<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Let&#8217;s Stop Cutesy Names for Attacks</title>
	<atom:link href="http://emergentchaos.com/archives/2007/02/lets-stop-cutesy-names-for-attacks.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2007/02/lets-stop-cutesy-names-for-attacks.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Mon, 15 Mar 2010 15:02:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Elphaba</title>
		<link>http://emergentchaos.com/archives/2007/02/lets-stop-cutesy-names-for-attacks.html/comment-page-1#comment-3249</link>
		<dc:creator>Elphaba</dc:creator>
		<pubDate>Wed, 07 Mar 2007 00:42:44 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2224#comment-3249</guid>
		<description>I&#039;ve been thinking about this post for some time now (obviously), and apparently so have other people I know because more than once I&#039;ve heard &#039;social engineering = fraud&#039; tossed around with disdain and disgust, like only an uneducated plebe would use the term social engineering anymore.
But social engineering != fraud &lt;i&gt;all of the time&lt;/i&gt;.  Sometimes fraud is just fraud, like counterfeiting.  And sometimes social engineering is just social engineering, like dressing nicely, smiling sincerely, and treating the ticketing agent like a human being so you stand out from the masses of annoying and frustrated travelers as a Nice Person That Should Be Upgraded To A Premium Seat Without Having To Ask.  That isn&#039;t fraud, that is understanding something about psychology and sociology that you apply in human interactions to help yourself come out ahead. Social engineering is a concept, a practice if you will, that &lt;i&gt;can&lt;/i&gt; be used for malicious purposes, but in and of itself &lt;i&gt;does not require&lt;/i&gt; lying, misleading, deception or fraud!
I would suggest that saying &#039;social engineering is a con job&#039; is an oversimplification that contributes to shallow thought by the masses.  Like calling all of these populations:
- people who find security vulnerabilities and report them
- people who write POC code
- people who reverse engineer security patches
- people who write/release worms
- people who steal your credit card number and passwords via keystroke loggers and a botnet
a &#039;hacker&#039;.  Too much jargon and exclusionary language is bad, but so is oversimplification.  Should people be afraid of botherders?  yes.  Do they need to fear and revile security researchers?  no.  Well, not all of them anyway.  (ha ha, it&#039;s a joke people)
BTW, welcome to the E.C., Mordaxus.  I&#039;ve already told Adam that I like having you around, hope you understand this is just healthy debate, not a personal attack.
~Elphie
</description>
		<content:encoded><![CDATA[<p>I&#8217;ve been thinking about this post for some time now (obviously), and apparently so have other people I know because more than once I&#8217;ve heard &#8217;social engineering = fraud&#8217; tossed around with disdain and disgust, like only an uneducated plebe would use the term social engineering anymore.<br />
But social engineering != fraud <i>all of the time</i>.  Sometimes fraud is just fraud, like counterfeiting.  And sometimes social engineering is just social engineering, like dressing nicely, smiling sincerely, and treating the ticketing agent like a human being so you stand out from the masses of annoying and frustrated travelers as a Nice Person That Should Be Upgraded To A Premium Seat Without Having To Ask.  That isn&#8217;t fraud, that is understanding something about psychology and sociology that you apply in human interactions to help yourself come out ahead. Social engineering is a concept, a practice if you will, that <i>can</i> be used for malicious purposes, but in and of itself <i>does not require</i> lying, misleading, deception or fraud!<br />
I would suggest that saying &#8217;social engineering is a con job&#8217; is an oversimplification that contributes to shallow thought by the masses.  Like calling all of these populations:<br />
- people who find security vulnerabilities and report them<br />
- people who write POC code<br />
- people who reverse engineer security patches<br />
- people who write/release worms<br />
- people who steal your credit card number and passwords via keystroke loggers and a botnet<br />
a &#8216;hacker&#8217;.  Too much jargon and exclusionary language is bad, but so is oversimplification.  Should people be afraid of botherders?  yes.  Do they need to fear and revile security researchers?  no.  Well, not all of them anyway.  (ha ha, it&#8217;s a joke people)<br />
BTW, welcome to the E.C., Mordaxus.  I&#8217;ve already told Adam that I like having you around, hope you understand this is just healthy debate, not a personal attack.<br />
~Elphie</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frederick Wamsley</title>
		<link>http://emergentchaos.com/archives/2007/02/lets-stop-cutesy-names-for-attacks.html/comment-page-1#comment-3248</link>
		<dc:creator>Frederick Wamsley</dc:creator>
		<pubDate>Fri, 16 Feb 2007 17:12:16 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2224#comment-3248</guid>
		<description>Here&#039;s another reason you&#039;re right. Imprecise can turn into actively misleading, even among people familiar with the subject.
