<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8954966646386655038.post3199542270491264400..comments</id><updated>2009-03-12T21:59:34.447-04:00</updated><category term='IT Security'/><category term='Government 2.0 Security'/><category term='SRF'/><category term='Web Application Security'/><category term='Web 2.0 Security'/><category term='Certification and Accreditation'/><category term='Security Requirements Framework'/><category term='SDLC Security'/><category term='Security Requirements'/><category term='FISMA'/><category term='Secure SDLC'/><category term='Security Resources'/><category term='Security Budget'/><category term='Security Innovation'/><category term='FISMA 2.0'/><category term='Web Application Security 2.0'/><category term='QA Security'/><category term='WAS 2.0'/><title type='text'>Comments on Jason Yuen - "Understanding Information Security": WAS 2.0 - Are you ready?</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.jason-yuen.com/feeds/3199542270491264400/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/3199542270491264400/comments/default'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/02/was-20-are-you-ready.html'/><author><name>Jason Yuen</name><uri>http://www.blogger.com/profile/01689037743235268269</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_aVbrSQzZtzw/SXCVKavNwmI/AAAAAAAAAts/ARE75ujHsoM/S220/untitled.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8954966646386655038.post-8805534042399812526</id><published>2009-02-13T13:12:00.001-05:00</published><updated>2009-02-13T13:12:00.001-05:00</updated><title type='text'>Jason: As always, well said on a great topic. Anot...</title><content type='html'>Jason: As always, well said on a great topic. Another concern we have is the risk and attack factors associate with Web 2.0. Most of Web app security problems are instigated by user inputs. And the focus on RIA/Web 2.0 is all about user generated content, which broadens the attack surfaces. Also in some cases, a same existing attack can cause bigger impact on Web 2.0 environment than 1.0. For example, clickjacking is not that big of a deal in Web 1.0.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/3199542270491264400/comments/default/8805534042399812526'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/3199542270491264400/comments/default/8805534042399812526'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/02/was-20-are-you-ready.html?showComment=1234548720001#c8805534042399812526' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.jason-yuen.com/2009/02/was-20-are-you-ready.html' ref='tag:blogger.com,1999:blog-8954966646386655038.post-3199542270491264400' source='http://www.blogger.com/feeds/8954966646386655038/posts/default/3199542270491264400' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1443305907'/></entry></feed>
