<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Safari 3.01 released</title>
	<atom:link href="http://larholm.com/2007/06/14/safari-301-released/feed/" rel="self" type="application/rss+xml" />
	<link>http://larholm.com/2007/06/14/safari-301-released/</link>
	<description>Me, myself and I</description>
	<pubDate>Thu, 11 Mar 2010 19:42:02 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: kimblim</title>
		<link>http://larholm.com/2007/06/14/safari-301-released/#comment-307</link>
		<dc:creator>kimblim</dc:creator>
		<pubDate>Sat, 23 Jun 2007 03:39:30 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/06/14/safari-301-released/#comment-307</guid>
		<description>And now 3.02 is out - while I think it is great that Apple reacts so quickly to all the security issues, it also gives a clear signal that their beta was more of an alpha... 3.0 simply was not ready to hit the users, but I guess Apple had to deliver something for their conference. Apple can pretty much get away with everything these days because (for some crazy reason) everybody is believing the hype surrounding the company.</description>
		<content:encoded><![CDATA[<p>And now 3.02 is out - while I think it is great that Apple reacts so quickly to all the security issues, it also gives a clear signal that their beta was more of an alpha&#8230; 3.0 simply was not ready to hit the users, but I guess Apple had to deliver something for their conference. Apple can pretty much get away with everything these days because (for some crazy reason) everybody is believing the hype surrounding the company.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thor Larholm</title>
		<link>http://larholm.com/2007/06/14/safari-301-released/#comment-292</link>
		<dc:creator>Thor Larholm</dc:creator>
		<pubDate>Sun, 17 Jun 2007 19:47:09 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/06/14/safari-301-released/#comment-292</guid>
		<description>"Anon Ymous" is partially right, Apple will only credit researchers in their security updates if those researchers have given them advance notice and not released any information about that vulnerability until Apple has released a patch for the vulnerability.

Whether or not that is the definition of 'responsible disclosure' has been debated for many years. One thing that is certain is that the length of that time window for the patch release, whether it be days, weeks, months or years, is entirely up to Apples own discretion.

There are not that many enticing reasons for following a vendor procedure that is lacking in definition and can be changed at will.

I have definitely received proper credit for the discovery of this vulnerability by the security community at large.