Over on Slashdot, hundreds of technologists and hobbyists saw the phrase &quot;drive-by pharming&quot; and assumed that since it said &quot;drive-by&quot; it must have something to do with wireless networking. Most of the discussion was off the rails (more than usual) as a result.
Good communication is hard enough without deliberate sabotage by people trying to establish an in crowd by inventing obscure slang.
</description>
		<content:encoded><![CDATA[<p>Here&#8217;s another reason you&#8217;re right. Imprecise can turn into actively misleading, even among people familiar with the subject.<br />
Over on Slashdot, hundreds of technologists and hobbyists saw the phrase &#8220;drive-by pharming&#8221; and assumed that since it said &#8220;drive-by&#8221; it must have something to do with wireless networking. Most of the discussion was off the rails (more than usual) as a result.<br />
Good communication is hard enough without deliberate sabotage by people trying to establish an in crowd by inventing obscure slang.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nik</title>
		<link>http://emergentchaos.com/archives/2007/02/lets-stop-cutesy-names-for-attacks.html/comment-page-1#comment-3247</link>
		<dc:creator>Nik</dc:creator>
		<pubDate>Fri, 16 Feb 2007 09:24:27 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2224#comment-3247</guid>
		<description>Agreed in spades... &quot;Ph&quot; should be banned :-)
</description>
		<content:encoded><![CDATA[<p>Agreed in spades&#8230; &#8220;Ph&#8221; should be banned :-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Mason</title>
		<link>http://emergentchaos.com/archives/2007/02/lets-stop-cutesy-names-for-attacks.html/comment-page-1#comment-3246</link>
		<dc:creator>Justin Mason</dc:creator>
		<pubDate>Fri, 16 Feb 2007 08:00:14 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2224#comment-3246</guid>
		<description>The neologism &quot;pharming&quot; is a particular pet hate of mine; it reeks of companies ruled by their marketing departments, rather than adequate technical knowledge.
As I noted in &lt;a href=&quot;http://taint.org/2005/08/06/002104a.html&quot; rel=&quot;nofollow&quot;&gt;&lt;a href=&quot;http://taint.org/2005/08/06/002104a.html&quot; rel=&quot;nofollow&quot;&gt;&lt;a href=&quot;http://taint.org/2005/08/06/002104a.html&quot; rel=&quot;nofollow&quot;&gt;http://taint.org/2005/08/06/002104a.html&lt;/a&gt;&lt;/a&gt;&lt;/a&gt; , it has no less than four separate meanings:
1. genetically modified (transgenic) animals used to make human proteins that have medicinal value;
2. &#039;a malicious Web redirect, in which a person trying to reach a legitimate commercial site is sent to the phony site without his knowledge&#039; using DNS cache poisoning, according to Scott Chasin of MX Logic;
3. social-engineered domain transfers from their registrars, according to &#039;Green Armor Solutions&#039;;
4. a pop-up window that attempts to emulate a legit site’s input, used in a CSO Online article.
What&#039;s the point of creating new terms if we can&#039;t even agree what they _mean_?!
