<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Firefox 3 Untimely Security Advisory</title>
	<link>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Sun, 21 Mar 2010 20:34:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: hackademix.net » Yahoo!'s Attitude Encouraging Zero Day Full Disclosure?</title>
		<link>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8444</link>
		<dc:creator>hackademix.net » Yahoo!'s Attitude Encouraging Zero Day Full Disclosure?</dc:creator>
		<pubDate>Tue, 01 Jul 2008 14:51:47 +0000</pubDate>
		<guid>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8444</guid>
		<description>[...] processes, and “reward” reporters, not necessarily with money prizes, which may become dangerous when they feed an anonymous, uncontrolled vulnerability brokerage market. Most of these guys would [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] processes, and “reward” reporters, not necessarily with money prizes, which may become dangerous when they feed an anonymous, uncontrolled vulnerability brokerage market. Most of these guys would [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MJR's slef-reflections: Firefox 3, day 6: security flaw and banks</title>
		<link>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8354</link>
		<dc:creator>MJR's slef-reflections: Firefox 3, day 6: security flaw and banks</dc:creator>
		<pubDate>Mon, 23 Jun 2008 13:06:40 +0000</pubDate>
		<guid>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8354</guid>
		<description>[...] didn't spot this when I wrote my last post, but it seems there's a security alert for FF3 already - hackademix.net: Firefox 3 Untimely Security Advisory - but it also affects FF2 and probably my cautious Javascript settings are enough to stop it [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] didn&#8217;t spot this when I wrote my last post, but it seems there&#8217;s a security alert for FF3 already - hackademix.net: Firefox 3 Untimely Security Advisory - but it also affects FF2 and probably my cautious Javascript settings are enough to stop it [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ADH</title>
		<link>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8345</link>
		<dc:creator>ADH</dc:creator>
		<pubDate>Sun, 22 Jun 2008 16:36:52 +0000</pubDate>
		<guid>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8345</guid>
		<description>It happens many a times that there are some bugs in the old foundation(reusable modules) of software products which gets exposed when newer software versions are build on it. This case is very common with Windows. When Vista is tested for some attack/security hole , its also found to affecting XP. 
   Such incidences proves the need of thorough and continuous regression of the foundational classes/reusable modules.</description>
		<content:encoded><![CDATA[<p>It happens many a times that there are some bugs in the old foundation(reusable modules) of software products which gets exposed when newer software versions are build on it. This case is very common with Windows. When Vista is tested for some attack/security hole , its also found to affecting XP.<br />
   Such incidences proves the need of thorough and continuous regression of the foundational classes/reusable modules.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert Accettura</title>
		<link>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8310</link>
		<dc:creator>Robert Accettura</dc:creator>
		<pubDate>Fri, 20 Jun 2008 00:14:51 +0000</pubDate>
		<guid>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8310</guid>
		<description>I'm not a conspiracy theorist.  I'm a skeptic. ;-)</description>
		<content:encoded><![CDATA[<p>I&#8217;m not a conspiracy theorist.  I&#8217;m a skeptic. ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Primera vulnerabilidad en Firefox 3 « HispaSystem Group Blog</title>
		<link>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8305</link>
		<dc:creator>Primera vulnerabilidad en Firefox 3 « HispaSystem Group Blog</dc:creator>
		<pubDate>Thu, 19 Jun 2008 21:34:26 +0000</pubDate>
		<guid>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8305</guid>
		<description>[...] Mozilla ya investiga el asunto. Según Giorgio Maone, una vez más los usuarios de NoScript estarían a salvo [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Mozilla ya investiga el asunto. Según Giorgio Maone, una vez más los usuarios de NoScript estarían a salvo [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8303</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Thu, 19 Jun 2008 20:05:21 +0000</pubDate>
		<guid>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8303</guid>
		<description>*Exactly* the same thing (although not tipping point) happened with wordpress 2.5 as well. 

It seems fashionable to find bugs in RC releases and wait until RELEASE to publish them.</description>
		<content:encoded><![CDATA[<p>*Exactly* the same thing (although not tipping point) happened with wordpress 2.5 as well. </p>
<p>It seems fashionable to find bugs in RC releases and wait until RELEASE to publish them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firefox 3: una vulnerabilidad está siendo investigada &#124; Zona Firefox</title>
		<link>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8302</link>
		<dc:creator>Firefox 3: una vulnerabilidad está siendo investigada &#124; Zona Firefox</dc:creator>
		<pubDate>Thu, 19 Jun 2008 18:50:54 +0000</pubDate>
		<guid>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8302</guid>
		<description>[...] la delantera en tan embarazoso rubro, pero si te preocupa este problema siempre puedes seguir la recomendación de Giorgio Maone: instalar [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] la delantera en tan embarazoso rubro, pero si te preocupa este problema siempre puedes seguir la recomendación de Giorgio Maone: instalar [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8299</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Thu, 19 Jun 2008 17:35:11 +0000</pubDate>
		<guid>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8299</guid>
		<description>@&lt;b&gt;Mark Downling&lt;/b&gt;:
&lt;blockquote&gt;release did flush it out before autoupdate kicked in for the 2.0.x stream, which is nice…&lt;/blockquote&gt;
Not sure, why exactly is it nice, considered that this bug affects Firefox 2.0.x as well?</description>
		<content:encoded><![CDATA[<p>@<b>Mark Downling</b>:</p>
<blockquote><p>release did flush it out before autoupdate kicked in for the 2.0.x stream, which is nice…</p></blockquote>
<p>Not sure, why exactly is it nice, considered that this bug affects Firefox 2.0.x as well?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Dowling</title>
		<link>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8298</link>
		<dc:creator>Mark Dowling</dc:creator>
		<pubDate>Thu, 19 Jun 2008 17:28:33 +0000</pubDate>
		<guid>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8298</guid>
		<description>It might be untimely but I have no doubt that it was, in fact, timed by those who found it to appear on/after Download Day rather than reported during the RC process.  I wonder if there's a way to tweak bug bounties so that RC bugs get more $$...

That said, release did flush it out before autoupdate kicked in for the 2.0.x stream, which is nice...</description>
		<content:encoded><![CDATA[<p>It might be untimely but I have no doubt that it was, in fact, timed by those who found it to appear on/after Download Day rather than reported during the RC process.  I wonder if there&#8217;s a way to tweak bug bounties so that RC bugs get more $$&#8230;</p>
<p>That said, release did flush it out before autoupdate kicked in for the 2.0.x stream, which is nice&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Congrats to Mozilla’s Download Day « I’m Just an Avatar</title>
		<link>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8297</link>
		<dc:creator>Congrats to Mozilla’s Download Day « I’m Just an Avatar</dc:creator>
		<pubDate>Thu, 19 Jun 2008 14:57:27 +0000</pubDate>
		<guid>http://hackademix.net/2008/06/19/firefox-3-untimely-security-advisory/#comment-8297</guid>
		<description>[...] the news is not all good for Firefox 3, as the first vulnerability was announced while millions of people were still helping go for the record. Window Snyder, [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] the news is not all good for Firefox 3, as the first vulnerability was announced while millions of people were still helping go for the record. Window Snyder, [&#8230;]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
