<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.11" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Keeping up with the Jones&#8217; Security Initiatives</title>
	<link>http://www.cigital.com/justiceleague/2007/02/22/keeping-up-with-the-jones-security-initiatives/</link>
	<description>The Cigital Software Security and Quality Blog</description>
	<pubDate>Fri, 16 May 2008 02:59:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.11</generator>

	<item>
		<title>by: gem</title>
		<link>http://www.cigital.com/justiceleague/2007/02/22/keeping-up-with-the-jones-security-initiatives/#comment-348</link>
		<pubDate>Fri, 20 Apr 2007 19:11:33 +0000</pubDate>
		<guid>http://www.cigital.com/justiceleague/2007/02/22/keeping-up-with-the-jones-security-initiatives/#comment-348</guid>
					<description>There was no silver bullet for security until last year.  Now, thankfully, there is one:

www.cigital.com/silverbullet

Slightly less ridiculously, I agree with you about spreading knowledge, so the title of my podcast series may have a tiny little core of truth to it.

gem</description>
		<content:encoded><![CDATA[<p>There was no silver bullet for security until last year.  Now, thankfully, there is one:</p>
<p><a href="http://www.cigital.com/silverbullet" rel="nofollow">www.cigital.com/silverbullet</a></p>
<p>Slightly less ridiculously, I agree with you about spreading knowledge, so the title of my podcast series may have a tiny little core of truth to it.</p>
<p>gem
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Iang (Market for Silver Bullets)</title>
		<link>http://www.cigital.com/justiceleague/2007/02/22/keeping-up-with-the-jones-security-initiatives/#comment-316</link>
		<pubDate>Wed, 18 Apr 2007 09:55:42 +0000</pubDate>
		<guid>http://www.cigital.com/justiceleague/2007/02/22/keeping-up-with-the-jones-security-initiatives/#comment-316</guid>
					<description>&lt;blockquote&gt; “Is the Jones family really the goal?” I asked myself. &lt;/blockquote&gt;

The reason that security people do what their competitors are doing is because they cannot explain what is right and proper. In such an environment, they have to CYA by doing _best practices_ which naturally emerge to be a standard set (it doesn't matter what the best practices are, only that they exist). Best practices secures the jobs of the security people, because there is nothing, apparently, better that they can do. Problem solved.

(I call this the market in silver bullets.)

The underlying problem then becomes one of knowing what security is and how to improve that knowledge. For this reason, secondary disclosure of breaches is very interesting; if we can disclose our breaches to our competitors, then our knowledge can improve.

Unfortunately, breach disclosure suffers from a prisoner's dilemma, as we only benefit if we all exchange the information, and we don't lose if we cheat.</description>
		<content:encoded><![CDATA[<blockquote><p> “Is the Jones family really the goal?” I asked myself. </p></blockquote>
<p>The reason that security people do what their competitors are doing is because they cannot explain what is right and proper. In such an environment, they have to CYA by doing _best practices_ which naturally emerge to be a standard set (it doesn&#8217;t matter what the best practices are, only that they exist). Best practices secures the jobs of the security people, because there is nothing, apparently, better that they can do. Problem solved.</p>
<p>(I call this the market in silver bullets.)</p>
<p>The underlying problem then becomes one of knowing what security is and how to improve that knowledge. For this reason, secondary disclosure of breaches is very interesting; if we can disclose our breaches to our competitors, then our knowledge can improve.</p>
<p>Unfortunately, breach disclosure suffers from a prisoner&#8217;s dilemma, as we only benefit if we all exchange the information, and we don&#8217;t lose if we cheat.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: 1 Raindrop</title>
		<link>http://www.cigital.com/justiceleague/2007/02/22/keeping-up-with-the-jones-security-initiatives/#comment-3</link>
		<pubDate>Thu, 01 Mar 2007 20:16:12 +0000</pubDate>
		<guid>http://www.cigital.com/justiceleague/2007/02/22/keeping-up-with-the-jones-security-initiatives/#comment-3</guid>
					<description>&lt;strong&gt;Justice League blog&lt;/strong&gt;

I am happy to see that my friends at Cigital have started a blog called Justice League focsuing on software security and quality. Cigital is one security company that has always recognized that pinning your security hopes on a magic device or widget do...</description>
		<content:encoded><![CDATA[<p><strong>Justice League blog</strong></p>
<p>I am happy to see that my friends at Cigital have started a blog called Justice League focsuing on software security and quality. Cigital is one security company that has always recognized that pinning your security hopes on a magic device or widget do&#8230;
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
