<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Evolution is Punctuated Equilibria</title>
	<atom:link href="http://blog.trailofbits.com/2008/07/24/evolution-is-punctuated-equilibria/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.trailofbits.com/2008/07/24/evolution-is-punctuated-equilibria/</link>
	<description>4888 C3C4 099A 4240 9648  719B 84E0 A6FE 32AE 38F6</description>
	<pubDate>Wed, 07 Jan 2009 05:13:10 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Dino Dai Zovi</title>
		<link>http://blog.trailofbits.com/2008/07/24/evolution-is-punctuated-equilibria/#comment-132</link>
		<dc:creator>Dino Dai Zovi</dc:creator>
		<pubDate>Fri, 22 Aug 2008 03:11:17 +0000</pubDate>
		<guid isPermaLink="false">http://trailofbits.wordpress.com/?p=60#comment-132</guid>
		<description>@Kent

Thanks.  I am not yet an old geezer, just a curmudgeony late 20-something who wasted too much of his youth on the Internet.  I've been on the Internet since '93, so I did get to see some of the fun.  But now the Internet is SERIOUS BUSINESS.</description>
		<content:encoded><![CDATA[<p>@Kent</p>
<p>Thanks.  I am not yet an old geezer, just a curmudgeony late 20-something who wasted too much of his youth on the Internet.  I&#8217;ve been on the Internet since &#8216;93, so I did get to see some of the fun.  But now the Internet is SERIOUS BUSINESS.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kent</title>
		<link>http://blog.trailofbits.com/2008/07/24/evolution-is-punctuated-equilibria/#comment-121</link>
		<dc:creator>Kent</dc:creator>
		<pubDate>Tue, 05 Aug 2008 22:02:38 +0000</pubDate>
		<guid isPermaLink="false">http://trailofbits.wordpress.com/?p=60#comment-121</guid>
		<description>Wow, Dino, my first reading from your blog (referred by Google Reader) and I must wonder, are you an old geezer like me that remembers the history of malware on the Internet from personal experience or do you, unlike everyone else, actually learn from history?

What a terrific post to read first from your blog.</description>
		<content:encoded><![CDATA[<p>Wow, Dino, my first reading from your blog (referred by Google Reader) and I must wonder, are you an old geezer like me that remembers the history of malware on the Internet from personal experience or do you, unlike everyone else, actually learn from history?</p>
<p>What a terrific post to read first from your blog.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ShawnM</title>
		<link>http://blog.trailofbits.com/2008/07/24/evolution-is-punctuated-equilibria/#comment-120</link>
		<dc:creator>ShawnM</dc:creator>
		<pubDate>Thu, 31 Jul 2008 05:12:18 +0000</pubDate>
		<guid isPermaLink="false">http://trailofbits.wordpress.com/?p=60#comment-120</guid>
		<description>@Ivan

Oh man, I totally remember trying to find the magic bit that was broken in exploits on Bugtraq back then. It at least motivated me to learn enough C to get things to compile, so I suppose it was a good public service. =)</description>
		<content:encoded><![CDATA[<p>@Ivan</p>
<p>Oh man, I totally remember trying to find the magic bit that was broken in exploits on Bugtraq back then. It at least motivated me to learn enough C to get things to compile, so I suppose it was a good public service. =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ivan</title>
		<link>http://blog.trailofbits.com/2008/07/24/evolution-is-punctuated-equilibria/#comment-118</link>
		<dc:creator>ivan</dc:creator>
		<pubDate>Thu, 31 Jul 2008 01:30:42 +0000</pubDate>
		<guid isPermaLink="false">http://trailofbits.wordpress.com/?p=60#comment-118</guid>
		<description>@dino
Great article! minor comments: skript kiddies pre-date Bugtraq (or at least they can be traced to independent sources of "skripts"). They used to get their warez by trading with others that in turn obtained them from leaks or breakins to systems of those subscribed to the closed-group mailing lists like Zardoz and Core. This was described in Suelette Dreyfuss and Julian Assanges's book "Underground" (http://reactor-core.org/underground.html).
BTW as the original post indicated the SSH exploit posted to the Bugtraq mailing list was "skript-kiddie proof", it did not work out-of-the-box unless you knew what you were doing.</description>
		<content:encoded><![CDATA[<p>@dino<br />
Great article! minor comments: skript kiddies pre-date Bugtraq (or at least they can be traced to independent sources of &#8220;skripts&#8221;). They used to get their warez by trading with others that in turn obtained them from leaks or breakins to systems of those subscribed to the closed-group mailing lists like Zardoz and Core. This was described in Suelette Dreyfuss and Julian Assanges&#8217;s book &#8220;Underground&#8221; (http://reactor-core.org/underground.html).<br />
BTW as the original post indicated the SSH exploit posted to the Bugtraq mailing list was &#8220;skript-kiddie proof&#8221;, it did not work out-of-the-box unless you knew what you were doing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ShawnM</title>
		<link>http://blog.trailofbits.com/2008/07/24/evolution-is-punctuated-equilibria/#comment-117</link>
		<dc:creator>ShawnM</dc:creator>
		<pubDate>Wed, 30 Jul 2008 20:04:37 +0000</pubDate>
		<guid isPermaLink="false">http://trailofbits.wordpress.com/?p=60#comment-117</guid>
		<description>First of all re: MS, it's properly spelled "Security Putsch". =)

I like Marcus as a human being, if for nothing else, for his awesome side work as a &lt;a href="http://photo.net/photodb/photo?photo_id=946155" rel="nofollow"&gt;fetish photog&lt;/a&gt;, but I've watched and read several of the anti-disclosure rants as well, and they just don't compute.

