<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Persona Non Grata</title>
	<atom:link href="http://www.randomlyevil.org.uk/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.randomlyevil.org.uk</link>
	<description>Mr Bryn goes to London.</description>
	<lastBuildDate>Thu, 02 Feb 2012 11:37:58 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.4</generator>
	<item>
		<title>Comment on Hacio&#8217;r Iaith &#8211; Hacio beth? &#124; Hacking what? by Dan Q</title>
		<link>http://www.randomlyevil.org.uk/2012/01/23/hacio-beth-hacking-what/comment-page-1/#comment-3432</link>
		<dc:creator>Dan Q</dc:creator>
		<pubDate>Thu, 02 Feb 2012 11:37:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.randomlyevil.org.uk/?p=425#comment-3432</guid>
		<description>Hope it all went well! I&#039;ve done a couple of barcamps over this end of the country and they&#039;ve been fabulous: the philosophy works incredibly well in geeky pastimes because we&#039;re the kind of people who all have fun projects on, and because we&#039;re also the kind of people who are interested in all kinds of different areas. As a result, the unconference nature of a barcamp means that everybody gets to hear interesting things, and be heard on the things that they think might interest others.

Somehow, at the last one I was at, I ran a workshop on getting started with Android development! No idea how that happened!</description>
		<content:encoded><![CDATA[<p>Hope it all went well! I&#8217;ve done a couple of barcamps over this end of the country and they&#8217;ve been fabulous: the philosophy works incredibly well in geeky pastimes because we&#8217;re the kind of people who all have fun projects on, and because we&#8217;re also the kind of people who are interested in all kinds of different areas. As a result, the unconference nature of a barcamp means that everybody gets to hear interesting things, and be heard on the things that they think might interest others.</p>
<p>Somehow, at the last one I was at, I ran a workshop on getting started with Android development! No idea how that happened!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hacio&#8217;r Iaith &#8211; Hacio beth? &#124; Hacking what? by Hacio&#8217;r Iaith 2012 &#124; Gwenu Dan Fysiau</title>
		<link>http://www.randomlyevil.org.uk/2012/01/23/hacio-beth-hacking-what/comment-page-1/#comment-3422</link>
		<dc:creator>Hacio&#8217;r Iaith 2012 &#124; Gwenu Dan Fysiau</dc:creator>
		<pubDate>Wed, 25 Jan 2012 08:53:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.randomlyevil.org.uk/?p=425#comment-3422</guid>
		<description>[...] Dyma gofnod gan Bryn sy&#8217;n esbonio ychydig am drefn digwyddiad o&#8217;r fath. [...]</description>
		<content:encoded><![CDATA[<p>[...] Dyma gofnod gan Bryn sy&#8217;n esbonio ychydig am drefn digwyddiad o&#8217;r fath. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hacio&#8217;r Iaith &#8211; Hacio beth? &#124; Hacking what? by Hacio'r Iaith - Hacio'r Beth? &#124; Hacio&#039;r Iaith</title>
		<link>http://www.randomlyevil.org.uk/2012/01/23/hacio-beth-hacking-what/comment-page-1/#comment-3417</link>
		<dc:creator>Hacio'r Iaith - Hacio'r Beth? &#124; Hacio&#039;r Iaith</dc:creator>
		<pubDate>Mon, 23 Jan 2012 12:45:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.randomlyevil.org.uk/?p=425#comment-3417</guid>
		<description>[...] Hacio&#8217;r Iaith &#8211; Hacio&#8217;r Beth?Ryff geid Bryn Salisbury i wneud y mwyaf o&#8217;ch Hacio&#8217;r Iaith cyntaf &#8211; wedi ei gyhoeddi&#8217;n wreiddiol ar ei flog: Persona Non Grata: Hacio&#8217;r Iaith &#8211; Hacio&#8217;r Beth? &#124; Hacking what?&#8221;. [...]</description>
		<content:encoded><![CDATA[<p>[...] Hacio&#8217;r Iaith &#8211; Hacio&#8217;r Beth?Ryff geid Bryn Salisbury i wneud y mwyaf o&#8217;ch Hacio&#8217;r Iaith cyntaf &#8211; wedi ei gyhoeddi&#8217;n wreiddiol ar ei flog: Persona Non Grata: Hacio&#8217;r Iaith &#8211; Hacio&#8217;r Beth? | Hacking what?&#8221;. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Datblygu Diogel &#124; Secure Development by sioda</title>
		<link>http://www.randomlyevil.org.uk/2011/10/26/datblygu-diogel-secure-development/comment-page-1/#comment-2312</link>
		<dc:creator>sioda</dc:creator>
		<pubDate>Sat, 29 Oct 2011 13:49:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.randomlyevil.org.uk/?p=354#comment-2312</guid>
		<description>I can attest that the comment doesn&#039;t sound at all like Jericho of attrition.org. He would not have been so polite
http://attrition.org/postal/

