<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: hack3.txt</title>
	<atom:link href="http://antisec.wordpress.com/2005/12/18/hack3txt/feed/" rel="self" type="application/rss+xml" />
	<link>http://antisec.wordpress.com/2005/12/18/hack3txt/</link>
	<description>spreading eleatic thought among antisecurity professionals</description>
	<lastBuildDate>Fri, 01 Jan 2010 18:16:43 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: syniack</title>
		<link>http://antisec.wordpress.com/2005/12/18/hack3txt/#comment-2766</link>
		<dc:creator>syniack</dc:creator>
		<pubDate>Fri, 07 Aug 2009 18:57:44 +0000</pubDate>
		<guid isPermaLink="false">http://antisec.wordpress.com/2005/12/18/hack3txt/#comment-2766</guid>
		<description>Good job guys you are our voice. that have only one option.... ! fuck them then they listen you :)</description>
		<content:encoded><![CDATA[<p>Good job guys you are our voice. that have only one option&#8230;. ! fuck them then they listen you <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Monarch</title>
		<link>http://antisec.wordpress.com/2005/12/18/hack3txt/#comment-2762</link>
		<dc:creator>Monarch</dc:creator>
		<pubDate>Mon, 13 Jul 2009 20:28:38 +0000</pubDate>
		<guid isPermaLink="false">http://antisec.wordpress.com/2005/12/18/hack3txt/#comment-2762</guid>
		<description>I can&#039;t spend all day reading your rants. I will say this though, it seems you&#039;re just an angry person because you were never rewarded adequately for your work.  Its not anyone else&#039;s fault you can&#039;t market yourself and gain a profit margin from security research.

If you find the market place unfair or fell burnt because no one would buy your cool exploit you have a few options:
1. Fuck off
2. Make your own market
3. Try again</description>
		<content:encoded><![CDATA[<p>I can&#8217;t spend all day reading your rants. I will say this though, it seems you&#8217;re just an angry person because you were never rewarded adequately for your work.  Its not anyone else&#8217;s fault you can&#8217;t market yourself and gain a profit margin from security research.</p>
<p>If you find the market place unfair or fell burnt because no one would buy your cool exploit you have a few options:<br />
1. Fuck off<br />
2. Make your own market<br />
3. Try again</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MFox</title>
		<link>http://antisec.wordpress.com/2005/12/18/hack3txt/#comment-2757</link>
		<dc:creator>MFox</dc:creator>
		<pubDate>Sun, 12 Jul 2009 09:42:14 +0000</pubDate>
		<guid isPermaLink="false">http://antisec.wordpress.com/2005/12/18/hack3txt/#comment-2757</guid>
		<description>&quot;Find an exploit? Okay, get some industry/vendor/manufacturer guys together and get a patch done. Release the patch, and give people some time to patch their systems and then give a full disclosure of the exploit and vulnerabilities.&quot;

SHIT !!! full-bullshit u called out!
that&#039;s WhiteHat bastards&#039; way, u know!?
stop junkin &#039;round!!! why blackhats should release their vulnerabilities for all!?
so, security expert bitches are for just patching what we found ?? and earning lost of money! lol bullshit.
did u heard &#039;bout security paradox?! no? but i heard, read Phrack 64 or 65.
we find bugs, we exploit them, we hack them, then they&#039;ll patch those bugz themselves, if they&#039;re smart ! if no, go to hell. return 0;</description>
		<content:encoded><![CDATA[<p>&#8220;Find an exploit? Okay, get some industry/vendor/manufacturer guys together and get a patch done. Release the patch, and give people some time to patch their systems and then give a full disclosure of the exploit and vulnerabilities.&#8221;</p>
<p>SHIT !!! full-bullshit u called out!<br />
that&#8217;s WhiteHat bastards&#8217; way, u know!?<br />
stop junkin &#8217;round!!! why blackhats should release their vulnerabilities for all!?<br />
so, security expert bitches are for just patching what we found ?? and earning lost of money! lol bullshit.<br />
did u heard &#8217;bout security paradox?! no? but i heard, read Phrack 64 or 65.<br />
we find bugs, we exploit them, we hack them, then they&#8217;ll patch those bugz themselves, if they&#8217;re smart ! if no, go to hell. return 0;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Regina</title>
		<link>http://antisec.wordpress.com/2005/12/18/hack3txt/#comment-2746</link>
		<dc:creator>Regina</dc:creator>
		<pubDate>Sat, 11 Jul 2009 17:25:54 +0000</pubDate>
		<guid isPermaLink="false">http://antisec.wordpress.com/2005/12/18/hack3txt/#comment-2746</guid>
		<description>Guys, I have a question for your philosophy of non-disclosure.

