<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>mcwresearch.com &#187; Rant</title>
	<atom:link href="http://mcwresearch.com/archives/category/rant/feed" rel="self" type="application/rss+xml" />
	<link>http://mcwresearch.com</link>
	<description>Things I think I've thought about</description>
	<lastBuildDate>Thu, 07 Jan 2010 15:25:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>AV must innovate or die</title>
		<link>http://mcwresearch.com/archives/603</link>
		<comments>http://mcwresearch.com/archives/603#comments</comments>
		<pubDate>Fri, 08 Feb 2008 15:40:35 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[AV sucks]]></category>
		<category><![CDATA[Rant]]></category>
		<category><![CDATA[Antivirus]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/603</guid>
		<description><![CDATA[One of the things I&#8217;ve been doing with my HIPS software is take a closer look at my AV protection, or lack thereof.  I have HIPS on roughly 300 hosts on my network, which is a slice of about 1/5th of my entire host population.  I have the HIPS software pulling selected events [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/603/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Your AV *still* sucks and you know it&#8230;</title>
		<link>http://mcwresearch.com/archives/591</link>
		<comments>http://mcwresearch.com/archives/591#comments</comments>
		<pubDate>Thu, 03 Jan 2008 16:01:46 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[AV sucks]]></category>
		<category><![CDATA[Rant]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Antivirus]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/591</guid>
		<description><![CDATA[I posted an article back in April of &#8216;07 bemoaning the piss-poor performance of current antivirus technology and it looks like the mainstream guys are slowly picking it up as well.  
According to this article by PCWorld.com, their tests showed that &#8220;the best performer detected only one in four new malware samples.&#8221;  Catching [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/591/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Bruce the blowhard</title>
		<link>http://mcwresearch.com/archives/582</link>
		<comments>http://mcwresearch.com/archives/582#comments</comments>
		<pubDate>Wed, 05 Dec 2007 15:40:41 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Rant]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/582</guid>
		<description><![CDATA[I haven&#8217;t figured out yet what the fascination is with Bruce Schneier.  A friend sent me a link to a Q&#038;A with Bruce the almighty and his answer to the first question immediately turned me off.  The very first question boiled down to &#8216;what will be the most incredible technology in 50 years?&#8217; [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/582/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>the Leopard needs tamed</title>
		<link>http://mcwresearch.com/archives/564</link>
		<comments>http://mcwresearch.com/archives/564#comments</comments>
		<pubDate>Thu, 08 Nov 2007 16:29:15 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[All-things-apple]]></category>
		<category><![CDATA[Rant]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/564</guid>
		<description><![CDATA[Me:I&#8217;m having serious second thoughts about Leopard.  After updating iTunes and Quicktime yesterday, I&#8217;ve had three separate apps go tits-up.
Luke: really?
Me: yeah, really.  It feels more like a fucking windows machine now.  

I&#8217;ve had three separate applications hang since applying the iTunes and Quicktime updates yesterday plus a kernel panic last night. [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/564/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bloatware = h@x0rdware</title>
		<link>http://mcwresearch.com/archives/559</link>
		<comments>http://mcwresearch.com/archives/559#comments</comments>
		<pubDate>Mon, 22 Oct 2007 22:21:56 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Rant]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/559</guid>
		<description><![CDATA[This is one example of why software can be so vulnerable.  Below is output from a HIPS log on one our laptops:
The process &#8216;C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE&#8217; (as user SCRUBBED\joe.soap) attempted to initiate a connection as a client on TCP port 21 to XX.XX.XX.XX. The process was added to the application class FTP Client Software.
Why [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/559/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>What&#8217;s a Bot? (the un-lazy definition)</title>
		<link>http://mcwresearch.com/archives/501</link>
		<comments>http://mcwresearch.com/archives/501#comments</comments>
		<pubDate>Thu, 28 Jun 2007 14:43:17 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Rant]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/501</guid>
		<description><![CDATA[Michael over at An Information Security Place has taken a bit of flack for calling out Douglas Schweitzer for a lazy and inaccurate (my words not Michael&#8217;s) definition of what a &#8216;bot&#8217; is.
I chimed in on Michael&#8217;s behalf to agree that saying a bot is &#8220;essentially just another term for an infected computer&#8221; is only [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/501/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>You speaka my language?</title>
		<link>http://mcwresearch.com/archives/479</link>
		<comments>http://mcwresearch.com/archives/479#comments</comments>
		<pubDate>Thu, 24 May 2007 11:37:25 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Rant]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/479</guid>
		<description><![CDATA[I&#8217;ve been working a problem for several weeks now between vendor X&#8217;s UTM device and vendor Y&#8217;s firewall device.  To bring you up to speed; we recently started deploying UTM devices to our satellite offices.  Since each of our offices has its own link to the Intarweb, we have a VPN mesh for [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/479/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8216;Upgrade your firmware&#8217; is support-speak for &#8216;I have no friggin&#8217; clue&#8217;</title>
		<link>http://mcwresearch.com/archives/468</link>
		<comments>http://mcwresearch.com/archives/468#comments</comments>
		<pubDate>Mon, 30 Apr 2007 19:39:34 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Rant]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/468</guid>
		<description><![CDATA[I really do hate when I&#8217;m trying to troubleshoot a problem with vendor support and they say something like &#8216;there&#8217;s a new upgrade available that addresses several problems relating to the one you&#8217;re having and we&#8217;d like you to upgrade.&#8217;
I seriously have never had a situation where upgrading firmware solved a problem.  ever 
I [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/468/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Radical Islam (OT)</title>
		<link>http://mcwresearch.com/archives/463</link>
		<comments>http://mcwresearch.com/archives/463#comments</comments>
		<pubDate>Thu, 19 Apr 2007 19:37:32 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Rant]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/463</guid>
		<description><![CDATA[I took a trip to Iran last summer and took this picture in one of their holy shrines.  In my description of the picture I mentioned the gorgeous architecture of the shrine but then said it was desecrated when the cleric lead the congregation through a chant of  &#8216;death to Israel, death to [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/463/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Messenger Spam still active (and effective!?)</title>
		<link>http://mcwresearch.com/archives/455</link>
		<comments>http://mcwresearch.com/archives/455#comments</comments>
		<pubDate>Wed, 11 Apr 2007 21:16:49 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Rant]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/455</guid>
		<description><![CDATA[I am working with a guy here who is troubleshooting a connection through our firewalls so I&#8217;m grep&#8217;ing through live firewall logs.  Almost immediately after placing his host online it was getting bombarded with connection attempts, likely connection attempts to entire blocks, not just our host specifically (I could tell if I actually looked [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/455/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