.sioda,</description>
		<content:encoded><![CDATA[<p>I can attest that the comment doesn&#8217;t sound at all like Jericho of attrition.org. He would not have been so polite<br />
<a href="http://attrition.org/postal/" rel="nofollow">http://attrition.org/postal/</a></p>
<p>.sioda,</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Datblygu Diogel &#124; Secure Development by The Real Jericho</title>
		<link>http://www.randomlyevil.org.uk/2011/10/26/datblygu-diogel-secure-development/comment-page-1/#comment-2310</link>
		<dc:creator>The Real Jericho</dc:creator>
		<pubDate>Fri, 28 Oct 2011 23:51:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.randomlyevil.org.uk/?p=354#comment-2310</guid>
		<description>The comment above from &#039;Jericho&#039; was not done by Jericho of attrition.org. Don&#039;t mind the spoofing, just want to be clear though.</description>
		<content:encoded><![CDATA[<p>The comment above from &#8216;Jericho&#8217; was not done by Jericho of attrition.org. Don&#8217;t mind the spoofing, just want to be clear though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Datblygu Diogel &#124; Secure Development by J4vv4D</title>
		<link>http://www.randomlyevil.org.uk/2011/10/26/datblygu-diogel-secure-development/comment-page-1/#comment-2309</link>
		<dc:creator>J4vv4D</dc:creator>
		<pubDate>Fri, 28 Oct 2011 11:46:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.randomlyevil.org.uk/?p=354#comment-2309</guid>
		<description>Seeing as we&#039;re using analogies within analogies within analogies.

Dan - you&#039;re wrong. 

From a protection perspective let me introduce another analogy.

I know that bullet proof glass will stop a bullet so I have it installed. I don&#039;t need to know how a gun works, the velocity of a bullet, the different types of bullets or anything like that. All I&#039;ll need to know is how to install it properly in the window-frames. Which is in effect what a coder is doing. Installing / building something to the best of their ability.

Fully understanding how attacks work and the methodologies of the bad guys falls under the remit of pen testers.</description>
		<content:encoded><![CDATA[<p>Seeing as we&#8217;re using analogies within analogies within analogies.</p>
<p>Dan &#8211; you&#8217;re wrong. </p>
<p>From a protection perspective let me introduce another analogy.</p>
<p>I know that bullet proof glass will stop a bullet so I have it installed. I don&#8217;t need to know how a gun works, the velocity of a bullet, the different types of bullets or anything like that. All I&#8217;ll need to know is how to install it properly in the window-frames. Which is in effect what a coder is doing. Installing / building something to the best of their ability.</p>
<p>Fully understanding how attacks work and the methodologies of the bad guys falls under the remit of pen testers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Datblygu Diogel &#124; Secure Development by Bryn_S</title>
		<link>http://www.randomlyevil.org.uk/2011/10/26/datblygu-diogel-secure-development/comment-page-1/#comment-2307</link>
		<dc:creator>Bryn_S</dc:creator>
		<pubDate>Thu, 27 Oct 2011 09:16:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.randomlyevil.org.uk/?p=354#comment-2307</guid>
		<description>Thanks Dan, some good points raised. Is it not dependant on who you&#039;re talking to though? You&#039;re an experienced coder, but if you&#039;re new at it, doesn&#039;t a friendlier/positive approach carry more weight? Rather than scaring the poor bugger to death?</description>
		<content:encoded><![CDATA[<p>Thanks Dan, some good points raised. Is it not dependant on who you&#8217;re talking to though? You&#8217;re an experienced coder, but if you&#8217;re new at it, doesn&#8217;t a friendlier/positive approach carry more weight? Rather than scaring the poor bugger to death?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Datblygu Diogel &#124; Secure Development by Dan Q</title>
		<link>http://www.randomlyevil.org.uk/2011/10/26/datblygu-diogel-secure-development/comment-page-1/#comment-2306</link>
		<dc:creator>Dan Q</dc:creator>
		<pubDate>Thu, 27 Oct 2011 09:06:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.randomlyevil.org.uk/?p=354#comment-2306</guid>
		<description>No.