Sure, I agree with you that all that the bastard corporations and banks care about is their shit bottom line. One detailed look at how loans and mortgages are structured and you see how hey suck every last dime out of people all while wearing a pleasant little smile. Hey, I don&#039;t mind if you (banks) suck people dry, but at least have to balls to be upfront about it.

In the case you guys are championing though, I have hit a snag.

Why don&#039;t you guys promote delayed full-disclosure instead of non-disclosure?

Find an exploit? Okay, get some industry/vendor/manufacturer guys together and get a patch done. Release the patch, and give people some time to patch their systems and then give a full disclosure of the exploit and vulnerabilities.

I mean if the Network Admins don&#039;t patch up their systems in time, hey it&#039;s their own freaking fault. You were notified, you were given time and you are paid to do your job but yet you sit around not securing the very networks you&#039;re paid to manage? Well, you deserve the attacks.

Let&#039;s all not be naive here, full-disclosure or no-disclosure, the information is going to leak out and spread through underground hacker networks, USENET, VPNs and all kinds of other non-visible links whether you like it or not. And if this information is not openly disclosed, the people out there are going to be ignorant about it and take no preventative steps to mitigate widespread disaster.

So guys, tell me. Why not support delayed-full-disclosure?</description>
		<content:encoded><![CDATA[<p>Guys, I have a question for your philosophy of non-disclosure.</p>
<p>Sure, I agree with you that all that the bastard corporations and banks care about is their shit bottom line. One detailed look at how loans and mortgages are structured and you see how hey suck every last dime out of people all while wearing a pleasant little smile. Hey, I don&#8217;t mind if you (banks) suck people dry, but at least have to balls to be upfront about it.</p>
<p>In the case you guys are championing though, I have hit a snag.</p>
<p>Why don&#8217;t you guys promote delayed full-disclosure instead of non-disclosure?</p>
<p>Find an exploit? Okay, get some industry/vendor/manufacturer guys together and get a patch done. Release the patch, and give people some time to patch their systems and then give a full disclosure of the exploit and vulnerabilities.</p>
<p>I mean if the Network Admins don&#8217;t patch up their systems in time, hey it&#8217;s their own freaking fault. You were notified, you were given time and you are paid to do your job but yet you sit around not securing the very networks you&#8217;re paid to manage? Well, you deserve the attacks.</p>
<p>Let&#8217;s all not be naive here, full-disclosure or no-disclosure, the information is going to leak out and spread through underground hacker networks, USENET, VPNs and all kinds of other non-visible links whether you like it or not. And if this information is not openly disclosed, the people out there are going to be ignorant about it and take no preventative steps to mitigate widespread disaster.</p>
<p>So guys, tell me. Why not support delayed-full-disclosure?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jhonny</title>
		<link>http://antisec.wordpress.com/2005/12/18/hack3txt/#comment-394</link>
		<dc:creator>jhonny</dc:creator>
		<pubDate>Fri, 09 Feb 2007 01:12:30 +0000</pubDate>
		<guid isPermaLink="false">http://antisec.wordpress.com/2005/12/18/hack3txt/#comment-394</guid>
		<description>dfdf</description>
		<content:encoded><![CDATA[<p>dfdf</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: antisec</title>
		<link>http://antisec.wordpress.com/2005/12/18/hack3txt/#comment-3</link>
		<dc:creator>antisec</dc:creator>
		<pubDate>Tue, 20 Dec 2005 16:22:54 +0000</pubDate>
		<guid isPermaLink="false">http://antisec.wordpress.com/2005/12/18/hack3txt/#comment-3</guid>
		<description>&quot;What about organisations you support? While too many are silly corporations, surely you recognise the need for defense?&quot;

The root of the ethical problems in the whitehat community come with what they&#039;re defending. What is it that defense really defends? Do we really want to be defending corporate empires that have been built on injustice, totalitarian countries that regularly topple democracies and slaughter the innocent, and barely legitimate enterprises with links to organized crime?

