<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>New faces and predictions for the New Year...</title><link>http://blogs.msdn.com/sdl/archive/2008/01/22/new-faces-and-predictions-for-the-new-year.aspx</link><description>Hello all - Dave here For a change of pace, a few of the SDL blog crew decided to take a poke at a "Security Predictions for 2008" posting. In selecting a prediction, the only guiding rule was that the prediction had to cover something that could be influenced</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>New faces and predictions for the New Year&amp;#8230; | Online Services</title><link>http://blogs.msdn.com/sdl/archive/2008/01/22/new-faces-and-predictions-for-the-new-year.aspx#7203305</link><pubDate>Wed, 23 Jan 2008 03:21:52 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7203305</guid><dc:creator>New faces and predictions for the New Year… | Online Services</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.fulq.com/new-faces-and-predictions-for-the-new-year"&gt;http://www.fulq.com/new-faces-and-predictions-for-the-new-year&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: New faces and predictions for the New Year...</title><link>http://blogs.msdn.com/sdl/archive/2008/01/22/new-faces-and-predictions-for-the-new-year.aspx#7213319</link><pubDate>Thu, 24 Jan 2008 02:39:39 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:7213319</guid><dc:creator>asteingruebl</dc:creator><description>&lt;p&gt;Eric,&lt;/p&gt;
&lt;p&gt;Wouldn't you rather have a reduction in the total number of vulnerabilities, rather than just the percentage? &amp;nbsp; Ideally you'd like to reduce your total reported vulnerability count rather than just reduce your percentage of the problem. &amp;nbsp;Hackers turning their attention to another product can account for both however, so again maybe its not the right metric?&lt;/p&gt;
&lt;p&gt;Do you have an associated internal goal related to this? &amp;nbsp;Something like &amp;quot;no more buffer overflows in anything&amp;quot; for example? :)&lt;/p&gt;
</description></item></channel></rss>