<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: On Security Vulnerabilities</title>
	<atom:link href="http://kveton.com/blog/2006/11/26/on-security-vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://kveton.com/blog/2006/11/26/on-security-vulnerabilities/</link>
	<description>Father, entrepreneur, pizza maker &#38; bacon lover</description>
	<lastBuildDate>Mon, 22 Feb 2010 20:18:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: j3h</title>
		<link>http://kveton.com/blog/2006/11/26/on-security-vulnerabilities/comment-page-1/#comment-3393</link>
		<dc:creator>j3h</dc:creator>
		<pubDate>Mon, 27 Nov 2006 21:37:38 +0000</pubDate>
		<guid isPermaLink="false">http://kveton.com/blog/2006/11/26/on-security-vulnerabilities/#comment-3393</guid>
		<description>We have just made a release that changes the behavior so that it rejects sign-ups even if the entered credentials match an existing account. This should make the sign-up process less confusing if people are testing it.</description>
		<content:encoded><![CDATA[<p>We have just made a release that changes the behavior so that it rejects sign-ups even if the entered credentials match an existing account. This should make the sign-up process less confusing if people are testing it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kveton</title>
		<link>http://kveton.com/blog/2006/11/26/on-security-vulnerabilities/comment-page-1/#comment-3387</link>
		<dc:creator>kveton</dc:creator>
		<pubDate>Mon, 27 Nov 2006 15:44:11 +0000</pubDate>
		<guid isPermaLink="false">http://kveton.com/blog/2006/11/26/on-security-vulnerabilities/#comment-3387</guid>
		<description>For the very reason that you have not given me any cause to do so.  From previous experience, I&#039;m not convinced you could do a thorough analysis.

I&#039;m sorry we didn&#039;t get back to you as quickly as we normally respond to such events.  However, the timing of these events were correct, we simply failed to notify you in a timely fashion.

You continue to question my integrity at every opportunity and yet you have not shown one bit of proof of a security vulnerability.</description>
		<content:encoded><![CDATA[<p>For the very reason that you have not given me any cause to do so.  From previous experience, I&#8217;m not convinced you could do a thorough analysis.</p>
<p>I&#8217;m sorry we didn&#8217;t get back to you as quickly as we normally respond to such events.  However, the timing of these events were correct, we simply failed to notify you in a timely fashion.</p>
<p>You continue to question my integrity at every opportunity and yet you have not shown one bit of proof of a security vulnerability.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dmitry Shechtman</title>
		<link>http://kveton.com/blog/2006/11/26/on-security-vulnerabilities/comment-page-1/#comment-3386</link>
		<dc:creator>Dmitry Shechtman</dc:creator>
		<pubDate>Mon, 27 Nov 2006 10:57:46 +0000</pubDate>
		<guid isPermaLink="false">http://kveton.com/blog/2006/11/26/on-security-vulnerabilities/#comment-3386</guid>
		<description>Full disclosure is open source to me. Why didn&#039;t you agree to open your code repository, not even under NDA?

And &lt;a href=&quot;http://test.phpbb.cc/viewtopic.php?p=78#p78&quot; rel=&quot;nofollow&quot;&gt;what&#039;s wrong with your clock?&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Full disclosure is open source to me. Why didn&#8217;t you agree to open your code repository, not even under NDA?</p>
<p>And <a href="http://test.phpbb.cc/viewtopic.php?p=78#p78" rel="nofollow">what&#8217;s wrong with your clock?</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kveton</title>
		<link>http://kveton.com/blog/2006/11/26/on-security-vulnerabilities/comment-page-1/#comment-3371</link>
		<dc:creator>kveton</dc:creator>
		<pubDate>Sun, 26 Nov 2006 21:41:55 +0000</pubDate>
		<guid isPermaLink="false">http://kveton.com/blog/2006/11/26/on-security-vulnerabilities/#comment-3371</guid>
		<description>That wasn&#039;t the only place you made that public claim:

http://startrekguide.com/forum/viewtopic.php?p=12128

We take security seriously here so we respond to any and all questions about the quality of the services we provide.  Test site or otherwise, people might happen upon that site via Google and not know its a test site.  I&#039;d rather err on the side of full-disclosure and discussion than not.

Thanks for the post Dmitry!</description>
		<content:encoded><![CDATA[<p>That wasn&#8217;t the only place you made that public claim:</p>
<p><a href="http://startrekguide.com/forum/viewtopic.php?p=12128" rel="nofollow">http://startrekguide.com/forum/viewtopic.php?p=12128</a></p>
<p>We take security seriously here so we respond to any and all questions about the quality of the services we provide.  Test site or otherwise, people might happen upon that site via Google and not know its a test site.  I&#8217;d rather err on the side of full-disclosure and discussion than not.</p>
<p>Thanks for the post Dmitry!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dmitry Shechtman</title>
		<link>http://kveton.com/blog/2006/11/26/on-security-vulnerabilities/comment-page-1/#comment-3370</link>
		<dc:creator>Dmitry Shechtman</dc:creator>
		<pubDate>Sun, 26 Nov 2006 21:36:10 +0000</pubDate>
		<guid isPermaLink="false">http://kveton.com/blog/2006/11/26/on-security-vulnerabilities/#comment-3370</guid>
		<description>As I repeatedly noted in our conversation, a test board hardly counts as an arena for public claims. But since we have gone public with this now, here are a few backlinks:

http://test.phpbb.cc/viewtopic.php?t=37
http://test.phpbb.cc/viewtopic.php?t=38

Vulnerability or not, coverup or not &#151; you are invited to draw your conclusion.</description>
		<content:encoded><![CDATA[<p>As I repeatedly noted in our conversation, a test board hardly counts as an arena for public claims. But since we have gone public with this now, here are a few backlinks:</p>
<p><a href="http://test.phpbb.cc/viewtopic.php?t=37" rel="nofollow">http://test.phpbb.cc/viewtopic.php?t=37</a><br />
<a href="http://test.phpbb.cc/viewtopic.php?t=38" rel="nofollow">http://test.phpbb.cc/viewtopic.php?t=38</a></p>
<p>Vulnerability or not, coverup or not &#8212; you are invited to draw your conclusion.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
