<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>You don’t have to be faster than the bear</title><link>http://blogs.msdn.com/b/david_leblanc/archive/2010/05/28/you-don-t-have-to-be-faster-than-the-bear.aspx</link><description>Note – this post disappeared during the blog upgrade, recovered due to search cache.
 Just got done reading Michal Zalewski's really interesting post on the Zero Day blog, found here. 
 His premise, which I don't debate, is that we've done a lousy job</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: You don’t have to be faster than the bear</title><link>http://blogs.msdn.com/b/david_leblanc/archive/2010/05/28/you-don-t-have-to-be-faster-than-the-bear.aspx#10019487</link><pubDate>Thu, 03 Jun 2010 15:00:30 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10019487</guid><dc:creator>Alan J. McFarlane</dc:creator><description>&lt;p&gt;The link to the blog article, lost from the original article, is:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.zdnet.com/blog/security/security-engineering-broken-promises/6503?tag=mantle_skin;content"&gt;www.zdnet.com/.../6503&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10019487" width="1" height="1"&gt;</description></item><item><title>re: You don’t have to be faster than the bear</title><link>http://blogs.msdn.com/b/david_leblanc/archive/2010/05/28/you-don-t-have-to-be-faster-than-the-bear.aspx#10017265</link><pubDate>Sat, 29 May 2010 10:47:53 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10017265</guid><dc:creator>Fleet Command</dc:creator><description>&lt;p&gt;What? But that is exactly what I and others have been expecting all along ... Are you saying that the fact that you don&amp;#39;t have to outrun the bear has only so recently reached you, David?&lt;/p&gt;
&lt;p&gt;[dcl] No, not at all. That part is obvious. What is not so obvious is that we keep expecting security to be binary - either something is completely secure, or it is insecure. In reality, it is a function of time.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10017265" width="1" height="1"&gt;</description></item></channel></rss>