<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Coyote Tracks &#187; XSS</title>
	<atom:link href="http://kagan.mactane.org/blog/tag/xss/feed/" rel="self" type="application/rss+xml" />
	<link>http://kagan.mactane.org/blog</link>
	<description>The prints of an Internet-enabled coyote.</description>
	<lastBuildDate>Tue, 31 Jan 2012 03:26:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>McAfee: Failing at Security Since 2005</title>
		<link>http://kagan.mactane.org/blog/2009/05/05/mcafee-failing-at-security-since-2005/</link>
		<comments>http://kagan.mactane.org/blog/2009/05/05/mcafee-failing-at-security-since-2005/#comments</comments>
		<pubDate>Tue, 05 May 2009 17:37:42 +0000</pubDate>
		<dc:creator>Kai MacTane</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[hall of shame]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[XSS]]></category>
		<category><![CDATA[you fail]]></category>

		<guid isPermaLink="false">http://kai.mactane.org/blog/2009/05/05/mcafee-failing-at-security-since-2005/</guid>
		<description><![CDATA[Back in 2005, I was a &#8220;geek for hire&#8221; and did a lot of general troubleshooting for end-users. Including malware removal and general PC tune-ups. One client wanted me to install some software, including McAfee&#8217;s main end-user product at the time&#160;&#8212; I don&#8217;t recall the name. I do recall, however, that my head nearly exploded [...]]]></description>
			<content:encoded><![CDATA[<p>Back in 2005, I was a &#8220;geek for hire&#8221; and did a lot of general troubleshooting for end-users. Including malware removal and general PC tune-ups. One client wanted me to install some software, including McAfee&#8217;s main end-user product at the time&nbsp;&mdash; I don&#8217;t recall the name.</p>
<p>I <em>do</em> recall, however, that my head nearly exploded when I found that the product required the user to <em>turn on</em> ActiveX&#8230; and not even restrict it to local execution only! I informed the client (with as little ranting as I could) that this was an extremely bad idea, and strongly advised that he get a different security software suite, and ditch the McAfee product as quickly as he could.</p>
<p><a href="http://www.readwriteweb.com/archives/mcafee_enabling_malware_distribution_and_fraud.php">It seems that McAfee has not improved their security practices since then.</a> People are saying that a security company should know better. I agree, but I&#8217;m not all that surprised; this just looks like more of the same stuff I saw from them back in &#8217;05.</p>
]]></content:encoded>
			<wfw:commentRss>http://kagan.mactane.org/blog/2009/05/05/mcafee-failing-at-security-since-2005/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