&quot;What if a NGO doing good work wanted to solicit donations via a webpage? Why should they have to hire a security expert?&quot;

They shouldn&#039;t. As far as I&#039;m concerned, forcing them to buy security &quot;solutions&quot; that fix problems that only exist because the security industry forces the disclosure of exploits is a form of extortion.

&quot;Not everyone in the whitehat community serves corporate interests&quot;

Disclosure of any sort to commercial entities is serving corporate interests. If your systems are insecure, fix the problem and don&#039;t leak to any vendor that&#039;s not an free software product.

&quot;Building on the work of people smarter than you (actually building not copying) is how knowledge gets developed all over the place.&quot;

It&#039;s funny that the patent machine seems to reward the corporate oligarchy but not independent researchers. I spent many years developing exploits and exploitation techniques in good faith. Then I figured out that the entire intellectual property rights game is rigged and have been better off since. I want Chris Klaus and Al Huger to give a cut of all revenue to the people that made their business for them.

Open your eyes and stop being a slave.</description>
		<content:encoded><![CDATA[<p>&#8220;What about organisations you support? While too many are silly corporations, surely you recognise the need for defense?&#8221;</p>
<p>The root of the ethical problems in the whitehat community come with what they&#8217;re defending. What is it that defense really defends? Do we really want to be defending corporate empires that have been built on injustice, totalitarian countries that regularly topple democracies and slaughter the innocent, and barely legitimate enterprises with links to organized crime?</p>
<p>&#8220;What if a NGO doing good work wanted to solicit donations via a webpage? Why should they have to hire a security expert?&#8221;</p>
<p>They shouldn&#8217;t. As far as I&#8217;m concerned, forcing them to buy security &#8220;solutions&#8221; that fix problems that only exist because the security industry forces the disclosure of exploits is a form of extortion.</p>
<p>&#8220;Not everyone in the whitehat community serves corporate interests&#8221;</p>
<p>Disclosure of any sort to commercial entities is serving corporate interests. If your systems are insecure, fix the problem and don&#8217;t leak to any vendor that&#8217;s not an free software product.</p>
<p>&#8220;Building on the work of people smarter than you (actually building not copying) is how knowledge gets developed all over the place.&#8221;</p>
<p>It&#8217;s funny that the patent machine seems to reward the corporate oligarchy but not independent researchers. I spent many years developing exploits and exploitation techniques in good faith. Then I figured out that the entire intellectual property rights game is rigged and have been better off since. I want Chris Klaus and Al Huger to give a cut of all revenue to the people that made their business for them.</p>
<p>Open your eyes and stop being a slave.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dominic White</title>
		<link>http://antisec.wordpress.com/2005/12/18/hack3txt/#comment-2</link>
		<dc:creator>Dominic White</dc:creator>
		<pubDate>Tue, 20 Dec 2005 16:04:17 +0000</pubDate>
		<guid isPermaLink="false">http://antisec.wordpress.com/2005/12/18/hack3txt/#comment-2</guid>
		<description>What about organisations you support? While too many are silly corporations, surely you recognise the need for defense?

What if a NGO doing good work wanted to solicit donations via a webpage? Why should they have to hire a security expert?

Not everyone in the whitehat community serves corporate interests, and not everyone thinks they are the smartest. Building on the work of people smarter than you (actually building not copying) is how knowledge gets developed all over the place.</description>
		<content:encoded><![CDATA[<p>What about organisations you support? While too many are silly corporations, surely you recognise the need for defense?</p>
<p>What if a NGO doing good work wanted to solicit donations via a webpage? Why should they have to hire a security expert?</p>
<p>Not everyone in the whitehat community serves corporate interests, and not everyone thinks they are the smartest. Building on the work of people smarter than you (actually building not copying) is how knowledge gets developed all over the place.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
