<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Disclosing in a public forum is not whistle blowing</title>
	<atom:link href="http://www.mckeay.net/2008/05/29/disclosing-in-a-public-forum-is-not-whistle-blowing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mckeay.net/2008/05/29/disclosing-in-a-public-forum-is-not-whistle-blowing/</link>
	<description>The views of one man on security, privacy and anything else that catches his attention</description>
	<pubDate>Fri, 21 Nov 2008 19:45:57 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>By: Brian Greer</title>
		<link>http://www.mckeay.net/2008/05/29/disclosing-in-a-public-forum-is-not-whistle-blowing/#comment-2048</link>
		<dc:creator>Brian Greer</dc:creator>
		<pubDate>Sun, 01 Jun 2008 13:11:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/05/29/disclosing-in-a-public-forum-is-not-whistle-blowing/#comment-2048</guid>
		<description>You are spot on. Oddly enough, the only proper action in the whole story was the firing of this poor soul. Perhaps they will still have access to all the same servers/information though, since TJX apparently has terrible security policy (if any). I would've thought the notoriety and shame from their massive breach would have at least given the appearance of improvement. Sadly, they still think of themselves as an unfortunate victim that did nothing wrong, and therefore has no reason to change their ways.</description>
		<content:encoded><![CDATA[<p>You are spot on. Oddly enough, the only proper action in the whole story was the firing of this poor soul. Perhaps they will still have access to all the same servers/information though, since TJX apparently has terrible security policy (if any). I would&#8217;ve thought the notoriety and shame from their massive breach would have at least given the appearance of improvement. Sadly, they still think of themselves as an unfortunate victim that did nothing wrong, and therefore has no reason to change their ways.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Network Security Blog &#187; Look to the acquiring banks, not the PCI Security Council</title>
		<link>http://www.mckeay.net/2008/05/29/disclosing-in-a-public-forum-is-not-whistle-blowing/#comment-2031</link>
		<dc:creator>Network Security Blog &#187; Look to the acquiring banks, not the PCI Security Council</dc:creator>
		<pubDate>Sat, 31 May 2008 07:12:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/05/29/disclosing-in-a-public-forum-is-not-whistle-blowing/#comment-2031</guid>
		<description>[...] is continuing the conversation about the firing at TJX and reporting Payment Card Industries &#8216;violations&#8217; to someone. I want to pause the [...]</description>
		<content:encoded><![CDATA[<p>[...] is continuing the conversation about the firing at TJX and reporting Payment Card Industries &#8216;violations&#8217; to someone. I want to pause the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Network Security Blog &#187; Who you gonna run to?</title>
		<link>http://www.mckeay.net/2008/05/29/disclosing-in-a-public-forum-is-not-whistle-blowing/#comment-2017</link>
		<dc:creator>Network Security Blog &#187; Who you gonna run to?</dc:creator>
		<pubDate>Fri, 30 May 2008 05:59:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/05/29/disclosing-in-a-public-forum-is-not-whistle-blowing/#comment-2017</guid>
		<description>[...] Shimel faults me for saying sometimes you just have to walk away, in reference to TJX firing Cryptic_Mauler (the upper/lower case stuff is too much for me to type [...]</description>
		<content:encoded><![CDATA[<p>[...] Shimel faults me for saying sometimes you just have to walk away, in reference to TJX firing Cryptic_Mauler (the upper/lower case stuff is too much for me to type [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: StillSecure, After All These Years</title>
		<link>http://www.mckeay.net/2008/05/29/disclosing-in-a-public-forum-is-not-whistle-blowing/#comment-2015</link>
		<dc:creator>StillSecure, After All These Years</dc:creator>
		<pubDate>Fri, 30 May 2008 02:11:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.mckeay.net/2008/05/29/disclosing-in-a-public-forum-is-not-whistle-blowing/#comment-2015</guid>
		<description>&lt;strong&gt;When do you have an obligation to go public?...&lt;/strong&gt;

...</description>
		<content:encoded><![CDATA[<p><strong>When do you have an obligation to go public?&#8230;</strong></p>
<p>&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