Regards
Thor Larholm</description>
		<content:encoded><![CDATA[<p>&#8220;Anon Ymous&#8221; is partially right, Apple will only credit researchers in their security updates if those researchers have given them advance notice and not released any information about that vulnerability until Apple has released a patch for the vulnerability.</p>
<p>Whether or not that is the definition of &#8216;responsible disclosure&#8217; has been debated for many years. One thing that is certain is that the length of that time window for the patch release, whether it be days, weeks, months or years, is entirely up to Apples own discretion.</p>
<p>There are not that many enticing reasons for following a vendor procedure that is lacking in definition and can be changed at will.</p>
<p>I have definitely received proper credit for the discovery of this vulnerability by the security community at large.</p>
<p>Regards<br />
Thor Larholm</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anon Ymous</title>
		<link>http://larholm.com/2007/06/14/safari-301-released/#comment-291</link>
		<dc:creator>Anon Ymous</dc:creator>
		<pubDate>Sun, 17 Jun 2007 16:49:32 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/06/14/safari-301-released/#comment-291</guid>
		<description>I believe Apple's policy is not to credit researchers in security updates unless they practice responsible disclosure.  Those that let Apple know about a security issue and provide some time window for a fix to be released before publishing details to the public are credited as you can easily see by looking at the details of Apple's past software and security updates.</description>
		<content:encoded><![CDATA[<p>I believe Apple&#8217;s policy is not to credit researchers in security updates unless they practice responsible disclosure.  Those that let Apple know about a security issue and provide some time window for a fix to be released before publishing details to the public are credited as you can easily see by looking at the details of Apple&#8217;s past software and security updates.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charlie</title>
		<link>http://larholm.com/2007/06/14/safari-301-released/#comment-286</link>
		<dc:creator>Charlie</dc:creator>
		<pubDate>Sat, 16 Jun 2007 23:16:32 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/06/14/safari-301-released/#comment-286</guid>
		<description>Cool, keep up the bug finding!  It's super super easy to do URL encoding, I'm somewhat shocked that they didn't just use that function. And thanks for the extra explanation in the comments of the previous article, it became much more clear.</description>
		<content:encoded><![CDATA[<p>Cool, keep up the bug finding!  It&#8217;s super super easy to do URL encoding, I&#8217;m somewhat shocked that they didn&#8217;t just use that function. And thanks for the extra explanation in the comments of the previous article, it became much more clear.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Trancer</title>
		<link>http://larholm.com/2007/06/14/safari-301-released/#comment-276</link>
		<dc:creator>Trancer</dc:creator>
		<pubDate>Sat, 16 Jun 2007 01:44:32 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/06/14/safari-301-released/#comment-276</guid>
		<description>&lt;p&gt;They fixed five security issues, without crediting anyone of the bug finders.&lt;br /&gt;
There are additional vulnerabilities that has disclosed, reported to Apple (with no reply), and hasn't been fixed:&lt;br /&gt;
&lt;a href="http://www.rec-sec.co.il/2007/06/12/apple-safari-for-windows-vulnerabilities/#one" rel="nofollow"&gt;http://www.rec-sec.co.il/2007/06/12/apple-safari-for-windows-vulnerabilities/#one&lt;/a&gt;&lt;br /&gt;
I see no point in that.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>They fixed five security issues, without crediting anyone of the bug finders.<br />
There are additional vulnerabilities that has disclosed, reported to Apple (with no reply), and hasn&#8217;t been fixed:<br />
<a href="http://www.rec-sec.co.il/2007/06/12/apple-safari-for-windows-vulnerabilities/#one" rel="nofollow">http://www.rec-sec.co.il/2007/06/12/apple-safari-for-windows-vulnerabilities/#one</a><br />
I see no point in that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nueva versión beta de Safari para Windows &#171; Un poco de mucho</title>
		<link>http://larholm.com/2007/06/14/safari-301-released/#comment-270</link>
		<dc:creator>Nueva versión beta de Safari para Windows &#171; Un poco de mucho</dc:creator>
		<pubDate>Fri, 15 Jun 2007 09:30:25 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/06/14/safari-301-released/#comment-270</guid>
		<description>[...] siendo &#8220;tan inestable y poco fiable como su predecesora&#8221;. Por su parte, Thor Larholm comenta en su blog que se encuentra ahora mismo en el trabajo y aún no dispone de tiempo para echar un vistazo a la [...]</description>
		<content:encoded><![CDATA[<p>[...] siendo &#8220;tan inestable y poco fiable como su predecesora&#8221;. Por su parte, Thor Larholm comenta en su blog que se encuentra ahora mismo en el trabajo y aún no dispone de tiempo para echar un vistazo a la [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackd &#187; Tame Safari</title>
		<link>http://larholm.com/2007/06/14/safari-301-released/#comment-268</link>
		<dc:creator>hackd &#187; Tame Safari</dc:creator>
		<pubDate>Fri, 15 Jun 2007 04:10:28 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/06/14/safari-301-released/#comment-268</guid>
		<description>[...] impressive - 3 days after the original release and the justified shit-storm that followed, 3.0.1 got out. Thor Larholm mentions his finding is no longer exploitable on this version [but still very much so [...]</description>
		<content:encoded><![CDATA[<p>[...] impressive - 3 days after the original release and the justified shit-storm that followed, 3.0.1 got out. Thor Larholm mentions his finding is no longer exploitable on this version [but still very much so [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: No tío, contra Mozilla no le resulta at &#60;/nerdpride&#62;</title>
		<link>http://larholm.com/2007/06/14/safari-301-released/#comment-267</link>
		<dc:creator>No tío, contra Mozilla no le resulta at &#60;/nerdpride&#62;</dc:creator>
		<pubDate>Fri, 15 Jun 2007 03:13:19 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/06/14/safari-301-released/#comment-267</guid>
		<description>[...] &#8230;dijo tío Steve en algún lugar de la WWDC, y quizás contra Internet Explorer le resulte (en fallos, como contó pancho) pero contra firefox, un poco difícil. Cuatro días después de haber lanzado el primer ehhrgrg uhmm ¿beta? de Safari para windows, y haber parchado los no uno, ni dos, si no tres bugs con esta nueva -y mejorada versión- se vuelve a poner en duda. [...]</description>
		<content:encoded><![CDATA[<p>[...] &#8230;dijo tío Steve en algún lugar de la WWDC, y quizás contra Internet Explorer le resulte (en fallos, como contó pancho) pero contra firefox, un poco difícil. Cuatro días después de haber lanzado el primer ehhrgrg uhmm ¿beta? de Safari para windows, y haber parchado los no uno, ni dos, si no tres bugs con esta nueva -y mejorada versión- se vuelve a poner en duda. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: After hacker dissection, Safari beta is patched &#171; Connect Fans</title>
		<link>http://larholm.com/2007/06/14/safari-301-released/#comment-266</link>
		<dc:creator>After hacker dissection, Safari beta is patched &#171; Connect Fans</dc:creator>
		<pubDate>Fri, 15 Jun 2007 01:53:43 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/06/14/safari-301-released/#comment-266</guid>
		<description>[...] Apple for fixing a serious security vulnerability in such a short time frame,&#8221; he wrote in a blog posting. &#8220;Their usual response time can be counted in weeks to [...]</description>
		<content:encoded><![CDATA[<p>[...] Apple for fixing a serious security vulnerability in such a short time frame,&#8221; he wrote in a blog posting. &#8220;Their usual response time can be counted in weeks to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Johnny Not My Name</title>
		<link>http://larholm.com/2007/06/14/safari-301-released/#comment-264</link>
		<dc:creator>Johnny Not My Name</dc:creator>
		<pubDate>Fri, 15 Jun 2007 01:11:14 +0000</pubDate>
		<guid isPermaLink="false">http://larholm.com/2007/06/14/safari-301-released/#comment-264</guid>
		<description>You rule dude!  Just found your blog.. dig the way you are real.</description>
		<content:encoded><![CDATA[<p>You rule dude!  Just found your blog.. dig the way you are real.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
