<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: But That&#8217;s Impossible!</title>
	<atom:link href="http://www.veracode.com/blog/2009/05/but-thats-impossible/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog/2009/05/but-thats-impossible/</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Thu, 09 Feb 2012 11:59:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: no way</title>
		<link>http://www.veracode.com/blog/2009/05/but-thats-impossible/comment-page-1/#comment-10356</link>
		<dc:creator>no way</dc:creator>
		<pubDate>Thu, 17 Nov 2011 18:17:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=774#comment-10356</guid>
		<description>as a developer on more of the security side than most..

about 30% of what veracode is saying is rather retarded.</description>
		<content:encoded><![CDATA[<p>as a developer on more of the security side than most..</p>
<p>about 30% of what veracode is saying is rather retarded.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ZeroDay Labs blog &#187; Stay Cool, Nobody is Calling Your Baby Ugly</title>
		<link>http://www.veracode.com/blog/2009/05/but-thats-impossible/comment-page-1/#comment-10014</link>
		<dc:creator>ZeroDay Labs blog &#187; Stay Cool, Nobody is Calling Your Baby Ugly</dc:creator>
		<pubDate>Fri, 21 Oct 2011 17:48:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=774#comment-10014</guid>
		<description>[...] questions wanting to understand the situation better, the other folds his arms and fires back with responses like this. What&#8217;s the difference? One is acting defensively while the other is [...]</description>
		<content:encoded><![CDATA[<p>[...] questions wanting to understand the situation better, the other folds his arms and fires back with responses like this. What&#8217;s the difference? One is acting defensively while the other is [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PB</title>
		<link>http://www.veracode.com/blog/2009/05/but-thats-impossible/comment-page-1/#comment-2816</link>
		<dc:creator>PB</dc:creator>
		<pubDate>Wed, 27 May 2009 10:00:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=774#comment-2816</guid>
		<description>Oh hahhaa I forgot &quot;We&#039;re running that service on a higher port number.&quot; Security obfuscation for the win!</description>
		<content:encoded><![CDATA[<p>Oh hahhaa I forgot &#8220;We&#8217;re running that service on a higher port number.&#8221; Security obfuscation for the win!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Motoma</title>
		<link>http://www.veracode.com/blog/2009/05/but-thats-impossible/comment-page-1/#comment-2814</link>
		<dc:creator>Motoma</dc:creator>
		<pubDate>Tue, 26 May 2009 20:00:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=774#comment-2814</guid>
		<description>&quot;If the client&#039;s are dumb enough to do ___ then they deserve what they get.&quot;</description>
		<content:encoded><![CDATA[<p>&#8220;If the client&#8217;s are dumb enough to do ___ then they deserve what they get.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: veye0l8tr</title>
		<link>http://www.veracode.com/blog/2009/05/but-thats-impossible/comment-page-1/#comment-2811</link>
		<dc:creator>veye0l8tr</dc:creator>
		<pubDate>Sat, 23 May 2009 06:22:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=774#comment-2811</guid>
		<description>How about &quot;That&#039;s a problem with the vendor software not our security&quot;, to which my response was &quot;If it&#039;s a problem with the vendor software you are using then it&#039;s a problem with your security&quot;

or another one I hear often &quot;how many people actually know how to do that?&quot; to which my response is &quot;Anyone that has an interest in breaching your security, with internet access and the ability to read.&quot;

The script kiddie arguement mentioned above is another common thread, I usually end up explaining that Uber-hackers document methods and script kiddies can follow instructions.</description>
		<content:encoded><![CDATA[<p>How about &#8220;That&#8217;s a problem with the vendor software not our security&#8221;, to which my response was &#8220;If it&#8217;s a problem with the vendor software you are using then it&#8217;s a problem with your security&#8221;</p>
<p>or another one I hear often &#8220;how many people actually know how to do that?&#8221; to which my response is &#8220;Anyone that has an interest in breaching your security, with internet access and the ability to read.&#8221;</p>
<p>The script kiddie arguement mentioned above is another common thread, I usually end up explaining that Uber-hackers document methods and script kiddies can follow instructions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Erich</title>
		<link>http://www.veracode.com/blog/2009/05/but-thats-impossible/comment-page-1/#comment-2810</link>
		<dc:creator>Erich</dc:creator>
		<pubDate>Thu, 21 May 2009 21:53:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=774#comment-2810</guid>
		<description>&quot;We&#039;re certainly not in focus. Who&#039;s gonna attack OUR minor website?&quot;

Later on wondering, why the website is spreading malicious code to any visitor so google marks it as dangerous.</description>
		<content:encoded><![CDATA[<p>&#8220;We&#8217;re certainly not in focus. Who&#8217;s gonna attack OUR minor website?&#8221;</p>
<p>Later on wondering, why the website is spreading malicious code to any visitor so google marks it as dangerous.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Timsta</title>
		<link>http://www.veracode.com/blog/2009/05/but-thats-impossible/comment-page-1/#comment-2808</link>
		<dc:creator>Timsta</dc:creator>
		<pubDate>Thu, 21 May 2009 09:41:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=774#comment-2808</guid>
		<description>&quot;The application must be secure. All our competitors use it!&quot;</description>
		<content:encoded><![CDATA[<p>&#8220;The application must be secure. All our competitors use it!&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MikeP</title>
		<link>http://www.veracode.com/blog/2009/05/but-thats-impossible/comment-page-1/#comment-2806</link>
		<dc:creator>MikeP</dc:creator>
		<pubDate>Wed, 20 May 2009 15:28:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=774#comment-2806</guid>
		<description>My own favourite: &quot;Yeah, but who has the time to figure that out?  We&#039;re just xxx.&quot;</description>
		<content:encoded><![CDATA[<p>My own favourite: &#8220;Yeah, but who has the time to figure that out?  We&#8217;re just xxx.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: saari</title>
		<link>http://www.veracode.com/blog/2009/05/but-thats-impossible/comment-page-1/#comment-2804</link>
		<dc:creator>saari</dc:creator>
		<pubDate>Wed, 20 May 2009 05:48:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=774#comment-2804</guid>
		<description>This stuff doesn&#039;t bother me, it&#039;s the fundamentally broken by design issues and basic social engineering that bother me. See OAuth session fixation.</description>
		<content:encoded><![CDATA[<p>This stuff doesn&#8217;t bother me, it&#8217;s the fundamentally broken by design issues and basic social engineering that bother me. See OAuth session fixation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: links for 2009-05-19 (Jarrett House North)</title>
		<link>http://www.veracode.com/blog/2009/05/but-thats-impossible/comment-page-1/#comment-2802</link>
		<dc:creator>links for 2009-05-19 (Jarrett House North)</dc:creator>
		<pubDate>Wed, 20 May 2009 02:01:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=774#comment-2802</guid>
		<description>[...] But That’s Impossible! (Veracode Blog) Responses to security audits range from the funny to the sad. (tags: security) [...]</description>
		<content:encoded><![CDATA[<p>[...] But That’s Impossible! (Veracode Blog) Responses to security audits range from the funny to the sad. (tags: security) [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