</description>
		<content:encoded><![CDATA[<p>The neologism &#8220;pharming&#8221; is a particular pet hate of mine; it reeks of companies ruled by their marketing departments, rather than adequate technical knowledge.<br />
As I noted in <a href="http://taint.org/2005/08/06/002104a.html" rel="nofollow"></a><a href="http://taint.org/2005/08/06/002104a.html" rel="nofollow"></a><a href="http://taint.org/2005/08/06/002104a.html" rel="nofollow">http://taint.org/2005/08/06/002104a.html</a> , it has no less than four separate meanings:<br />
1. genetically modified (transgenic) animals used to make human proteins that have medicinal value;<br />
2. &#8216;a malicious Web redirect, in which a person trying to reach a legitimate commercial site is sent to the phony site without his knowledge&#8217; using DNS cache poisoning, according to Scott Chasin of MX Logic;<br />
3. social-engineered domain transfers from their registrars, according to &#8216;Green Armor Solutions&#8217;;<br />
4. a pop-up window that attempts to emulate a legit site’s input, used in a CSO Online article.<br />
What&#8217;s the point of creating new terms if we can&#8217;t even agree what they _mean_?!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mordaxus</title>
		<link>http://emergentchaos.com/archives/2007/02/lets-stop-cutesy-names-for-attacks.html/comment-page-1#comment-3245</link>
		<dc:creator>Mordaxus</dc:creator>
		<pubDate>Thu, 15 Feb 2007 22:36:40 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2224#comment-3245</guid>
		<description>Chris, I was tempted to say that cutesiness is 1336, but it&#039;s a relatively subtle remark.
Thank you, Culprit, I couldn&#039;t agree more.
And thank you as well, Mark. I smiled broadly.
</description>
		<content:encoded><![CDATA[<p>Chris, I was tempted to say that cutesiness is 1336, but it&#8217;s a relatively subtle remark.<br />
Thank you, Culprit, I couldn&#8217;t agree more.<br />
And thank you as well, Mark. I smiled broadly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Curphey</title>
		<link>http://emergentchaos.com/archives/2007/02/lets-stop-cutesy-names-for-attacks.html/comment-page-1#comment-3244</link>
		<dc:creator>Mark Curphey</dc:creator>
		<pubDate>Thu, 15 Feb 2007 17:59:33 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2224#comment-3244</guid>
		<description>A cartoon in your honor sir!
</description>
		<content:encoded><![CDATA[<p>A cartoon in your honor sir!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Culprit</title>
		<link>http://emergentchaos.com/archives/2007/02/lets-stop-cutesy-names-for-attacks.html/comment-page-1#comment-3243</link>
		<dc:creator>Culprit</dc:creator>
		<pubDate>Thu, 15 Feb 2007 17:35:03 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2224#comment-3243</guid>
		<description>Language is an inadequate kludge for communicating ideas we have trapped in our individual minds.
But it is all we have until we evolve selective telepathy or some such.
Learning to use words to communicate without confusion should be every citizen&#039;s duty.
Newspeak-style word-play just allows ideas that are incongruent in everyone&#039;s minds to coalesce together into some sort of mob-rage emotion-driven thoughtlessness.
It is a way of stripping individual thought from people.  Words lose their power, and the only power an individual has in a representativity society comes from words.
Please use language well.  Don&#039;t dilute thought exchanges.
</description>
		<content:encoded><![CDATA[<p>Language is an inadequate kludge for communicating ideas we have trapped in our individual minds.<br />
But it is all we have until we evolve selective telepathy or some such.<br />
Learning to use words to communicate without confusion should be every citizen&#8217;s duty.<br />
Newspeak-style word-play just allows ideas that are incongruent in everyone&#8217;s minds to coalesce together into some sort of mob-rage emotion-driven thoughtlessness.<br />
It is a way of stripping individual thought from people.  Words lose their power, and the only power an individual has in a representativity society comes from words.<br />
Please use language well.  Don&#8217;t dilute thought exchanges.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://emergentchaos.com/archives/2007/02/lets-stop-cutesy-names-for-attacks.html/comment-page-1#comment-3242</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Thu, 15 Feb 2007 16:55:53 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2224#comment-3242</guid>
		<description>So, neologisms aren&#039;t 7337?  :^)
</description>
		<content:encoded><![CDATA[<p>So, neologisms aren&#8217;t 7337?  :^)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
