<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Phishing your own users?</title>
	<atom:link href="http://infosecplace.com/blog/2007/01/08/phishing-your-own-users/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecplace.com/blog/2007/01/08/phishing-your-own-users/</link>
	<description>Commentary on the State of Information Security</description>
	<lastBuildDate>Sun, 10 Jan 2010 16:13:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Marcin Wielgoszewski</title>
		<link>http://infosecplace.com/blog/2007/01/08/phishing-your-own-users/comment-page-1/#comment-6828</link>
		<dc:creator>Marcin Wielgoszewski</dc:creator>
		<pubDate>Tue, 09 Jan 2007 15:37:47 +0000</pubDate>
		<guid isPermaLink="false">http://infosecplace.com/blog/2007/01/08/phishing-your-own-users/#comment-6828</guid>
		<description>A couple other things to consider regarding this kind of testing: How is the information going to be handled afterward? How do they plan on scheming their users? If they send out Ebay, Bank of America, or Chase phishing emails, the data they might get back could be very sensitive.

Like you said, incriminating users just makes them hate you even more. We don&#039;t need anymore hate, hehe :p</description>
		<content:encoded><![CDATA[<p>A couple other things to consider regarding this kind of testing: How is the information going to be handled afterward? How do they plan on scheming their users? If they send out Ebay, Bank of America, or Chase phishing emails, the data they might get back could be very sensitive.</p>
<p>Like you said, incriminating users just makes them hate you even more. We don&#8217;t need anymore hate, hehe :p</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tssci security &#187; This is horrible, this idea: &#8220;Phishing your own users&#8221;</title>
		<link>http://infosecplace.com/blog/2007/01/08/phishing-your-own-users/comment-page-1/#comment-6811</link>
		<dc:creator>tssci security &#187; This is horrible, this idea: &#8220;Phishing your own users&#8221;</dc:creator>
		<pubDate>Tue, 09 Jan 2007 05:13:22 +0000</pubDate>
		<guid isPermaLink="false">http://infosecplace.com/blog/2007/01/08/phishing-your-own-users/#comment-6811</guid>
		<description>[...] I see Michael Farnum has responded to Terry Sweeney&#8217;s blog post on Phishing your own users. I would just like to remind everyone that while intentions may be good, remember the times people have tried this tactic with viruses. How many times did someone write a virus that removes viruses or one that enables a security feature? Or how about testing the effectiveness of an anti-virus solution by distributing to users a file (containing a virus) that says &#8220;DO_NOT_OPEN_ME&#8221; ? [...]</description>
		<content:encoded><![CDATA[<p>[...] I see Michael Farnum has responded to Terry Sweeney&#8217;s blog post on Phishing your own users. I would just like to remind everyone that while intentions may be good, remember the times people have tried this tactic with viruses. How many times did someone write a virus that removes viruses or one that enables a security feature? Or how about testing the effectiveness of an anti-virus solution by distributing to users a file (containing a virus) that says &#8220;DO_NOT_OPEN_ME&#8221; ? [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
