<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Nation State Cyberwarfare Reality Check</title>
	<atom:link href="http://www.veracode.com/blog/2009/07/nation-state-cyberwarfare-reality-check/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog/2009/07/nation-state-cyberwarfare-reality-check/</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Tue, 15 May 2012 22:16:53 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Richard Bejtlich</title>
		<link>http://www.veracode.com/blog/2009/07/nation-state-cyberwarfare-reality-check/comment-page-1/#comment-2913</link>
		<dc:creator>Richard Bejtlich</dc:creator>
		<pubDate>Sat, 11 Jul 2009 21:33:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=850#comment-2913</guid>
		<description>&quot;The root cause of these denial of service attacks is insecure software... Each and every computer system, and each and every software package running on them must be made secure.&quot;

You mean like every single physical asset is &quot;made secure?&quot;  I&#039;m guessing you live in a concrete house with bars over the windows, send your kids to school in an armored personnel carrier, etc.?  

The root cause of these denial of service attacks is a group of bad guys.  We need to deal with bad guys in the cyber world like we deal with them in the physical world.

If you say you lock your house I&#039;ll mention bump keys, breaking a door or window, etc.  The same goes for cars and every other example.  Real world security is threat-focused, not vulnerability focused.</description>
		<content:encoded><![CDATA[<p>&#8220;The root cause of these denial of service attacks is insecure software&#8230; Each and every computer system, and each and every software package running on them must be made secure.&#8221;</p>
<p>You mean like every single physical asset is &#8220;made secure?&#8221;  I&#8217;m guessing you live in a concrete house with bars over the windows, send your kids to school in an armored personnel carrier, etc.?  </p>
<p>The root cause of these denial of service attacks is a group of bad guys.  We need to deal with bad guys in the cyber world like we deal with them in the physical world.</p>
<p>If you say you lock your house I&#8217;ll mention bump keys, breaking a door or window, etc.  The same goes for cars and every other example.  Real world security is threat-focused, not vulnerability focused.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CrabbyOlBastard</title>
		<link>http://www.veracode.com/blog/2009/07/nation-state-cyberwarfare-reality-check/comment-page-1/#comment-2910</link>
		<dc:creator>CrabbyOlBastard</dc:creator>
		<pubDate>Thu, 09 Jul 2009 18:50:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=850#comment-2910</guid>
		<description>If one were able to get secure coding codified and implemented, then I believe that the problem will then be the human nature aspect. Unless forced by software, they will more often then not, weaken their systems by installing rogue software, lessening passwords, or being completely unversed in security practices.

It&#039;s a tough nut to crack overall... There may never be a solution to this problem.</description>
		<content:encoded><![CDATA[<p>If one were able to get secure coding codified and implemented, then I believe that the problem will then be the human nature aspect. Unless forced by software, they will more often then not, weaken their systems by installing rogue software, lessening passwords, or being completely unversed in security practices.</p>
<p>It&#8217;s a tough nut to crack overall&#8230; There may never be a solution to this problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Wysopal</title>
		<link>http://www.veracode.com/blog/2009/07/nation-state-cyberwarfare-reality-check/comment-page-1/#comment-2908</link>
		<dc:creator>Chris Wysopal</dc:creator>
		<pubDate>Thu, 09 Jul 2009 17:00:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=850#comment-2908</guid>
		<description>One malignant cell is not a problem.  It is when they reach a critical mass withing the community of cells making up the animal that is a problem.  

The way I look at it many low risk compromised machines (the home PC user) be come a high risk collectively to any single machine on the internet community.</description>
		<content:encoded><![CDATA[<p>One malignant cell is not a problem.  It is when they reach a critical mass withing the community of cells making up the animal that is a problem.  </p>
<p>The way I look at it many low risk compromised machines (the home PC user) be come a high risk collectively to any single machine on the internet community.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.veracode.com/blog/2009/07/nation-state-cyberwarfare-reality-check/comment-page-1/#comment-2906</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Thu, 09 Jul 2009 12:12:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=850#comment-2906</guid>
		<description>I like the cell analogy, so lets go with that. Molecular biology seems to be the field we computer security people are looking towards for answers to our own problems these days. And that&#039;s not necessarily a bad thing but it does bring up the question: &#039;Is the cat and mouse game ever avoidable?&#039;. (I don&#039;t think it is). But we can become a better cat. We need a good way to tell the ecosystem those cells are infected and require a cure, or at least detect the symptoms early. So we should also be looking at other fields such as neuroscience (the CS community has for a long time). Every country have their own dominant social networking website, this is a good place to start to get the word out &#039;mass infection happening ... do xyz&#039;. You can&#039;t post it on ISC and expect 500 million normal people to read it. This also raises the possibility of an attacker using that same system for malicious gain, but certain virii does this in nature IIRC. While auditing all software before release is a great idea (and yes is great for business ;) its not %100 possible, the same way your born with flawed cells that will eventually be owned by some virus specifically designed to exploit its weaknesses. One thing is certain, I am not smart enough to solve this problem. Good post.</description>
		<content:encoded><![CDATA[<p>I like the cell analogy, so lets go with that. Molecular biology seems to be the field we computer security people are looking towards for answers to our own problems these days. And that&#8217;s not necessarily a bad thing but it does bring up the question: &#8216;Is the cat and mouse game ever avoidable?&#8217;. (I don&#8217;t think it is). But we can become a better cat. We need a good way to tell the ecosystem those cells are infected and require a cure, or at least detect the symptoms early. So we should also be looking at other fields such as neuroscience (the CS community has for a long time). Every country have their own dominant social networking website, this is a good place to start to get the word out &#8216;mass infection happening &#8230; do xyz&#8217;. You can&#8217;t post it on ISC and expect 500 million normal people to read it. This also raises the possibility of an attacker using that same system for malicious gain, but certain virii does this in nature IIRC. While auditing all software before release is a great idea (and yes is great for business ;) its not %100 possible, the same way your born with flawed cells that will eventually be owned by some virus specifically designed to exploit its weaknesses. One thing is certain, I am not smart enough to solve this problem. Good post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nation State Cyberwarfare Reality Check &#171; euraktiva</title>
		<link>http://www.veracode.com/blog/2009/07/nation-state-cyberwarfare-reality-check/comment-page-1/#comment-2905</link>
		<dc:creator>Nation State Cyberwarfare Reality Check &#171; euraktiva</dc:creator>
		<pubDate>Thu, 09 Jul 2009 10:59:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=850#comment-2905</guid>
		<description>[...] via Nation State Cyberwarfare Reality Check. [...]</description>
		<content:encoded><![CDATA[<p>[...] via Nation State Cyberwarfare Reality Check. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

