<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Today's Fail Open Goat Award goes to: Insecure 3rd party software updaters</title><link>http://blogs.technet.com/robert_hensing/archive/2008/07/29/today-s-fail-open-goat-award-goes-to-insecure-3rd-party-software-updaters.aspx</link><description>You'll notice Microsoft's auto-updaters (Windows Update / Microsoft Update / Automatic Updates) are not on the list. Why? Because we're paranoid, and we anticipated this type of threat years ago and mitigated it by signing all of our binaries and only</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Insecure 3rd party software updaters</title><link>http://blogs.technet.com/robert_hensing/archive/2008/07/29/today-s-fail-open-goat-award-goes-to-insecure-3rd-party-software-updaters.aspx#3095407</link><pubDate>Tue, 29 Jul 2008 22:52:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3095407</guid><dc:creator>Michael Howard's Web Log</dc:creator><description>&lt;p&gt;Gotta love Robert's sarcasm .. but he's right.&lt;/p&gt;
</description></item><item><title>Il ne faut pas se moquer des erreurs d'autrui</title><link>http://blogs.technet.com/robert_hensing/archive/2008/07/29/today-s-fail-open-goat-award-goes-to-insecure-3rd-party-software-updaters.aspx#3096123</link><pubDate>Thu, 31 Jul 2008 17:55:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3096123</guid><dc:creator>pascals.blog</dc:creator><description>&lt;p&gt;...Mais quand m&amp;amp;#234;me. Combien de fois m'a-t-on demand&amp;amp;#233; comment Microsoft garantissait que les&lt;/p&gt;
</description></item><item><title>re: Today's Fail Open Goat Award goes to: Insecure 3rd party software updaters</title><link>http://blogs.technet.com/robert_hensing/archive/2008/07/29/today-s-fail-open-goat-award-goes-to-insecure-3rd-party-software-updaters.aspx#3103696</link><pubDate>Tue, 12 Aug 2008 01:17:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3103696</guid><dc:creator>Jorge_Aguinaga</dc:creator><description>&lt;p&gt;According to the University of Arizona, updating Linux distros has its own risks too. ( &lt;a rel="nofollow" target="_new" href="http://www.cs.arizona.edu/people/justin/packagemanagersecurity/attacks-on-package-managers.html"&gt;http://www.cs.arizona.edu/people/justin/packagemanagersecurity/attacks-on-package-managers.html&lt;/a&gt; )&lt;/p&gt;
</description></item></channel></rss>