<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Something better to do</title>
	<atom:link href="http://blog.kamens.us/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kamens.us</link>
	<description>Musings of an indignant mind</description>
	<lastBuildDate>Fri, 03 Sep 2010 22:37:56 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>Comment on Mac OS X Mail parental controls vulnerability by jik</title>
		<link>http://blog.kamens.us/2010/08/03/mac-os-x-mail-parental-controls-vulnerability/comment-page-1/#comment-106516</link>
		<dc:creator>jik</dc:creator>
		<pubDate>Fri, 03 Sep 2010 22:37:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kamens.us/?p=1693#comment-106516</guid>
		<description>I respectfully disagree.

The parental controls impose a security restriction, i.e., a restriction on the entities with whom a user is allowed to exchange email. This vulnerability allows that restriction to be bypassed, which is to my mind makes it applicable to both the second and third points you listed.

I&#039;m making a big deal out of it because it is a big deal. Parents are led by Apple to believe that the parental controls will prevent their children from being able to correspond with strangers on the Internet, which is a huge safety concern, when in fact that they will not.</description>
		<content:encoded><![CDATA[<p>I respectfully disagree.</p>
<p>The parental controls impose a security restriction, i.e., a restriction on the entities with whom a user is allowed to exchange email. This vulnerability allows that restriction to be bypassed, which is to my mind makes it applicable to both the second and third points you listed.</p>
<p>I&#8217;m making a big deal out of it because it is a big deal. Parents are led by Apple to believe that the parental controls will prevent their children from being able to correspond with strangers on the Internet, which is a huge safety concern, when in fact that they will not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Mac OS X Mail parental controls vulnerability by Commonsensicus</title>
		<link>http://blog.kamens.us/2010/08/03/mac-os-x-mail-parental-controls-vulnerability/comment-page-1/#comment-106515</link>
		<dc:creator>Commonsensicus</dc:creator>
		<pubDate>Fri, 03 Sep 2010 22:25:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kamens.us/?p=1693#comment-106515</guid>
		<description>You shouldn&#039;t refer to this bug as a &quot;vulnerability&quot; or an &quot;exploit&quot;.  All it allows you to do is send email to someone whose email address you already know.  That&#039;s not terribly surprising, really.  Now, if this bug allowed the attacker to actually execute code on the victim&#039;s machine, you could call it an &quot;exploit&quot;; but just being able to hold an email conversation with the victim isn&#039;t a bad thing.

For CVE, a vulnerability is a state in a computing system (or set of systems) that either:

    * allows an attacker to execute commands as another user
    * allows an attacker to access data that is contrary to the specified access restrictions for that data
    * allows an attacker to pose as another entity
    * allows an attacker to conduct a denial of service