Security engineering is by definition a preventative measure: an effort to stop the bad guys (or just guys with strange names, like little Bobby Tables) from successfully attacking your system. To do this, you &lt;em&gt;must&lt;/em&gt; take the approach of looking at how such attacks work.

To take an example: if you were in charge of training police officers, you wouldn&#039;t spend your time showing them what a well-behaved, law-abiding citizen looks like. It&#039;s no use demonstrating how to &lt;em&gt;not&lt;/em&gt; have to arrest people.

You need to see what the bad things are if you&#039;re going to combat them.</description>
		<content:encoded><![CDATA[<p>No.</p>
<p>Security engineering is by definition a preventative measure: an effort to stop the bad guys (or just guys with strange names, like little Bobby Tables) from successfully attacking your system. To do this, you <em>must</em> take the approach of looking at how such attacks work.</p>
<p>To take an example: if you were in charge of training police officers, you wouldn&#8217;t spend your time showing them what a well-behaved, law-abiding citizen looks like. It&#8217;s no use demonstrating how to <em>not</em> have to arrest people.</p>
<p>You need to see what the bad things are if you&#8217;re going to combat them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Datblygu Diogel &#124; Secure Development by Bryn_S</title>
		<link>http://www.randomlyevil.org.uk/2011/10/26/datblygu-diogel-secure-development/comment-page-1/#comment-2303</link>
		<dc:creator>Bryn_S</dc:creator>
		<pubDate>Wed, 26 Oct 2011 20:22:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.randomlyevil.org.uk/?p=354#comment-2303</guid>
		<description>Jericho - again, sorry... I&#039;ve re-read both the English and Welsh versions, and the English version is a little ambiguous (the Welsh version was a lot clearer). I&#039;ve made a quick edit which should make it a bit clearer.</description>
		<content:encoded><![CDATA[<p>Jericho &#8211; again, sorry&#8230; I&#8217;ve re-read both the English and Welsh versions, and the English version is a little ambiguous (the Welsh version was a lot clearer). I&#8217;ve made a quick edit which should make it a bit clearer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Datblygu Diogel &#124; Secure Development by Bryn_S</title>
		<link>http://www.randomlyevil.org.uk/2011/10/26/datblygu-diogel-secure-development/comment-page-1/#comment-2302</link>
		<dc:creator>Bryn_S</dc:creator>
		<pubDate>Wed, 26 Oct 2011 20:08:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.randomlyevil.org.uk/?p=354#comment-2302</guid>
		<description>Hi Jericho,

Thanks for the comment... I don&#039;t think I was pretending it was my idea at all. I did intact mention to our mutual friend that I was going to put it together as a talk (which he seemed to suggest was a good idea - I&#039;m a little restricted from being quite so overt about naming the people I get to work with). 

Given a lot of my work tends to revolve around helping people with their security programs, I&#039;d like to be able to advise them on the best way of doing things, and if we can get better results through showing people how it should be done, rather than scaring them with how badly it can go wrong, then all the better.

Thanks for the slide references, but I was more keen to use a session as a discussion (rather than a presentation) to crowd-source the ideal solution.</description>
		<content:encoded><![CDATA[<p>Hi Jericho,</p>
<p>Thanks for the comment&#8230; I don&#8217;t think I was pretending it was my idea at all. I did intact mention to our mutual friend that I was going to put it together as a talk (which he seemed to suggest was a good idea &#8211; I&#8217;m a little restricted from being quite so overt about naming the people I get to work with). </p>
<p>Given a lot of my work tends to revolve around helping people with their security programs, I&#8217;d like to be able to advise them on the best way of doing things, and if we can get better results through showing people how it should be done, rather than scaring them with how badly it can go wrong, then all the better.</p>
<p>Thanks for the slide references, but I was more keen to use a session as a discussion (rather than a presentation) to crowd-source the ideal solution.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.312 seconds -->

