<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>shaver &#187; black-hat</title>
	<atom:link href="http://shaver.off.net/diary/tag/black-hat/feed/" rel="self" type="application/rss+xml" />
	<link>http://shaver.off.net/diary</link>
	<description>noise from signal</description>
	<lastBuildDate>Fri, 18 Nov 2011 02:15:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>about ten days at black hat</title>
		<link>http://shaver.off.net/diary/2007/08/06/about-ten-days-at-black-hat/</link>
		<comments>http://shaver.off.net/diary/2007/08/06/about-ten-days-at-black-hat/#comments</comments>
		<pubDate>Mon, 06 Aug 2007 17:38:12 +0000</pubDate>
		<dc:creator>shaver</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[black-hat]]></category>
		<category><![CDATA[mea-culpa]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://shaver.off.net/diary/2007/08/06/about-ten-days-at-black-hat/</guid>
		<description><![CDATA[I&#8217;ll write more about this later, but since people are starting to pick this up, I want to get this out quickly. When I wrote &#8220;ten fucking days&#8221; on a card for Robert (rsnake), I was intending to express my confidence in our ability to turn around a fix quickly if we needed to, by [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ll write more about this later, but since people are starting to pick this up, I want to get this out quickly.</p>

<p>When I wrote &#8220;ten fucking days&#8221; on a card for Robert (rsnake), I was intending to express my confidence in our ability to turn around a fix quickly if we needed to, by giving him a sort of &#8220;admit one&#8221; ticket for a disclosure that he thought needed an especially fast response due to extreme risk or some such.  That was a bit overzealous, in the cold light of hindsight, but at no point did I intend to indicate that Mozilla policy was a ten-day turn around on all disclosed vulnerabilities.  People are reading the conversation and Robert&#8217;s post that way, but that&#8217;s not our situation, and it certainly wasn&#8217;t my intent to give that impression.</p>

<p>I apologize, and hope that nobody will think less of Mozilla because of my error.  We don&#8217;t issue challenges, and nobody here thinks that security response is a game.  This was a personal bargain and overwrought showmanship from a late-night Black Hat party that has now taken on a life of its own, and I hope the fracas about my overzealous comments to Robert don&#8217;t overshadow the great work that people on the Mozilla project do to keep our users secure.</p>

<p>[Update: Window has posted on this topic as well, over at the <a href="http://blog.mozilla.com/security/2007/08/06/mike-shaver-ten-days-and-expletives/">Mozilla security blog</a>.]</p>
]]></content:encoded>
			<wfw:commentRss>http://shaver.off.net/diary/2007/08/06/about-ten-days-at-black-hat/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>vegas, baby</title>
		<link>http://shaver.off.net/diary/2007/07/31/vegas-baby/</link>
		<comments>http://shaver.off.net/diary/2007/07/31/vegas-baby/#comments</comments>
		<pubDate>Tue, 31 Jul 2007 06:57:52 +0000</pubDate>
		<dc:creator>shaver</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[black-hat]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[travel]]></category>

		<guid isPermaLink="false">http://shaver.off.net/diary/2007/07/31/vegas-baby/</guid>
		<description><![CDATA[Back at the Boston DevDay in March, Window asked me if I&#8217;d be interested in speaking with her at Black Hat. Just as I would if Tony Hawk asked if I&#8217;d like to hit the half-pipe with him, I agreed enthusiastically, and the fruit of that agreement &#8212; and Window&#8217;s patience as co-speaker and designated [...]]]></description>
			<content:encoded><![CDATA[<p>Back at the <a href="http://starkravingfinkle.org/blog/2007/04/boston-developer-day-wrap-up/">Boston DevDay</a> in March, Window asked me if I&#8217;d be interested in speaking with her at Black Hat.  Just as I would if Tony Hawk asked if I&#8217;d like to hit the half-pipe with him, I agreed enthusiastically, and the fruit of that agreement &#8212; and Window&#8217;s patience as co-speaker and designated grown-up &#8212; will be available this Thursday, when we present <a href="http://www.blackhat.com/html/bh-usa-07/bh-usa-07-speakers.html#Snyder">Building and Breaking the Browser</a> at this year&#8217;s <a href="http://www.blackhat.com/html/bh-usa-07/bh-usa-07-index.html">Black Hat Briefings</a> in Las Vegas.  Window will be talking about how process, product design and tools all help us build a more secure product, and how those techniques and strategies can help others make their own software more secure.  Jesse will, I believe, be demonstrating one of his killer tools.  I&#8217;ll be wondering why I stayed at our <a href="http://blog.mozilla.com/security/2007/07/30/off-to-black-hat/">most chill party</a> until the early morning when I knew I had to be on stage at 10AM, and trying to not make it totally obvious that I&#8217;m the dumbest guy in the room.</p>
]]></content:encoded>
			<wfw:commentRss>http://shaver.off.net/diary/2007/07/31/vegas-baby/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