This is pretty clear from MITRE&#039;s website, which you seem to be fond of, so it&#039;s surprising that you&#039;re making a big deal about it.</description>
		<content:encoded><![CDATA[<p>You shouldn&#8217;t refer to this bug as a &#8220;vulnerability&#8221; or an &#8220;exploit&#8221;.  All it allows you to do is send email to someone whose email address you already know.  That&#8217;s not terribly surprising, really.  Now, if this bug allowed the attacker to actually execute code on the victim&#8217;s machine, you could call it an &#8220;exploit&#8221;; but just being able to hold an email conversation with the victim isn&#8217;t a bad thing.</p>
<p>For CVE, a vulnerability is a state in a computing system (or set of systems) that either:</p>
<p>    * allows an attacker to execute commands as another user<br />
    * allows an attacker to access data that is contrary to the specified access restrictions for that data<br />
    * allows an attacker to pose as another entity<br />
    * allows an attacker to conduct a denial of service</p>
<p>This is pretty clear from MITRE&#8217;s website, which you seem to be fond of, so it&#8217;s surprising that you&#8217;re making a big deal about it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Virgin Mobile sucks by balls</title>
		<link>http://blog.kamens.us/2008/09/24/virgin-mobile-sucks/comment-page-2/#comment-106514</link>
		<dc:creator>balls</dc:creator>
		<pubDate>Fri, 03 Sep 2010 22:18:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kamens.brookline.ma.us/~jik/wordpress/?p=283#comment-106514</guid>
		<description>I hate them so much. My phone isn&#039;t receiving texts or sending them, so i try to change to my older phone and guess what? Their [bleep] [bleep] website won&#039;t work. Virgin mobile, [BLEEP]! I&#039;m switching</description>
		<content:encoded><![CDATA[<p>I hate them so much. My phone isn&#8217;t receiving texts or sending them, so i try to change to my older phone and guess what? Their [bleep] [bleep] website won&#8217;t work. Virgin mobile, [BLEEP]! I&#8217;m switching</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Scam call from &#8220;Mitchell Communications Group&#8221; by Steve-o</title>
		<link>http://blog.kamens.us/2010/08/06/scam-call-from-mitchell-communications-group/comment-page-1/#comment-106513</link>
		<dc:creator>Steve-o</dc:creator>
		<pubDate>Fri, 03 Sep 2010 18:29:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kamens.us/?p=1731#comment-106513</guid>
		<description>Thanks for posting this...saved me from dealing with these people.</description>
		<content:encoded><![CDATA[<p>Thanks for posting this&#8230;saved me from dealing with these people.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Scam call from &#8220;Mitchell Communications Group&#8221; by jik</title>
		<link>http://blog.kamens.us/2010/08/06/scam-call-from-mitchell-communications-group/comment-page-1/#comment-106509</link>
		<dc:creator>jik</dc:creator>
		<pubDate>Fri, 03 Sep 2010 00:30:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kamens.us/?p=1731#comment-106509</guid>
		<description>I hope those of you who got this call and are on the National Do Not Call Registry (why would anyone &lt;em&gt;not&lt;/em&gt; put themselves on the do not call registry?) are filing complaints at &lt;a href=&quot;https://complaints.donotcall.gov/complaint/complaintcheck.aspx?panel=2&quot; rel=&quot;nofollow&quot;&gt;donotcall.gov&lt;/a&gt;. The more people complain, the more likely it is that the FCC or state attorneys general will do something about it.</description>
		<content:encoded><![CDATA[<p>I hope those of you who got this call and are on the National Do Not Call Registry (why would anyone <em>not</em> put themselves on the do not call registry?) are filing complaints at <a href="https://complaints.donotcall.gov/complaint/complaintcheck.aspx?panel=2">donotcall.gov</a>. The more people complain, the more likely it is that the FCC or state attorneys general will do something about it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Scam call from &#8220;Mitchell Communications Group&#8221; by AMS</title>
		<link>http://blog.kamens.us/2010/08/06/scam-call-from-mitchell-communications-group/comment-page-1/#comment-106508</link>
		<dc:creator>AMS</dc:creator>
		<pubDate>Fri, 03 Sep 2010 00:27:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kamens.us/?p=1731#comment-106508</guid>
		<description>Same as everyone else.  A push call from &quot;Patrick.&quot;</description>
		<content:encoded><![CDATA[<p>Same as everyone else.  A push call from &#8220;Patrick.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Scam call from &#8220;Mitchell Communications Group&#8221; by Tammie in Seattle</title>
		<link>http://blog.kamens.us/2010/08/06/scam-call-from-mitchell-communications-group/comment-page-1/#comment-106506</link>
		<dc:creator>Tammie in Seattle</dc:creator>
		<pubDate>Thu, 02 Sep 2010 16:30:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kamens.us/?p=1731#comment-106506</guid>
		<description>yup...I got the same message on my phone yesterday..they didn&#039;t even have a first name or ask for anyone...just the same message...final attenpt yada yada....thank God for caller ID :)</description>
		<content:encoded><![CDATA[<p>yup&#8230;I got the same message on my phone yesterday..they didn&#8217;t even have a first name or ask for anyone&#8230;just the same message&#8230;final attenpt yada yada&#8230;.thank God for caller ID <img src='http://blog.kamens.us/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Send Later 3 Thunderbird Add-on by jik</title>
		<link>http://blog.kamens.us/send-later-3/comment-page-1/#comment-106502</link>
		<dc:creator>jik</dc:creator>
		<pubDate>Thu, 02 Sep 2010 12:46:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kamens.us/?page_id=1637#comment-106502</guid>
		<description>I believe this is fixed in the current beta release. Visit the &lt;a href=&quot;https://addons.mozilla.org/en-US/thunderbird/addon/195275/&quot; rel=&quot;nofollow&quot;&gt;add-on page&lt;/a&gt; and click on &quot;Install beta version&quot; to try it out.</description>
		<content:encoded><![CDATA[<p>I believe this is fixed in the current beta release. Visit the <a href="https://addons.mozilla.org/en-US/thunderbird/addon/195275/">add-on page</a> and click on &#8220;Install beta version&#8221; to try it out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Send Later 3 Thunderbird Add-on by Shling</title>
		<link>http://blog.kamens.us/send-later-3/comment-page-1/#comment-106501</link>
		<dc:creator>Shling</dc:creator>
		<pubDate>Thu, 02 Sep 2010 11:40:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kamens.us/?page_id=1637#comment-106501</guid>
		<description>Seems to have a massive RAM leak.  Left running for a day or two and it balloons the amount of memory T-Bird takes up.  When disabled, T-Bird goes back to normal memory usage.  Otherwise great.</description>
		<content:encoded><![CDATA[<p>Seems to have a massive RAM leak.  Left running for a day or two and it balloons the amount of memory T-Bird takes up.  When disabled, T-Bird goes back to normal memory usage.  Otherwise great.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MBTA Transit Police threaten to arrest me for distributing flyers to reporters at Google Transit press conference by Bob Lothrope</title>
		<link>http://blog.kamens.us/2009/07/30/mbta-transit-police-threaten-to-arrest-me-for-distributing-flyers-to-reporters-at-google-transit-press-conference/comment-page-1/#comment-106499</link>
		<dc:creator>Bob Lothrope</dc:creator>
		<pubDate>Wed, 01 Sep 2010 20:59:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kamens.brookline.ma.us/~jik/wordpress/?p=793#comment-106499</guid>
		<description>(Apologies for the year+ delay in following up.)

