<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Computer Security</title>
	<atom:link href="http://timworstall.com/2008/07/23/computer-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://timworstall.com/2008/07/23/computer-security/</link>
	<description>It is all obvious or trivial except...</description>
	<lastBuildDate>Thu, 24 May 2012 19:11:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: That Asprox Virus&#8230; &#124; Tim Almond</title>
		<link>http://timworstall.com/2008/07/23/computer-security/comment-page-1/#comment-19087</link>
		<dc:creator>That Asprox Virus&#8230; &#124; Tim Almond</dc:creator>
		<pubDate>Wed, 23 Jul 2008 21:01:42 +0000</pubDate>
		<guid isPermaLink="false">http://timworstall.com/2008/07/23/computer-security/#comment-19087</guid>
		<description>[...] H/T Tim Worstall [...]</description>
		<content:encoded><![CDATA[<p>[...] H/T Tim Worstall [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TomJ</title>
		<link>http://timworstall.com/2008/07/23/computer-security/comment-page-1/#comment-19051</link>
		<dc:creator>TomJ</dc:creator>
		<pubDate>Wed, 23 Jul 2008 16:50:37 +0000</pubDate>
		<guid isPermaLink="false">http://timworstall.com/2008/07/23/computer-security/#comment-19051</guid>
		<description>http://xkcd.com/327/

8-)</description>
		<content:encoded><![CDATA[<p><a href="http://xkcd.com/327/" rel="nofollow">http://xkcd.com/327/</a></p>
<p> <img src='http://timworstall.com/wp-includes/images/smilies/icon_cool.gif' alt='8-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JuliaM</title>
		<link>http://timworstall.com/2008/07/23/computer-security/comment-page-1/#comment-19033</link>
		<dc:creator>JuliaM</dc:creator>
		<pubDate>Wed, 23 Jul 2008 15:12:31 +0000</pubDate>
		<guid isPermaLink="false">http://timworstall.com/2008/07/23/computer-security/#comment-19033</guid>
		<description>&lt;i&gt;&quot;which is also why the government frequently pays major agencies amounts for web development that make people here say “I could have done that for fifty quid”. Yes, you could, &lt;b&gt;but the government can’t show you won’t screw it up&lt;/b&gt;.&quot;&lt;/i&gt;

Given the lax way the government usually writes its IT contracts, not only can they not show that the private company won&#039;t screw it up &lt;i&gt;either&lt;/i&gt;, but if they do, they usually can&#039;t/won&#039;t charge them any penalty...</description>
		<content:encoded><![CDATA[<p><i>&#8220;which is also why the government frequently pays major agencies amounts for web development that make people here say “I could have done that for fifty quid”. Yes, you could, <b>but the government can’t show you won’t screw it up</b>.&#8221;</i></p>
<p>Given the lax way the government usually writes its IT contracts, not only can they not show that the private company won&#8217;t screw it up <i>either</i>, but if they do, they usually can&#8217;t/won&#8217;t charge them any penalty&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter Risdon</title>
		<link>http://timworstall.com/2008/07/23/computer-security/comment-page-1/#comment-19017</link>
		<dc:creator>Peter Risdon</dc:creator>
		<pubDate>Wed, 23 Jul 2008 13:48:07 +0000</pubDate>
		<guid isPermaLink="false">http://timworstall.com/2008/07/23/computer-security/#comment-19017</guid>
		<description>It&#039;s unacceptable in a junior web developer. I&#039;ve explained why &lt;a href=&quot;http://freebornjohn.blogspot.com/2008/07/government-it-watch.html&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt;. MTAS was even worse. 

