<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Spinnin&#8217; Yarns</title>
	<atom:link href="http://www.securitycurve.com/wordpress/archives/415/feed" rel="self" type="application/rss+xml" />
	<link>http://www.securitycurve.com/wordpress/archives/415?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=spinnin-yarns</link>
	<description></description>
	<lastBuildDate>Thu, 26 Jan 2012 14:33:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Starfan</title>
		<link>http://www.securitycurve.com/wordpress/archives/415/comment-page-1#comment-22</link>
		<dc:creator>Starfan</dc:creator>
		<pubDate>Fri, 17 Nov 2006 23:14:11 +0000</pubDate>
		<guid isPermaLink="false">http://securitycurve.com/wordpress/?p=415#comment-22</guid>
		<description>You know, I&#039;ve been looking all over the place for a security minded blogger to address SGC certs.  These are nothing more than fools gold being sold to network and security &quot;professionals&quot; who don&#039;t take a little bit of time to analyze whether or not they are a good fit for their organization.

Currently, I&#039;m in a debate with some of my peers about their usefulness.  CAs quote that these certs will ensure 99.9% protection.  What they fail to mention is that SGC technology is extremely limited in scope and that all the right pieces must be at play in order for it to be useful at all.  Old browsers on machines capable of 128bit encryption...Win2k boxes WITHOUT at least SP4.  It has a very specific application that is probably not applicable to most of the security pros that buy into its usefulness today.

If I had a multitude of users overseas who had not done a thing to update their PC since mid-2000, I might be able to convice myself to buy into the hype.  Otherwise, the actual segment of clients that would need SGC technology is probably less than 1%...and they can&#039;t use SGC anyway!

I&#039;m finished ranting! :)  Thanks for your post.
</description>
		<content:encoded><![CDATA[<p>You know, I&#8217;ve been looking all over the place for a security minded blogger to address SGC certs.  These are nothing more than fools gold being sold to network and security &#8220;professionals&#8221; who don&#8217;t take a little bit of time to analyze whether or not they are a good fit for their organization.</p>
<p>Currently, I&#8217;m in a debate with some of my peers about their usefulness.  CAs quote that these certs will ensure 99.9% protection.  What they fail to mention is that SGC technology is extremely limited in scope and that all the right pieces must be at play in order for it to be useful at all.  Old browsers on machines capable of 128bit encryption&#8230;Win2k boxes WITHOUT at least SP4.  It has a very specific application that is probably not applicable to most of the security pros that buy into its usefulness today.</p>
<p>If I had a multitude of users overseas who had not done a thing to update their PC since mid-2000, I might be able to convice myself to buy into the hype.  Otherwise, the actual segment of clients that would need SGC technology is probably less than 1%&#8230;and they can&#8217;t use SGC anyway!</p>
<p>I&#8217;m finished ranting! <img src='http://www.securitycurve.com/wordpress/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />   Thanks for your post.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

