<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Refaktor blog &#187; security</title>
	<atom:link href="http://www.refaktor.si/blog/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.refaktor.si/blog</link>
	<description>Haps and mishaps of yet anothe web company</description>
	<lastBuildDate>Sat, 10 Oct 2009 11:43:46 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Security and priorities!</title>
		<link>http://www.refaktor.si/blog/2009/10/security-and-priorities/</link>
		<comments>http://www.refaktor.si/blog/2009/10/security-and-priorities/#comments</comments>
		<pubDate>Sat, 10 Oct 2009 02:40:29 +0000</pubDate>
		<dc:creator>Janko</dc:creator>
				<category><![CDATA[cebelca.biz]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[products]]></category>
		<category><![CDATA[risks]]></category>

		<guid isPermaLink="false">http://www.refaktor.si/blog/?p=71</guid>
		<description><![CDATA[I was visiting a web page of some invoicing / time tracking web-app and saw this text in their FAQ:
&#8220;In the very unlikely event of a security incident, we’d be in more peril of someone duplicating our application and attempting to resell it than you losing your data or someone stealing your identity.&#8221;
Eeeee&#8230; wrong answer!! [...]]]></description>
			<content:encoded><![CDATA[<p>I was visiting a web page of some invoicing / <a class="zem_slink" href="http://en.wikipedia.org/wiki/Timesheet" title="Timesheet" rel="wikipedia">time tracking</a> web-app and saw this text in their FAQ:</p>
<blockquote><p>&#8220;In the very unlikely event of a <a class="zem_slink" href="http://en.wikipedia.org/wiki/Security" title="Security" rel="wikipedia">security</a> incident, we’d be in more peril of someone duplicating our <a class="zem_slink" href="http://en.wikipedia.org/wiki/Application_software" title="Application software" rel="wikipedia">application</a> and attempting to resell it than you losing your data or someone stealing your identity.&#8221;</p></blockquote>
<p>Eeeee&#8230; wrong answer!! Totally!!!</p>
<p>Well, the service seems very solid otherwise so maybe it&#8217;s just a case of not well thought out <a class="zem_slink" href="http://en.wikipedia.org/wiki/Public_relations" title="Public relations" rel="wikipedia">PR</a>.</p>
<p><strong>Security is a very complex subject..</strong><br />
You can never simply cover all the corners and go to sleep. There are no absolutes. Linear/feed forward thinking of do/pay more/better to get more in not very effective. It&#8217;s about being smart, creating a system that will <strong>by design</strong> minimize <b>certain</b> problems (better than other problems).</p>
<p>So although you really want <strong>none</strong> of security issues to happen, you must get a very clear priority of things you want to prevent. </p>
<p>At cebelca.biz which is a local <a class="zem_slink" href="http://en.wikipedia.org/wiki/Small_business" title="Small business" rel="wikipedia">small business</a> application the priorities are (from most important to least, number is the level of importance from 100 to 0):</p>
<ol>
<dt>100</dt>
<dd>A hacker gets to data of our users.</dd>
<dt>95</dt>
<dd>A hacker destroys the data of our users.</dd>
<dt>35</dt>
<dd>A hacker for noticeable period disables our service.</dd>
<dt>20</dt>
<dd>A hacker gets the <a class="zem_slink" href="http://en.wikipedia.org/wiki/Source_code" title="Source code" rel="wikipedia">source code</a> of our application.</dd>
</ol>
<p>To me, our users data is of <strong>top</strong> priority, they trusted us with their data. And our source code&#8230; meh&#8230; capable developers want to code and design their solutions according to their ideas, not copy someone else&#8217;s stuff and get a outdated copy of something that already exists.</p>
<div style="margin-top: 10px; height: 15px;" class="zemanta-pixie"><a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/c30d3bea-9bca-417f-bae4-7f9b5650a22f/" title="Reblog this post [with Zemanta]"><img style="border: medium none ; float: right;" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=c30d3bea-9bca-417f-bae4-7f9b5650a22f" alt="Reblog this post [with Zemanta]"></a><span class="zem-script more-related pretty-attribution"><script type="text/javascript" src="http://static.zemanta.com/readside/loader.js" defer="defer"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.refaktor.si/blog/2009/10/security-and-priorities/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
