<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Commenti a: Pwn2Own 2010: interview with Charlie Miller</title>
	<atom:link href="http://www.oneitsecurity.it/01/03/2010/interview-with-charlie-miller-pwn2own/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.oneitsecurity.it/01/03/2010/interview-with-charlie-miller-pwn2own/</link>
	<description>Blog sulla sicurezza informatica</description>
	<lastBuildDate>Mon, 06 Feb 2012 20:41:10 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
	<item>
		<title>Di: Theresa Richardt</title>
		<link>http://www.oneitsecurity.it/01/03/2010/interview-with-charlie-miller-pwn2own/#comment-2420</link>
		<dc:creator>Theresa Richardt</dc:creator>
		<pubDate>Mon, 20 Jun 2011 09:36:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.oneitsecurity.it/01/03/2010/pwn2own-2010-interview-with-charlie-miller/#comment-2420</guid>
		<description>Great post. I was checking constantly this blog and I am impressed! Very useful information specifically the last part :) I care for such information much. I was seeking this certain info for a very long time. Thank you and best of luck.</description>
		<content:encoded><![CDATA[<p>Great post. I was checking constantly this blog and I am impressed! Very useful information specifically the last part <img src='http://www.oneitsecurity.it/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  I care for such information much. I was seeking this certain info for a very long time. Thank you and best of luck.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Di: Oh For F's Sake</title>
		<link>http://www.oneitsecurity.it/01/03/2010/interview-with-charlie-miller-pwn2own/#comment-2281</link>
		<dc:creator>Oh For F's Sake</dc:creator>
		<pubDate>Sat, 19 Mar 2011 01:19:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.oneitsecurity.it/01/03/2010/pwn2own-2010-interview-with-charlie-miller/#comment-2281</guid>
		<description>ActiveX hasn&#039;t been a problem since IE4. Let me guess? Wikipedia? Firefox Forums? Urban Dictionary?

Don&#039;t even speak of secunia either, they have no system as to how &quot;serious&quot; an exploit is. If I see another &quot;A malicious website can look like a banking site&quot; security report labeled SERIOUS. Hell all their exploits involve you:
A) Being stupid enough to enter personal information on a redirected site.
B) Being stupid enough to visit &quot;unsecure sites&quot; (i.e. pornographic) and give out personal information.
C) Being stupid enough to disable security precautions (yes, one of their exploits involves using a low browser security. It never triggered for me [and I think they had a message asking me to lower security so it would work])
D) Being stupid.

So obviously microsoft won&#039;t bother, I mean... if you&#039;re dumb enough to disable web browser security and get &quot;infected&quot; with bonzo buddy... you obviously shouldn&#039;t be using a computer.

In other words, IE doesn&#039;t have security holes. IT HAS USERS. Firefox is secure ONLY because it makes it very difficult to disable security, while IE lets you do it in a few clicks.


Now IE still isn&#039;t into the whole &quot;browser customization&quot; market, I do believe... so Opera, Firefox, Chrome, w/e... they all support customization (and native Ad Blocking :D). Hence I use Opera... but IE really is just as secure... unlike what you kiddies seem to think.</description>
		<content:encoded><![CDATA[<p>ActiveX hasn&#8217;t been a problem since IE4. Let me guess? Wikipedia? Firefox Forums? Urban Dictionary?</p>
<p>Don&#8217;t even speak of secunia either, they have no system as to how &#8220;serious&#8221; an exploit is. If I see another &#8220;A malicious website can look like a banking site&#8221; security report labeled SERIOUS. Hell all their exploits involve you:<br />
A) Being stupid enough to enter personal information on a redirected site.<br />
B) Being stupid enough to visit &#8220;unsecure sites&#8221; (i.e. pornographic) and give out personal information.<br />
C) Being stupid enough to disable security precautions (yes, one of their exploits involves using a low browser security. It never triggered for me [and I think they had a message asking me to lower security so it would work])<br />
D) Being stupid.</p>
<p>So obviously microsoft won&#8217;t bother, I mean&#8230; if you&#8217;re dumb enough to disable web browser security and get &#8220;infected&#8221; with bonzo buddy&#8230; you obviously shouldn&#8217;t be using a computer.</p>
<p>In other words, IE doesn&#8217;t have security holes. IT HAS USERS. Firefox is secure ONLY because it makes it very difficult to disable security, while IE lets you do it in a few clicks.</p>
<p>Now IE still isn&#8217;t into the whole &#8220;browser customization&#8221; market, I do believe&#8230; so Opera, Firefox, Chrome, w/e&#8230; they all support customization (and native Ad Blocking <img src='http://www.oneitsecurity.it/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> ). Hence I use Opera&#8230; but IE really is just as secure&#8230; unlike what you kiddies seem to think.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Di: Ruvann</title>
		<link>http://www.oneitsecurity.it/01/03/2010/interview-with-charlie-miller-pwn2own/#comment-2267</link>
		<dc:creator>Ruvann</dc:creator>
		<pubDate>Sun, 13 Mar 2011 15:06:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.oneitsecurity.it/01/03/2010/pwn2own-2010-interview-with-charlie-miller/#comment-2267</guid>
		<description>I don&#039;t get the internet explorer recommendation. Serious flaws were the sole reason for attacks last year that made, if i recall correctly, the german government asking people not to use IE until those flaws were fixed. 
It was definitely no secret. That&#039;s just one of the incidents i have heard of concerning weak seacurity in IE. 

