<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: I Am So A Dinosaur&#8230;</title>
	<atom:link href="http://emergentchaos.com/archives/2005/01/i-am-so-a-dinosaur.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2005/01/i-am-so-a-dinosaur.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: adam</title>
		<link>http://emergentchaos.com/archives/2005/01/i-am-so-a-dinosaur.html/comment-page-1#comment-315</link>
		<dc:creator>adam</dc:creator>
		<pubDate>Thu, 27 Jan 2005 23:41:00 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=413#comment-315</guid>
		<description>&gt; &quot;The risk, of course, is that you never know whether you&#039;ve found them all.&quot;
Shoot, that one&#039;s easy.  You haven&#039;t found them all.  But have you hit a point of diminishing returns for the fully loaded costs of future support?
&gt; &quot;Not sure what you mean by &quot;blocking disclosure&quot;. &quot;
Laws like DMCA and UTICA.
</description>
		<content:encoded><![CDATA[<p>> &#8220;The risk, of course, is that you never know whether you&#8217;ve found them all.&#8221;<br />
Shoot, that one&#8217;s easy.  You haven&#8217;t found them all.  But have you hit a point of diminishing returns for the fully loaded costs of future support?<br />
> &#8220;Not sure what you mean by &#8220;blocking disclosure&#8221;. &#8221;<br />
Laws like DMCA and UTICA.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete</title>
		<link>http://emergentchaos.com/archives/2005/01/i-am-so-a-dinosaur.html/comment-page-1#comment-314</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Thu, 27 Jan 2005 23:36:59 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=413#comment-314</guid>
		<description>I am all for reducing the creation of vulns. The risk, of course, is that you never know whether you&#039;ve found them all. I would love for folks to begin using parallel QA teams of fault injection to estimate defects, but I am not sure that is likely to happen.
Yes, Eric&#039;s approach is pretty neat - basically he looks for a downward trend in the number of vulnerabilities found for an application.
Not sure what you mean by &quot;blocking disclosure&quot;. My initial reaction is that I didn&#039;t do a good job distinguishing between discovery and disclosure. (I am not really looking to block disclosure once the vuln is discovered, just to make it much less attractive to go looking in the first place.)
</description>
		<content:encoded><![CDATA[<p>I am all for reducing the creation of vulns. The risk, of course, is that you never know whether you&#8217;ve found them all. I would love for folks to begin using parallel QA teams of fault injection to estimate defects, but I am not sure that is likely to happen.<br />
Yes, Eric&#8217;s approach is pretty neat &#8211; basically he looks for a downward trend in the number of vulnerabilities found for an application.<br />
Not sure what you mean by &#8220;blocking disclosure&#8221;. My initial reaction is that I didn&#8217;t do a good job distinguishing between discovery and disclosure. (I am not really looking to block disclosure once the vuln is discovered, just to make it much less attractive to go looking in the first place.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: adam</title>
		<link>http://emergentchaos.com/archives/2005/01/i-am-so-a-dinosaur.html/comment-page-1#comment-313</link>
		<dc:creator>adam</dc:creator>
		<pubDate>Wed, 26 Jan 2005 23:32:32 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=413#comment-313</guid>
		<description>Pete, your point is a good one, but lets go back all the way to creation, rather than discovery.  Vuln density in new code is managable.  The tools are not yet mature, but they&#039;re improving.    I should also mention that Eric Rescorla has done good work on the question of &#039;Is Finding Vulns a Good Idea?&#039;   He answers no, but I think the tools available to us to block disclosure are worse than the disease.
I&#039;ll post more tomorrow on the econmics of disclosure, qua disclosure.
</description>
		<content:encoded><![CDATA[<p>Pete, your point is a good one, but lets go back all the way to creation, rather than discovery.  Vuln density in new code is managable.  The tools are not yet mature, but they&#8217;re improving.    I should also mention that Eric Rescorla has done good work on the question of &#8216;Is Finding Vulns a Good Idea?&#8217;   He answers no, but I think the tools available to us to block disclosure are worse than the disease.<br />
I&#8217;ll post more tomorrow on the econmics of disclosure, qua disclosure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete</title>
		<link>http://emergentchaos.com/archives/2005/01/i-am-so-a-dinosaur.html/comment-page-1#comment-312</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Wed, 26 Jan 2005 19:48:56 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=413#comment-312</guid>
		<description>To evaluate economics at the point of disclosure is too late because by then it is out of our collective hands - that&#039;s the whole problem to begin with, that we can&#039;t control the process at that point. Discovery is where we should be placing more emphasis. See &lt;a href=&quot;http://searchsecurity.techtarget.com/tip/1,289483,sid14_gci1014528,00.html&quot; rel=&quot;nofollow&quot;&gt;http://searchsecurity.techtarget.com/tip/1,289483,sid14_gci1014528,00.html&lt;/a&gt; for more info.
Here is a model for you: (LOCe (existing lines of code) + LOCd (new lines of code created daily)) x Vulnerability Density (5 per 1000 LOC? .1 per KLOC? doesn&#039;t really matter) is much, much larger than the avg 10 vulns per day we are finding, and the gap is widening. Discovered vulnerabilities are &quot;comfort food&quot; and distracting if we honestly believe that the true threats are zero-day attacks (exploits against discovered vulns that no good guys know about).
</description>
		<content:encoded><![CDATA[<p>To evaluate economics at the point of disclosure is too late because by then it is out of our collective hands &#8211; that&#8217;s the whole problem to begin with, that we can&#8217;t control the process at that point. Discovery is where we should be placing more emphasis. See <a href="http://searchsecurity.techtarget.com/tip/1,289483,sid14_gci1014528,00.html" rel="nofollow">http://searchsecurity.techtarget.com/tip/1,289483,sid14_gci1014528,00.html</a> for more info.<br />
Here is a model for you: (LOCe (existing lines of code) + LOCd (new lines of code created daily)) x Vulnerability Density (5 per 1000 LOC? .1 per KLOC? doesn&#8217;t really matter) is much, much larger than the avg 10 vulns per day we are finding, and the gap is widening. Discovered vulnerabilities are &#8220;comfort food&#8221; and distracting if we honestly believe that the true threats are zero-day attacks (exploits against discovered vulns that no good guys know about).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Iang</title>
		<link>http://emergentchaos.com/archives/2005/01/i-am-so-a-dinosaur.html/comment-page-1#comment-311</link>
		<dc:creator>Iang</dc:creator>
		<pubDate>Wed, 26 Jan 2005 18:11:08 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=413#comment-311</guid>
		<description>Has anyone modelled in economics terms why disclosure is better than the alternate(s) ?
</description>
		<content:encoded><![CDATA[<p>Has anyone modelled in economics terms why disclosure is better than the alternate(s) ?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

