<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Show 027 &#8211; An Interview with Gunnar Peterson</title>
	<atom:link href="http://www.cigital.com/silver-bullet/show-027/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cigital.com/silver-bullet/show-027/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=show-027</link>
	<description>Cigital CTO Gary McGraw discusses software security with security gurus.</description>
	<lastBuildDate>Tue, 30 Apr 2013 17:12:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Stephen Craig Evans</title>
		<link>http://www.cigital.com/silver-bullet/show-027/#comment-80</link>
		<dc:creator>Stephen Craig Evans</dc:creator>
		<pubDate>Fri, 20 Jun 2008 03:16:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-027/#comment-80</guid>
		<description><![CDATA[A great catch Gary (fishing pun intended) and Gunnar your blog is in my Top 5 list; nary a second was wasted...
What struck me immediately after the podcast (and maybe I should think about this more before possibly making a fool out of myself):
If we are doing such a bad job and spending so much effort on Web 1.0 prevention mechanisms and techniques, and Web 2.0 is here with Web 3.0 on its way, why don&#039;t we just say &quot;screw it&quot;, throw out all the Web 1.0 security stuff out the window, and focus all of our efforts at the data level, meaning architect and implement ALL of our applications using WS-*, SAML, SOA, Federated Identity, etc. ?]]></description>
		<content:encoded><![CDATA[<p>A great catch Gary (fishing pun intended) and Gunnar your blog is in my Top 5 list; nary a second was wasted&#8230;<br />
What struck me immediately after the podcast (and maybe I should think about this more before possibly making a fool out of myself):<br />
If we are doing such a bad job and spending so much effort on Web 1.0 prevention mechanisms and techniques, and Web 2.0 is here with Web 3.0 on its way, why don&#8217;t we just say &#8220;screw it&#8221;, throw out all the Web 1.0 security stuff out the window, and focus all of our efforts at the data level, meaning architect and implement ALL of our applications using WS-*, SAML, SOA, Federated Identity, etc. ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gunnar</title>
		<link>http://www.cigital.com/silver-bullet/show-027/#comment-79</link>
		<dc:creator>Gunnar</dc:creator>
		<pubDate>Thu, 19 Jun 2008 01:35:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-027/#comment-79</guid>
		<description><![CDATA[Hi Gary,

Two more thoughts to keep in mind, both from David Gelernter
http://www.edge.org/documents/archive/edge70.html

First, in terms of where SOA and Web 2.0 are leading:

&quot;If a million people use a Web site simultaneously, doesn&#039;t that mean that we must have a heavy-duty remote server to keep them all happy? No; we could move the site onto a million desktops and use the internet for coordination. The &quot;site&quot; is like a military unit in the field, the general moving with his troops (or like a hockey team in constant swarming motion). (We used essentially this technique to build the first tuple space implementations. They seemed to depend on a shared server, but the server was an illusion; there was no server, just a swarm of clients.) Could Amazon.com be an itinerant horde instead of a fixed Central Command Post? Yes.&quot;

Next, further amplification of the matrix problem you stated:

&quot;If you have three pet dogs, give them names. If you have 10,000 head of cattle, don&#039;t bother. Nowadays the idea of giving a name to every file on your computer is ridiculous.&quot;]]></description>
		<content:encoded><![CDATA[<p>Hi Gary,</p>
<p>Two more thoughts to keep in mind, both from David Gelernter<br />
<a href="http://www.edge.org/documents/archive/edge70.html" rel="nofollow">http://www.edge.org/documents/archive/edge70.html</a></p>
<p>First, in terms of where SOA and Web 2.0 are leading:</p>
<p>&#8220;If a million people use a Web site simultaneously, doesn&#8217;t that mean that we must have a heavy-duty remote server to keep them all happy? No; we could move the site onto a million desktops and use the internet for coordination. The &#8220;site&#8221; is like a military unit in the field, the general moving with his troops (or like a hockey team in constant swarming motion). (We used essentially this technique to build the first tuple space implementations. They seemed to depend on a shared server, but the server was an illusion; there was no server, just a swarm of clients.) Could Amazon.com be an itinerant horde instead of a fixed Central Command Post? Yes.&#8221;</p>
<p>Next, further amplification of the matrix problem you stated:</p>
<p>&#8220;If you have three pet dogs, give them names. If you have 10,000 head of cattle, don&#8217;t bother. Nowadays the idea of giving a name to every file on your computer is ridiculous.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 1 Raindrop</title>
		<link>http://www.cigital.com/silver-bullet/show-027/#comment-78</link>
		<dc:creator>1 Raindrop</dc:creator>
		<pubDate>Wed, 18 Jun 2008 19:01:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-027/#comment-78</guid>
		<description><![CDATA[&lt;strong&gt;Silver Bullet Security Podcast&lt;/strong&gt;

I did a podcast with Gary McGraw which is available here. Gary&#039;s questions were great, I could have written a ten page whitepaper in response to most of them, but tried to sum up my thoughts on &quot;what is security&quot;, and how you might approach security...]]></description>
		<content:encoded><![CDATA[<p><strong>Silver Bullet Security Podcast</strong></p>
<p>I did a podcast with Gary McGraw which is available here. Gary&#8217;s questions were great, I could have written a ten page whitepaper in response to most of them, but tried to sum up my thoughts on &#8220;what is security&#8221;, and how you might approach security&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