Government agencies routinely pay much more for development than private companies would consider for the same project. I know this from differentials in contract values I&#039;ve had myself.</description>
		<content:encoded><![CDATA[<p>It&#8217;s unacceptable in a junior web developer. I&#8217;ve explained why <a href="http://freebornjohn.blogspot.com/2008/07/government-it-watch.html" rel="nofollow">here</a>. MTAS was even worse. </p>
<p>Government agencies routinely pay much more for development than private companies would consider for the same project. I know this from differentials in contract values I&#8217;ve had myself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Almond</title>
		<link>http://timworstall.com/2008/07/23/computer-security/comment-page-1/#comment-19003</link>
		<dc:creator>Tim Almond</dc:creator>
		<pubDate>Wed, 23 Jul 2008 12:41:05 +0000</pubDate>
		<guid isPermaLink="false">http://timworstall.com/2008/07/23/computer-security/#comment-19003</guid>
		<description>john b,

&quot;which is also why the government frequently pays major agencies amounts for web development that make people here say “I could have done that for fifty quid”.&quot;

Well, not £50, but MTAS cost £1.75 million for the 1st year. For that, I&#039;d expect to have a system built where someone couldn&#039;t just change the URL and read someone else&#039;s mailbox.</description>
		<content:encoded><![CDATA[<p>john b,</p>
<p>&#8220;which is also why the government frequently pays major agencies amounts for web development that make people here say “I could have done that for fifty quid”.&#8221;</p>
<p>Well, not £50, but MTAS cost £1.75 million for the 1st year. For that, I&#8217;d expect to have a system built where someone couldn&#8217;t just change the URL and read someone else&#8217;s mailbox.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: john b</title>
		<link>http://timworstall.com/2008/07/23/computer-security/comment-page-1/#comment-18984</link>
		<dc:creator>john b</dc:creator>
		<pubDate>Wed, 23 Jul 2008 11:21:12 +0000</pubDate>
		<guid isPermaLink="false">http://timworstall.com/2008/07/23/computer-security/#comment-18984</guid>
		<description>...which is why this has only appeared in places like Hackney Council&#039;s recruitment site, rather than anything secure or high-profile. It&#039;ll be cases where the junior web monkey has been told &quot;can you knock up this site, the contractors would charge us a fortune and take a month&quot;.

(which is also why the government frequently pays major agencies amounts for web development that make people here say &quot;I could have done that for fifty quid&quot;. Yes, you could, but the government can&#039;t show you won&#039;t screw it up.)</description>
		<content:encoded><![CDATA[<p>&#8230;which is why this has only appeared in places like Hackney Council&#8217;s recruitment site, rather than anything secure or high-profile. It&#8217;ll be cases where the junior web monkey has been told &#8220;can you knock up this site, the contractors would charge us a fortune and take a month&#8221;.</p>
<p>(which is also why the government frequently pays major agencies amounts for web development that make people here say &#8220;I could have done that for fifty quid&#8221;. Yes, you could, but the government can&#8217;t show you won&#8217;t screw it up.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Almond</title>
		<link>http://timworstall.com/2008/07/23/computer-security/comment-page-1/#comment-18967</link>
		<dc:creator>Tim Almond</dc:creator>
		<pubDate>Wed, 23 Jul 2008 09:51:01 +0000</pubDate>
		<guid isPermaLink="false">http://timworstall.com/2008/07/23/computer-security/#comment-18967</guid>
		<description>It&#039;s what&#039;s known in the trade as a SQL injection attack . If you don&#039;t write your database code in quite the right way, your database can be vulnerable.

It&#039;s an error that I might expect a junior programmer to make, but I wouldn&#039;t expect a project manager or senior developer on a web project to be ignorant of it.</description>
		<content:encoded><![CDATA[<p>It&#8217;s what&#8217;s known in the trade as a SQL injection attack . If you don&#8217;t write your database code in quite the right way, your database can be vulnerable.</p>
<p>It&#8217;s an error that I might expect a junior programmer to make, but I wouldn&#8217;t expect a project manager or senior developer on a web project to be ignorant of it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Object Caching 256/256 objects using disk: basic

Served from: timworstall.com @ 2012-05-24 22:27:43 -->
