<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: MacOS X Vulnerability Metrics: Apple vs. The World</title>
	<atom:link href="http://trailofbits.com/2008/05/29/macos-x-vulnerability-metrics-apple-vs-the-world/feed/" rel="self" type="application/rss+xml" />
	<link>http://trailofbits.com/2008/05/29/macos-x-vulnerability-metrics-apple-vs-the-world/</link>
	<description>4888 C3C4 099A 4240 9648  719B 84E0 A6FE 32AE 38F6</description>
	<lastBuildDate>Mon, 02 May 2011 23:50:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Dino Dai Zovi</title>
		<link>http://trailofbits.com/2008/05/29/macos-x-vulnerability-metrics-apple-vs-the-world/#comment-13</link>
		<dc:creator><![CDATA[Dino Dai Zovi]]></dc:creator>
		<pubDate>Fri, 30 May 2008 05:31:44 +0000</pubDate>
		<guid isPermaLink="false">http://trailofbits.wordpress.com/?p=14#comment-13</guid>
		<description><![CDATA[@ShawnM
I have heard of external researchers not being credited and other vendors have refused to credit me for reported vulnerabilities before.  But it&#039;s hard to believe that all of the unaccredited vulnerabilities are due to denied credit.  Another possibility is that those bugs were discovered being exploited in the wild or from found exploits, but that also seems unlikely.

Custom security patches like PaX and GrSec for Darwin would be pretty darn cool...]]></description>
		<content:encoded><![CDATA[<p>@ShawnM<br />
I have heard of external researchers not being credited and other vendors have refused to credit me for reported vulnerabilities before.  But it&#8217;s hard to believe that all of the unaccredited vulnerabilities are due to denied credit.  Another possibility is that those bugs were discovered being exploited in the wild or from found exploits, but that also seems unlikely.</p>
<p>Custom security patches like PaX and GrSec for Darwin would be pretty darn cool&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ShawnM</title>
		<link>http://trailofbits.com/2008/05/29/macos-x-vulnerability-metrics-apple-vs-the-world/#comment-12</link>
		<dc:creator><![CDATA[ShawnM]]></dc:creator>
		<pubDate>Fri, 30 May 2008 05:12:50 +0000</pubDate>
		<guid isPermaLink="false">http://trailofbits.wordpress.com/?p=14#comment-12</guid>
		<description><![CDATA[Of course, door number three is that external researchers aren&#039;t necessarily always credited... Stranger things have happened, yesno? 

Still, I think Cupertino is turning a corner. Still have a way to go but yes, it seems to me they are making an effort. That said the recent CoreSec iMail disclosure is pretty embarassing. 4 months isn&#039;t that far off from HP / SnoSoft BITD...

/me loves shiny bits and a Bash prompt with transparent XTerms but is sticking with PaX+GrSec and $LINUX_DISTRO for now.]]></description>
		<content:encoded><![CDATA[<p>Of course, door number three is that external researchers aren&#8217;t necessarily always credited&#8230; Stranger things have happened, yesno? </p>
<p>Still, I think Cupertino is turning a corner. Still have a way to go but yes, it seems to me they are making an effort. That said the recent CoreSec iMail disclosure is pretty embarassing. 4 months isn&#8217;t that far off from HP / SnoSoft BITD&#8230;</p>
<p>/me loves shiny bits and a Bash prompt with transparent XTerms but is sticking with PaX+GrSec and $LINUX_DISTRO for now.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