I&#039;m no pro or anything but from all the many reports, i believe IE to be the last resort. 
The only thing IE is useful for is using it once to download another browser :-D</description>
		<content:encoded><![CDATA[<p>I don&#8217;t get the internet explorer recommendation. Serious flaws were the sole reason for attacks last year that made, if i recall correctly, the german government asking people not to use IE until those flaws were fixed.<br />
It was definitely no secret. That&#8217;s just one of the incidents i have heard of concerning weak seacurity in IE. </p>
<p>I&#8217;m no pro or anything but from all the many reports, i believe IE to be the last resort.<br />
The only thing IE is useful for is using it once to download another browser <img src='http://www.oneitsecurity.it/wp-includes/images/smilies/icon_biggrin.gif' alt=':-D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Di: Jdashn</title>
		<link>http://www.oneitsecurity.it/01/03/2010/interview-with-charlie-miller-pwn2own/#comment-2256</link>
		<dc:creator>Jdashn</dc:creator>
		<pubDate>Tue, 08 Mar 2011 22:13:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.oneitsecurity.it/01/03/2010/pwn2own-2010-interview-with-charlie-miller/#comment-2256</guid>
		<description>If linux security is a myth why does he not go for breaking linux/FF than OSX/Safari? Wouldnt it be worth the bragging rights seeing as how it&#039;s not been done at Pwn2Own before?</description>
		<content:encoded><![CDATA[<p>If linux security is a myth why does he not go for breaking linux/FF than OSX/Safari? Wouldnt it be worth the bragging rights seeing as how it&#8217;s not been done at Pwn2Own before?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Di: Andrea</title>
		<link>http://www.oneitsecurity.it/01/03/2010/interview-with-charlie-miller-pwn2own/#comment-2157</link>
		<dc:creator>Andrea</dc:creator>
		<pubDate>Fri, 04 Feb 2011 11:08:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.oneitsecurity.it/01/03/2010/pwn2own-2010-interview-with-charlie-miller/#comment-2157</guid>
		<description>It&#039;s funny to see that the myth of Linux security has become so entrenched that people would contradict even the best security hackers to keep the myth alive.

Linux is nothing special, get over it.</description>
		<content:encoded><![CDATA[<p>It&#8217;s funny to see that the myth of Linux security has become so entrenched that people would contradict even the best security hackers to keep the myth alive.</p>
<p>Linux is nothing special, get over it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Di: dc</title>
		<link>http://www.oneitsecurity.it/01/03/2010/interview-with-charlie-miller-pwn2own/#comment-1796</link>
		<dc:creator>dc</dc:creator>
		<pubDate>Wed, 14 Jul 2010 16:23:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.oneitsecurity.it/01/03/2010/pwn2own-2010-interview-with-charlie-miller/#comment-1796</guid>
		<description>First off, people don&#039;t know what they are talking about. ActiveX is not a &quot;scripting language&quot;, it is a code container that allows to run browser extensions. I agree that it is very unsafe if you have some untested 3rd party ActiveX installed, but still please have your terms straight. 

As for JScript and ActiveX going away or not being supported on a Windows platform, I doubt that it will happen in the near future. The reasons? There are too many web sites and companies that rely their whole livelihood on those. Example would be Adobe Flash itself, which runs as an ActiveX component.

As for IE not being as safe and secure as FF or Chrome for instance, I would agree with it. The reason being is not because MS wrote a bad code for it but because there are way too many hackers targeting Microsoft. It&#039;s that plain and simple.

As for the advice in this article not to use Flash and JScript in your browsers, I think it&#039;s like saying, if you don&#039;t want to get hurt stay in your basement. As you can imagine, that is not possible in today&#039;s world, so everything has to be done in moderation and people should be educated about what to do and what not to do on the web.

