<?xml version="1.0"?>
<rss version="2.0">
	<channel>
		<title>MotomaSTYLE</title>
		<link>http://motomastyle.com/home/</link>
		

		
		<item>
			<title>Comment by 'http://www.todofixthis.com' on Security: Perceived Risk versus Potential Damage</title>
			<link>http://motomastyle.com/security-perceived-risk-versus-potential-damage/#PageComment_10</link>
			<description>Your post alludes to a critical security vulnerability; you should never trust the User when it comes to security (or much of anything for that matter).

In the case of the iTunes music library app, the damage was amplified because the User did not properly manage his passwords (namely, he only had one).

There are two approaches to this situation:
The first option is to force the User to be more secure (&quot;Your password must contain at least 3 numbers, an uppercase letter and the symbol 'âˆ‚'.&quot;).

As a rule, though, this doesn't work; all you end up with is a bunch of post-it notes stuck to monitors.

Alternatively, assume that your Users will do everything insecurely and code around worst-case scenarios.

As I gather you were conveying as the main point in your post, it is a good idea to integrate security features now rather than wait until your app gets hacked.</description>
			<pubDate>Thu, 29 May 2008 13:25:37 -0400</pubDate>
			<author>http://www.todofixthis.com</author>
			<guid>http://motomastyle.com/security-perceived-risk-versus-potential-damage/#PageComment_10</guid>
		</item>
		
		<item>
			<title>Comment by 'scottjeynes' on Security: Perceived Risk versus Potential Damage</title>
			<link>http://motomastyle.com/security-perceived-risk-versus-potential-damage/#PageComment_9</link>
			<description>Good post! Over the years I've seen wide-open SQL injection opportunities (and attempts to exploit them in the logs); an &quot;is logged in&quot; variable passed as a hidden field on the browser; an internal web site that was &quot;securely&quot; made available to remote users by placing it on an &quot;unadvertised&quot; public IP (Google picked it up, of course).... Educating folks is a never-ending battle.</description>
			<pubDate>Thu, 29 May 2008 13:25:07 -0400</pubDate>
			<author>scottjeynes</author>
			<guid>http://motomastyle.com/security-perceived-risk-versus-potential-damage/#PageComment_9</guid>
		</item>
		

	</channel>
</rss>
