<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: How to report a security hole to Microsoft</title>
	<atom:link href="http://www.squarefree.com/2004/03/10/how-to-report-a-security-hole-to-microsoft/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.squarefree.com/2004/03/10/how-to-report-a-security-hole-to-microsoft/</link>
	<description>Jesse Ruderman on Firefox, security, and more</description>
	<pubDate>Tue, 06 Jan 2009 13:19:32 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
		<item>
		<title>By: Jan!</title>
		<link>http://www.squarefree.com/2004/03/10/how-to-report-a-security-hole-to-microsoft/#comment-405</link>
		<dc:creator>Jan!</dc:creator>
		<pubDate>Tue, 30 Nov 1999 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/test/wp15/wordpress/?p=116#comment-405</guid>
		<description>So the bug is in both Opera and IE, but not in Gecko-based browsers? Is it a serious one, as in: could it be exploited to make Bad Things happen?

(PS: Please fix your tabindex order so I can tab from this textarea to the submit button)

(Also, when previewing this comment, I got the followin error at the bottom of the page, under "Previous Comments": "MT::App::Comments=HASH(0x81051bc) Use of uninitialized value in sprintf at lib/MT/Template/Context.pm line 1187.")</description>
		<content:encoded><![CDATA[<p>So the bug is in both Opera and IE, but not in Gecko-based browsers? Is it a serious one, as in: could it be exploited to make Bad Things happen?</p>
<p>(PS: Please fix your tabindex order so I can tab from this textarea to the submit button)</p>
<p>(Also, when previewing this comment, I got the followin error at the bottom of the page, under &#8220;Previous Comments&#8221;: &#8220;MT::App::Comments=HASH(0&#215;81051bc) Use of uninitialized value in sprintf at lib/MT/Template/Context.pm line 1187.&#8221;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Paradise</title>
		<link>http://www.squarefree.com/2004/03/10/how-to-report-a-security-hole-to-microsoft/#comment-406</link>
		<dc:creator>Paul Paradise</dc:creator>
		<pubDate>Tue, 30 Nov 1999 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/test/wp15/wordpress/?p=116#comment-406</guid>
		<description>If you actually have a problem getting ahold of Microsoft for something important, don't forget your friendly alumni. Given I work there, I can probably forward something along and get it noticed way more easily.

-Paul</description>
		<content:encoded><![CDATA[<p>If you actually have a problem getting ahold of Microsoft for something important, don&#8217;t forget your friendly alumni. Given I work there, I can probably forward something along and get it noticed way more easily.</p>
<p>-Paul</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hao2lian</title>
		<link>http://www.squarefree.com/2004/03/10/how-to-report-a-security-hole-to-microsoft/#comment-407</link>
		<dc:creator>hao2lian</dc:creator>
		<pubDate>Tue, 30 Nov 1999 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/test/wp15/wordpress/?p=116#comment-407</guid>
		<description>Skywriting above the Redmond company usually works.</description>
		<content:encoded><![CDATA[<p>Skywriting above the Redmond company usually works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jesse Ruderman</title>
		<link>http://www.squarefree.com/2004/03/10/how-to-report-a-security-hole-to-microsoft/#comment-408</link>
		<dc:creator>Jesse Ruderman</dc:creator>
		<pubDate>Tue, 30 Nov 1999 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.squarefree.com/test/wp15/wordpress/?p=116#comment-408</guid>
		<description>I reported the hole using Microsoft's wish form and did not get a response.  I also reported it by e-mailing Paul and did not get a response.  I finally got a response from Microsoft after reporting the hole using Microsoft Premier Support. I was not satisfied with the response, but at least I know that someone at Microsoft read it.

Today I found &lt;a href="http://channel9.msdn.com/ShowPost.aspx?PostID=11308,"&gt;http://channel9.msdn.com/ShowPost.aspx?PostID=11308,&lt;/a&gt; which says that the correct way to report a security hole is to e-mail secure@microsoft.com. I'll try that next time I find a hole in IE.
</description>
		<content:encoded><![CDATA[<p>I reported the hole using Microsoft&#8217;s wish form and did not get a response.  I also reported it by e-mailing Paul and did not get a response.  I finally got a response from Microsoft after reporting the hole using Microsoft Premier Support. I was not satisfied with the response, but at least I know that someone at Microsoft read it.</p>
<p>Today I found <a href="http://channel9.msdn.com/ShowPost.aspx?PostID=11308,"></a><a href="http://channel9.msdn.com/ShowPost.aspx?PostID=11308" rel="nofollow">http://channel9.msdn.com/ShowPost.aspx?PostID=11308</a>, which says that the correct way to report a security hole is to e-mail <a href="mailto:secure@microsoft.com">secure@microsoft.com</a>. I&#8217;ll try that next time I find a hole in IE.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
