<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Do We Really Need a Security Industry?</title>
	<atom:link href="http://www.gnucitizen.org/blog/do-we-really-need-a-security-industry/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/do-we-really-need-a-security-industry/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/do-we-really-need-a-security-industry/comment-page-1/#comment-20546</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 09 May 2007 08:32:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/do-we-really-need-a-security-industry#comment-20546</guid>
		<description>Gar, here is an interesting though for you...

&lt;blockquote&gt;Security is a process not a destination.&lt;/blockquote&gt;</description>
		<content:encoded><![CDATA[<p>Gar, here is an interesting though for you&#8230;</p>
<blockquote><p>Security is a process not a destination.</p></blockquote>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gar</title>
		<link>http://www.gnucitizen.org/blog/do-we-really-need-a-security-industry/comment-page-1/#comment-20493</link>
		<dc:creator>Gar</dc:creator>
		<pubDate>Wed, 09 May 2007 03:49:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/do-we-really-need-a-security-industry#comment-20493</guid>
		<description>Let me be the devil&#039;s advocate here.

What is wrong with the security industry is that  much of it - think antiviruses - tries to mitigate problems that happened.

Now there is a very good reason for that: pointy-haired bosses are blissfully unaware of how secure their products are, and are therefore unable to wisely spend money on their own products&#039; security. But they will have problems, and they will spend a pot of money in trying to fix the problems once they are discovered.

I don&#039;t know if our economy (market forces, whatever) will be able to head into the distant future Schneier describes, where the security industry can&#039;t be told apart from the software industry. Still, I&#039;d consider the security industry a failure if it doesn&#039;t happen.</description>
		<content:encoded><![CDATA[<p>Let me be the devil&#8217;s advocate here.</p>
<p>What is wrong with the security industry is that  much of it &#8211; think antiviruses &#8211; tries to mitigate problems that happened.</p>
<p>Now there is a very good reason for that: pointy-haired bosses are blissfully unaware of how secure their products are, and are therefore unable to wisely spend money on their own products&#8217; security. But they will have problems, and they will spend a pot of money in trying to fix the problems once they are discovered.</p>
<p>I don&#8217;t know if our economy (market forces, whatever) will be able to head into the distant future Schneier describes, where the security industry can&#8217;t be told apart from the software industry. Still, I&#8217;d consider the security industry a failure if it doesn&#8217;t happen.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Kierznowski</title>
		<link>http://www.gnucitizen.org/blog/do-we-really-need-a-security-industry/comment-page-1/#comment-19922</link>
		<dc:creator>David Kierznowski</dc:creator>
		<pubDate>Sun, 06 May 2007 00:58:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/do-we-really-need-a-security-industry#comment-19922</guid>
		<description>In most cases all these things come down to money and not ethics - this is what I picked up from Bruce&#039;s post.

The major driving force behind security has always been fear. Why install alarms around your house, because it looks pretty?

The security industry thrives and booms on fear. What if my company website looks bad after being defaced? what if our customers information is disclosed to the Internet? What if corporate and government secrets are stolen? 

What drives the fear? Ultimately I belive its money in the form of credibility. If this makes us look bad we lose customers and therefore lose money.

As long as there are bad guys doing bad things, the security industry will be around. If they really wanted to hinder progress, they shouldn&#039;t do anything at all and be patient.</description>
		<content:encoded><![CDATA[<p>In most cases all these things come down to money and not ethics &#8211; this is what I picked up from Bruce&#8217;s post.</p>
<p>The major driving force behind security has always been fear. Why install alarms around your house, because it looks pretty?</p>
<p>The security industry thrives and booms on fear. What if my company website looks bad after being defaced? what if our customers information is disclosed to the Internet? What if corporate and government secrets are stolen? </p>
<p>What drives the fear? Ultimately I belive its money in the form of credibility. If this makes us look bad we lose customers and therefore lose money.</p>
<p>As long as there are bad guys doing bad things, the security industry will be around. If they really wanted to hinder progress, they shouldn&#8217;t do anything at all and be patient.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RobotSkirts &#187; Blog Archive &#187; Schneier on Security: Do We Really Need a Security Industry?</title>
		<link>http://www.gnucitizen.org/blog/do-we-really-need-a-security-industry/comment-page-1/#comment-19749</link>
		<dc:creator>RobotSkirts &#187; Blog Archive &#187; Schneier on Security: Do We Really Need a Security Industry?</dc:creator>
		<pubDate>Fri, 04 May 2007 20:18:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/do-we-really-need-a-security-industry#comment-19749</guid>
		<description>[...] Schneier&#8217;s Do We Really Need a Security Industry? has predictably started a firestorm. Responses from: Kaminsky, Bejtlich, and pdp. [...]</description>
		<content:encoded><![CDATA[<p>[...] Schneier&#8217;s Do We Really Need a Security Industry? has predictably started a firestorm. Responses from: Kaminsky, Bejtlich, and pdp. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aodhhan</title>
		<link>http://www.gnucitizen.org/blog/do-we-really-need-a-security-industry/comment-page-1/#comment-19746</link>
		<dc:creator>Aodhhan</dc:creator>
		<pubDate>Fri, 04 May 2007 19:46:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/do-we-really-need-a-security-industry#comment-19746</guid>
		<description>First time I&#039;ve heard of him. After reading his column I know why.
He obviously lacks any detailed education with tcp/ip, software development/reverse engineering, defense in depth, and the all powerful malicious insider. 
...Or perhaps he was drinking.</description>
		<content:encoded><![CDATA[<p>First time I&#8217;ve heard of him. After reading his column I know why.<br />
He obviously lacks any detailed education with tcp/ip, software development/reverse engineering, defense in depth, and the all powerful malicious insider.<br />
&#8230;Or perhaps he was drinking.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
