<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Thoughts about OpenOffice</title>
	<atom:link href="http://www.securitycurve.com/wordpress/archives/429/feed" rel="self" type="application/rss+xml" />
	<link>http://www.securitycurve.com/wordpress/archives/429?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=thoughts-about-openoffice</link>
	<description></description>
	<lastBuildDate>Thu, 26 Jan 2012 14:33:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Iang</title>
		<link>http://www.securitycurve.com/wordpress/archives/429/comment-page-1#comment-34</link>
		<dc:creator>Iang</dc:creator>
		<pubDate>Fri, 18 Aug 2006 09:05:02 +0000</pubDate>
		<guid isPermaLink="false">http://securitycurve.com/wordpress/?p=429#comment-34</guid>
		<description>There are security projects and then there are projects that talk about security.  In the former group are projects like BSDs/SSH.  In the latter camp are things like general user tools.  In this case OO, MO, and also e.g., browsers.

The projects that aren&#039;t security are often seduced into talking about security, and soon get themselves in a mess.  It&#039;s important to understand that these projects do not have security as a goal;  and unless and until they decide and positively elect to take on security as a goal, they are doing what we might characterise as a middle-order, reactive form of security.  That is, fixing bugs and trying not to slow down the good work in other areas too much.

We are talking about ... the office and what users do there.  In this sense, the reports just indicate furious agreement that these projects are not security projects, and won&#039;t pass muster if treated as security projects.
</description>
		<content:encoded><![CDATA[<p>There are security projects and then there are projects that talk about security.  In the former group are projects like BSDs/SSH.  In the latter camp are things like general user tools.  In this case OO, MO, and also e.g., browsers.</p>
<p>The projects that aren&#8217;t security are often seduced into talking about security, and soon get themselves in a mess.  It&#8217;s important to understand that these projects do not have security as a goal;  and unless and until they decide and positively elect to take on security as a goal, they are doing what we might characterise as a middle-order, reactive form of security.  That is, fixing bugs and trying not to slow down the good work in other areas too much.</p>
<p>We are talking about &#8230; the office and what users do there.  In this sense, the reports just indicate furious agreement that these projects are not security projects, and won&#8217;t pass muster if treated as security projects.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.securitycurve.com/wordpress/archives/429/comment-page-1#comment-33</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Thu, 17 Aug 2006 21:29:18 +0000</pubDate>
		<guid isPermaLink="false">http://securitycurve.com/wordpress/?p=429#comment-33</guid>
		<description>OO could very well be less secure than MSO, but I will continue to use OO all the time it is the minority player in the Office Marketplace.
MSO and OO are only as dangerous as the people using and abusing them.
I have both MSO and OO, but prefer OO for reasons such as stability and cost, not for security.
Any lack of faith in the security of OO is nothing to do with the fact it is OpenSource. Far from it.
Mine is from a pure security aspect.  If you swapped all users with MSO over to OO, and all the OO users to MSO, OO would become the tartget of the hackers.  OO would suddenly have a user base more capable of finding the issues that usually remain hidden, (no matter how good you think the test coverage is, give a million monkeys a Moveable Type installation and you&#039;ll have the complete works of Shakespeare in a week or so).
I&#039;d prefer to remain security conscious no matter what I am using...
</description>
		<content:encoded><![CDATA[<p>OO could very well be less secure than MSO, but I will continue to use OO all the time it is the minority player in the Office Marketplace.<br />
MSO and OO are only as dangerous as the people using and abusing them.<br />
I have both MSO and OO, but prefer OO for reasons such as stability and cost, not for security.<br />
Any lack of faith in the security of OO is nothing to do with the fact it is OpenSource. Far from it.<br />
Mine is from a pure security aspect.  If you swapped all users with MSO over to OO, and all the OO users to MSO, OO would become the tartget of the hackers.  OO would suddenly have a user base more capable of finding the issues that usually remain hidden, (no matter how good you think the test coverage is, give a million monkeys a Moveable Type installation and you&#8217;ll have the complete works of Shakespeare in a week or so).<br />
I&#8217;d prefer to remain security conscious no matter what I am using&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