If nothing else, the history above shows that both approaches have been tried, and neither have made much of difference. Looking to the next evolutionary leap forward out there somewhere.</description>
		<content:encoded><![CDATA[<p>First of all re: MS, it&#8217;s properly spelled &#8220;Security Putsch&#8221;. =)</p>
<p>I like Marcus as a human being, if for nothing else, for his awesome side work as a <a href="http://photo.net/photodb/photo?photo_id=946155" rel="nofollow">fetish photog</a>, but I&#8217;ve watched and read several of the anti-disclosure rants as well, and they just don&#8217;t compute.</p>
<p>If nothing else, the history above shows that both approaches have been tried, and neither have made much of difference. Looking to the next evolutionary leap forward out there somewhere.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dino Dai Zovi</title>
		<link>http://blog.trailofbits.com/2008/07/24/evolution-is-punctuated-equilibria/#comment-116</link>
		<dc:creator>Dino Dai Zovi</dc:creator>
		<pubDate>Wed, 30 Jul 2008 06:39:50 +0000</pubDate>
		<guid isPermaLink="false">http://trailofbits.wordpress.com/?p=60#comment-116</guid>
		<description>@AndrewJaquith
Thanks for the comments.  You are totally right about the cybercrime/drug meme and I have removed that reference from the post.

As for Ranum's talk, I didn't agree with him when I saw it at BH 2000, nor do I agree with it now.  He had been saying the same thing about full disclosure since 1998 or so.  Script kiddies suck, but they were nothing compared to today's malware/cybercrime threat.  Did the IIS WebDAV, WMF, ANI, or the Microsoft Word doc exploits that popped the State Department come from Bugtraq?  No.  These attackers are finding their own vulnerabilities and writing their own exploits and tools.  And they aren't so kind as to share them on a public mailing list, let alone inform the vendor and responsibly disclose.

Pre-cybercrime hacking by skilled underground groups, full-disclosure, and script kiddies were all part of the wake-up call that the Internet slept through.  Why did no one think that something was seriously wrong when teenagers were breaking into government agencies?  Were those specific teenagers the problem?  Or the fact that teenagers could break into the DoD over the Internet?  I think the latter.

That is part of the reason why the current state of Internet security can best be described as damage control.  More on this in a future blog rant.</description>
		<content:encoded><![CDATA[<p>@AndrewJaquith<br />
Thanks for the comments.  You are totally right about the cybercrime/drug meme and I have removed that reference from the post.</p>
<p>As for Ranum&#8217;s talk, I didn&#8217;t agree with him when I saw it at BH 2000, nor do I agree with it now.  He had been saying the same thing about full disclosure since 1998 or so.  Script kiddies suck, but they were nothing compared to today&#8217;s malware/cybercrime threat.  Did the IIS WebDAV, WMF, ANI, or the Microsoft Word doc exploits that popped the State Department come from Bugtraq?  No.  These attackers are finding their own vulnerabilities and writing their own exploits and tools.  And they aren&#8217;t so kind as to share them on a public mailing list, let alone inform the vendor and responsibly disclose.</p>
<p>Pre-cybercrime hacking by skilled underground groups, full-disclosure, and script kiddies were all part of the wake-up call that the Internet slept through.  Why did no one think that something was seriously wrong when teenagers were breaking into government agencies?  Were those specific teenagers the problem?  Or the fact that teenagers could break into the DoD over the Internet?  I think the latter.</p>
<p>That is part of the reason why the current state of Internet security can best be described as damage control.  More on this in a future blog rant.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Jaquith</title>
		<link>http://blog.trailofbits.com/2008/07/24/evolution-is-punctuated-equilibria/#comment-115</link>
		<dc:creator>Andrew Jaquith</dc:creator>
		<pubDate>Wed, 30 Jul 2008 05:21:00 +0000</pubDate>
		<guid isPermaLink="false">http://trailofbits.wordpress.com/?p=60#comment-115</guid>
		<description>Good post. Concise history, and well told. 

Two small quibbles: you might've included Marcus Ranum's 2000 Black Hat talk as the clarion blast that foreshadowed the "responsible disclosure" movement -- it pre-dated the OIS by two years, and Microsoft's SDL by about a year-and-a-half.

