<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Black, White or Grey? What colour hat do you wear?</title>
	<atom:link href="http://blog.jabawoki.com/2010/02/25/black-white-or-grey-what-colour-hat-do-you-wear/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.jabawoki.com/2010/02/25/black-white-or-grey-what-colour-hat-do-you-wear/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=black-white-or-grey-what-colour-hat-do-you-wear</link>
	<description>Nothing to see here, move along...</description>
	<lastBuildDate>Tue, 10 Jan 2012 12:18:18 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: SF</title>
		<link>http://blog.jabawoki.com/2010/02/25/black-white-or-grey-what-colour-hat-do-you-wear/comment-page-1/#comment-116</link>
		<dc:creator>SF</dc:creator>
		<pubDate>Mon, 12 Apr 2010 14:26:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jabawoki.com/?p=1740#comment-116</guid>
		<description>Just to add the laws that govern these acts make no ref to intent and I think unfairly some people have fallen foul of the law for just being inquisitive shall we say. Perhaps performing a simple directory traversal attempt on a tsunami charity site for example! (one instant) When if they really had a criminal intent\goal they have skills which would not fall so easily ie TOR\cantenna\spoofs etc. An example was required and made... I think motivation and threat capability is often forgotten to easily, which I debated with an ISO27001 lecturer recently in actual fact. The ISO feeling was that it was not a factor in risk criteria. My reply &quot;As Willie Sutton the bank robber said when asked why he robbed banks, &#039;because that&#039;s where the money is&#039;.&quot;</description>
		<content:encoded><![CDATA[<p>Just to add the laws that govern these acts make no ref to intent and I think unfairly some people have fallen foul of the law for just being inquisitive shall we say. Perhaps performing a simple directory traversal attempt on a tsunami charity site for example! (one instant) When if they really had a criminal intent\goal they have skills which would not fall so easily ie TOR\cantenna\spoofs etc. An example was required and made&#8230; I think motivation and threat capability is often forgotten to easily, which I debated with an ISO27001 lecturer recently in actual fact. The ISO feeling was that it was not a factor in risk criteria. My reply &#8220;As Willie Sutton the bank robber said when asked why he robbed banks, &#8216;because that&#8217;s where the money is&#8217;.&#8221;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
