<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Sorry, I No Speak (Security) &#8230;</title>
	<atom:link href="http://blog.impactalabs.com/2009/10/22/i-no-speak-securit/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.impactalabs.com/2009/10/22/i-no-speak-securit/</link>
	<description></description>
	<lastBuildDate>Sun, 06 Jun 2010 23:16:06 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Kevin Lam (IMPACTA)</title>
		<link>http://blog.impactalabs.com/2009/10/22/i-no-speak-securit/#comment-187</link>
		<dc:creator>Kevin Lam (IMPACTA)</dc:creator>
		<pubDate>Fri, 23 Oct 2009 05:45:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.impactalabs.com/?p=456#comment-187</guid>
		<description>Hey David,

Great to hear from you, hope all is well.  Indeed, the bigger the picture the security person has of things going outside of their box the better.  I am also glad you pointed out the need to provide advice that&#039;s actionable (it&#039;s one thing to tell someone they have a problem, but it&#039;s another to provide them with a solution). Thanks for taking the time to share your thoughts!

--Kevin</description>
		<content:encoded><![CDATA[<p>Hey David,</p>
<p>Great to hear from you, hope all is well.  Indeed, the bigger the picture the security person has of things going outside of their box the better.  I am also glad you pointed out the need to provide advice that&#8217;s actionable (it&#8217;s one thing to tell someone they have a problem, but it&#8217;s another to provide them with a solution). Thanks for taking the time to share your thoughts!</p>
<p>&#8211;Kevin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David LeBlanc</title>
		<link>http://blog.impactalabs.com/2009/10/22/i-no-speak-securit/#comment-186</link>
		<dc:creator>David LeBlanc</dc:creator>
		<pubDate>Fri, 23 Oct 2009 00:30:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.impactalabs.com/?p=456#comment-186</guid>
		<description>Interesting post - something I&#039;ve also observed is that if the security people aren&#039;t also developers - and not just developers, but people who ship code - then they&#039;re likely thinking about security in isolation. The developer is thinking schedule, perf, risk of regression, feature backlog, localization, making everything run on some number of platforms and/or browsers, AND security.

If the security person isn&#039;t in tune with the full range of the effects of their suggestions - features cut, schedule slipped, etc - then the developer might just flip the bozo bit, and now the security person sounds like Charlie Brown&#039;s teacher - BLAH, BLAH, BLAH...

As security people, we need to give advice that&#039;s actionable, takes into account the full range of issues the developer faces, and helps them deal with the biggest problems first.</description>
		<content:encoded><![CDATA[<p>Interesting post &#8211; something I&#8217;ve also observed is that if the security people aren&#8217;t also developers &#8211; and not just developers, but people who ship code &#8211; then they&#8217;re likely thinking about security in isolation. The developer is thinking schedule, perf, risk of regression, feature backlog, localization, making everything run on some number of platforms and/or browsers, AND security.</p>
<p>If the security person isn&#8217;t in tune with the full range of the effects of their suggestions &#8211; features cut, schedule slipped, etc &#8211; then the developer might just flip the bozo bit, and now the security person sounds like Charlie Brown&#8217;s teacher &#8211; BLAH, BLAH, BLAH&#8230;</p>
<p>As security people, we need to give advice that&#8217;s actionable, takes into account the full range of issues the developer faces, and helps them deal with the biggest problems first.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