Also, the "global cybercrime is more profitable than the illicit drug trade" meme is without basis in fact. Ryan Paul debunks that notion here: http://arstechnica.com/news.ars/post/20051129-5648.html (That said, cybercrime is indeed a good business to be in, even if it doesn't generate as much revenue as drugs. It is almost certainly more profitable.)</description>
		<content:encoded><![CDATA[<p>Good post. Concise history, and well told. </p>
<p>Two small quibbles: you might&#8217;ve included Marcus Ranum&#8217;s 2000 Black Hat talk as the clarion blast that foreshadowed the &#8220;responsible disclosure&#8221; movement &#8212; it pre-dated the OIS by two years, and Microsoft&#8217;s SDL by about a year-and-a-half.</p>
<p>Also, the &#8220;global cybercrime is more profitable than the illicit drug trade&#8221; meme is without basis in fact. Ryan Paul debunks that notion here: <a href="http://arstechnica.com/news.ars/post/20051129-5648.html" rel="nofollow">http://arstechnica.com/news.ars/post/20051129-5648.html</a> (That said, cybercrime is indeed a good business to be in, even if it doesn&#8217;t generate as much revenue as drugs. It is almost certainly more profitable.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John McDonald</title>
		<link>http://blog.trailofbits.com/2008/07/24/evolution-is-punctuated-equilibria/#comment-114</link>
		<dc:creator>John McDonald</dc:creator>
		<pubDate>Wed, 30 Jul 2008 04:36:29 +0000</pubDate>
		<guid isPermaLink="false">http://trailofbits.wordpress.com/?p=60#comment-114</guid>
		<description>I found this quote from the Stallman talk pretty funny:

"But for us, when an outsider started to change the system programs, that meant he was showing a real interest in becoming a contributing member of the community."

I think he'd find things have changed slightly these days. Then again, I guess it depends on his definition of 'community' and 'contributing.' 

+5 points for including Lopatic's NCSA exploit. He'll find this in two months when ego-surfing and smile to himself. Hey Thomas! :&#62;</description>
		<content:encoded><![CDATA[<p>I found this quote from the Stallman talk pretty funny:</p>
<p>&#8220;But for us, when an outsider started to change the system programs, that meant he was showing a real interest in becoming a contributing member of the community.&#8221;</p>
<p>I think he&#8217;d find things have changed slightly these days. Then again, I guess it depends on his definition of &#8216;community&#8217; and &#8216;contributing.&#8217; </p>
<p>+5 points for including Lopatic&#8217;s NCSA exploit. He&#8217;ll find this in two months when ego-surfing and smile to himself. Hey Thomas! :&gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: D2</title>
		<link>http://blog.trailofbits.com/2008/07/24/evolution-is-punctuated-equilibria/#comment-113</link>
		<dc:creator>D2</dc:creator>
		<pubDate>Wed, 30 Jul 2008 00:50:49 +0000</pubDate>
		<guid isPermaLink="false">http://trailofbits.wordpress.com/?p=60#comment-113</guid>
		<description>Kinda updated this here, mebad http://bsdosx.blogspot.com/2008/07/future-shock-security-20.html .. anyway, fun and games.</description>
		<content:encoded><![CDATA[<p>Kinda updated this here, mebad <a href="http://bsdosx.blogspot.com/2008/07/future-shock-security-20.html" rel="nofollow">http://bsdosx.blogspot.com/2008/07/future-shock-security-20.html</a> .. anyway, fun and games.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: D2</title>
		<link>http://blog.trailofbits.com/2008/07/24/evolution-is-punctuated-equilibria/#comment-112</link>
		<dc:creator>D2</dc:creator>
		<pubDate>Wed, 30 Jul 2008 00:39:49 +0000</pubDate>
		<guid isPermaLink="false">http://trailofbits.wordpress.com/?p=60#comment-112</guid>
		<description>Utility / Cloud will not take over but drive price comparison in internal IT shops. Atomic metrics must have abstract units or dollar costs associated.

It is nuts. It is scary. Breeding out the 'old guard' wil happen also, as it's a social and geo-political problem. Incentives and penalties will need to be introduced per country. Once RIRs get auth and sBGP, DNSSEC happens we may look at penalising entities. Virtual hosts, servers, networks and storage will also drive fluidity yet static nature of 'virtual nodes' transacting with each other.

Just a though...</description>
		<content:encoded><![CDATA[<p>Utility / Cloud will not take over but drive price comparison in internal IT shops. Atomic metrics must have abstract units or dollar costs associated.</p>
<p>It is nuts. It is scary. Breeding out the &#8216;old guard&#8217; wil happen also, as it&#8217;s a social and geo-political problem. Incentives and penalties will need to be introduced per country. Once RIRs get auth and sBGP, DNSSEC happens we may look at penalising entities. Virtual hosts, servers, networks and storage will also drive fluidity yet static nature of &#8216;virtual nodes&#8217; transacting with each other.</p>
<p>Just a though&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