Have a safe browsing!</description>
		<content:encoded><![CDATA[<p>First off, people don&#8217;t know what they are talking about. ActiveX is not a &#8220;scripting language&#8221;, it is a code container that allows to run browser extensions. I agree that it is very unsafe if you have some untested 3rd party ActiveX installed, but still please have your terms straight. </p>
<p>As for JScript and ActiveX going away or not being supported on a Windows platform, I doubt that it will happen in the near future. The reasons? There are too many web sites and companies that rely their whole livelihood on those. Example would be Adobe Flash itself, which runs as an ActiveX component.</p>
<p>As for IE not being as safe and secure as FF or Chrome for instance, I would agree with it. The reason being is not because MS wrote a bad code for it but because there are way too many hackers targeting Microsoft. It&#8217;s that plain and simple.</p>
<p>As for the advice in this article not to use Flash and JScript in your browsers, I think it&#8217;s like saying, if you don&#8217;t want to get hurt stay in your basement. As you can imagine, that is not possible in today&#8217;s world, so everything has to be done in moderation and people should be educated about what to do and what not to do on the web.</p>
<p>Have a safe browsing!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Di: Pit London</title>
		<link>http://www.oneitsecurity.it/01/03/2010/interview-with-charlie-miller-pwn2own/#comment-1713</link>
		<dc:creator>Pit London</dc:creator>
		<pubDate>Thu, 22 Apr 2010 22:14:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.oneitsecurity.it/01/03/2010/pwn2own-2010-interview-with-charlie-miller/#comment-1713</guid>
		<description>I use opera and firefox on win xp and is work fast and stabill i never use any IE i just dont trast becouse i seen to many trap things.i use as well linux ,i dont like really what come wrom M$.
ps. this is strange what saying charli millere or this is to much comersiall.......dont know???</description>
		<content:encoded><![CDATA[<p>I use opera and firefox on win xp and is work fast and stabill i never use any IE i just dont trast becouse i seen to many trap things.i use as well linux ,i dont like really what come wrom M$.<br />
ps. this is strange what saying charli millere or this is to much comersiall&#8230;&#8230;.dont know???</p>
]]></content:encoded>
	</item>
	<item>
		<title>Di: Kamilion</title>
		<link>http://www.oneitsecurity.it/01/03/2010/interview-with-charlie-miller-pwn2own/#comment-1715</link>
		<dc:creator>Kamilion</dc:creator>
		<pubDate>Tue, 06 Apr 2010 06:56:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.oneitsecurity.it/01/03/2010/pwn2own-2010-interview-with-charlie-miller/#comment-1715</guid>
		<description>Sorry to come in late on this -- but there&#039;s one big thing missing: Every copy of IE8 I&#039;ve seen in the field is filled with TOOLBARS! Sometimes SIX OR MORE! All the users I talked to dutifully carried whatever the website told them to do... (I just got another user today insisting that &quot;vista security 2010&quot; was legit... *sigh*)</description>
		<content:encoded><![CDATA[<p>Sorry to come in late on this &#8212; but there&#8217;s one big thing missing: Every copy of IE8 I&#8217;ve seen in the field is filled with TOOLBARS! Sometimes SIX OR MORE! All the users I talked to dutifully carried whatever the website told them to do&#8230; (I just got another user today insisting that &#8220;vista security 2010&#8243; was legit&#8230; *sigh*)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Di: LS</title>
		<link>http://www.oneitsecurity.it/01/03/2010/interview-with-charlie-miller-pwn2own/#comment-1689</link>
		<dc:creator>LS</dc:creator>
		<pubDate>Fri, 26 Mar 2010 23:54:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.oneitsecurity.it/01/03/2010/pwn2own-2010-interview-with-charlie-miller/#comment-1689</guid>
		<description>No hacking contest is complete without Linux involved.
I&#039;m sure this guy is biased because his job depends heavily on working with commercial software. He doesn&#039;t want to look any less skillful by admitting he can&#039;t hack Linux. Software is much like politics.</description>
		<content:encoded><![CDATA[<p>No hacking contest is complete without Linux involved.<br />
I&#8217;m sure this guy is biased because his job depends heavily on working with commercial software. He doesn&#8217;t want to look any less skillful by admitting he can&#8217;t hack Linux. Software is much like politics.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Di: EchoBravo</title>
		<link>http://www.oneitsecurity.it/01/03/2010/interview-with-charlie-miller-pwn2own/#comment-1686</link>
		<dc:creator>EchoBravo</dc:creator>
		<pubDate>Fri, 26 Mar 2010 18:34:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.oneitsecurity.it/01/03/2010/pwn2own-2010-interview-with-charlie-miller/#comment-1686</guid>
		<description>/*No, Linux is no harder, in fact probably easier, although some of this is dependent on the particular flavor of Linux you&#039;re talking about. */

How about doing it on your own just for the bragging rights to be the first one do it Linux using Firefox. You already have the money. Talk is cheap. Make all those companies running servers and desktops be aware. Many governments and universities have switched to Linux desktop.</description>
		<content:encoded><![CDATA[<p>/*No, Linux is no harder, in fact probably easier, although some of this is dependent on the particular flavor of Linux you&#8217;re talking about. */</p>
<p>How about doing it on your own just for the bragging rights to be the first one do it Linux using Firefox. You already have the money. Talk is cheap. Make all those companies running servers and desktops be aware. Many governments and universities have switched to Linux desktop.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