&quot; &#039;Why don’t you instead focus your efforts on getting in touch with the T’s planning department, who are the people who can actually fix the mistake?&#039;

If you had bothered to read the relevant blog postings before ignorantly commenting, you would know that I have been trying to get the T to fix these errors for over six years; my stunt at South Station was a last-ditch effort to shake loose an appropriate response from the T.&quot;

I did read them, and there&#039;s no reason to insult me.

My point was that while you&#039;ve certainly spent plenty of time trying to get these problems fixed, it would be more effective to keep trying to reach the right people at the T (the Planning Department), than to try to give flyers to reporters at a press conference.

(And in fact, flyering didn&#039;t work, since they haven&#039;t fixed it yet as far as I can tell.)

You could also try writing to the Starts &amp; Stops column at the Globe.

I know several people who have successfully reached the right people at the T to address various issues.  One has even had several conversations with the General Manager.</description>
		<content:encoded><![CDATA[<p>(Apologies for the year+ delay in following up.)</p>
<p>&#8221; &#8216;Why don’t you instead focus your efforts on getting in touch with the T’s planning department, who are the people who can actually fix the mistake?&#8217;</p>
<p>If you had bothered to read the relevant blog postings before ignorantly commenting, you would know that I have been trying to get the T to fix these errors for over six years; my stunt at South Station was a last-ditch effort to shake loose an appropriate response from the T.&#8221;</p>
<p>I did read them, and there&#8217;s no reason to insult me.</p>
<p>My point was that while you&#8217;ve certainly spent plenty of time trying to get these problems fixed, it would be more effective to keep trying to reach the right people at the T (the Planning Department), than to try to give flyers to reporters at a press conference.</p>
<p>(And in fact, flyering didn&#8217;t work, since they haven&#8217;t fixed it yet as far as I can tell.)</p>
<p>You could also try writing to the Starts &amp; Stops column at the Globe.</p>
<p>I know several people who have successfully reached the right people at the T to address various issues.  One has even had several conversations with the General Manager.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
