn’t the MBTA be suing the vendor who [...]</description>
		<content:encoded><![CDATA[<p>[...] Chris stated in his own article, &#8220;&#8230;Doesn’t this seem backwards to you? Shouldn’t the MBTA be suing the vendor who [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zero in a bit &#187; MBTA Hacking Injunction Lifted</title>
		<link>http://www.veracode.com/blog/2008/08/sorry-charliecard-your-security-model-is-broken/#comment-2021</link>
		<dc:creator>Zero in a bit &#187; MBTA Hacking Injunction Lifted</dc:creator>
		<pubDate>Wed, 20 Aug 2008 05:49:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=189#comment-2021</guid>
		<description>[...] Chris Wysopal pointed out last week, the MBTA&#8217;s ire is misdirected. Rather than suing the vendor who sold them the defective [...]</description>
		<content:encoded><![CDATA[<p>[...] Chris Wysopal pointed out last week, the MBTA&#8217;s ire is misdirected. Rather than suing the vendor who sold them the defective [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Catching up&#8230; &#124; Mike Andrews</title>
		<link>http://www.veracode.com/blog/2008/08/sorry-charliecard-your-security-model-is-broken/#comment-2013</link>
		<dc:creator>Catching up&#8230; &#124; Mike Andrews</dc:creator>
		<pubDate>Sun, 17 Aug 2008 07:01:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=189#comment-2013</guid>
		<description>[...] example that I&#8217;ve seen lots of posts about.&#160; The best intro is from Chris at Veracode here and here.&#160; Basically, the Massachusetts Bay Transportation Authority (MBTA) is (was?) suing [...]</description>
		<content:encoded><![CDATA[<p>[...] example that I&#8217;ve seen lots of posts about.&nbsp; The best intro is from Chris at Veracode here and here.&nbsp; Basically, the Massachusetts Bay Transportation Authority (MBTA) is (was?) suing [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
