<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Vietnamese Language Pack FAQ</title>
	<atom:link href="http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/</link>
	<description></description>
	<pubDate>Sun, 20 Jul 2008 00:38:56 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Aljullu</title>
		<link>http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-334</link>
		<dc:creator>Aljullu</dc:creator>
		<pubDate>Mon, 12 May 2008 11:15:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-334</guid>
		<description>@Dan Veditz, thank's, now I understand it ;-)</description>
		<content:encoded><![CDATA[<p>@Dan Veditz, thank&#8217;s, now I understand it ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marc Handelman</title>
		<link>http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-330</link>
		<dc:creator>Marc Handelman</dc:creator>
		<pubDate>Sun, 11 May 2008 19:01:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-330</guid>
		<description>Asa, in reality, the Wired post was an expose, in our opinion....It was not scathing, given the usual Wired view (as well as ours) given the source of the problem.

In our opinion, the verbiage utilized in the Wired blog Was expose like in nature, whilst our reporting linked not only to their post, but also to the Bugzilla link.  Granted,  Ryan also linked to Bugzilla in the blog. Our report was short and sweet.

If this is the only so-called fault you can scavenge from our post, I think we can live with that. 

Furthermore, as far as the rest of the argument, it begs the question. The real issue is all of this sorted out Quickly, Easily (Not Always, But Hopefully) and in the Open: clearly because of the lack of cruft in the code, and the openness of the work. Further proof in our eyes that Open Source is more secure, simply because of the People.

In fact, everyone, should be checking their system regularly, through a variety of methods, both automated and otherwise. The most important of all is what we promote daily. The simple utilization of Common Sense.</description>
		<content:encoded><![CDATA[<p>Asa, in reality, the Wired post was an expose, in our opinion&#8230;.It was not scathing, given the usual Wired view (as well as ours) given the source of the problem.</p>
<p>In our opinion, the verbiage utilized in the Wired blog Was expose like in nature, whilst our reporting linked not only to their post, but also to the Bugzilla link.  Granted,  Ryan also linked to Bugzilla in the blog. Our report was short and sweet.</p>
<p>If this is the only so-called fault you can scavenge from our post, I think we can live with that. </p>
<p>Furthermore, as far as the rest of the argument, it begs the question. The real issue is all of this sorted out Quickly, Easily (Not Always, But Hopefully) and in the Open: clearly because of the lack of cruft in the code, and the openness of the work. Further proof in our eyes that Open Source is more secure, simply because of the People.</p>
<p>In fact, everyone, should be checking their system regularly, through a variety of methods, both automated and otherwise. The most important of all is what we promote daily. The simple utilization of Common Sense.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Veditz</title>
		<link>http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-326</link>
		<dc:creator>Dan Veditz</dc:creator>
		<pubDate>Sat, 10 May 2008 08:07:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-326</guid>
		<description>@Aljullu: Virus scanners now detect the obfuscated web address of the ad site left in the help files, that's how the infection was found. It's like human doctors inferring the presence of a virus from antibodies.

Not only are we doing additional scans, we've identified that the help content viewer didn't need to render remote script in the first place and we'll be turning that off in the next update of Firefox 2 (bug 432919).</description>
		<content:encoded><![CDATA[<p>@Aljullu: Virus scanners now detect the obfuscated web address of the ad site left in the help files, that&#8217;s how the infection was found. It&#8217;s like human doctors inferring the presence of a virus from antibodies.</p>
<p>Not only are we doing additional scans, we&#8217;ve identified that the help content viewer didn&#8217;t need to render remote script in the first place and we&#8217;ll be turning that off in the next update of Firefox 2 (bug 432919).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aljullu</title>
		<link>http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-323</link>
		<dc:creator>Aljullu</dc:creator>
		<pubDate>Sat, 10 May 2008 05:14:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-323</guid>
		<description>@Asa, it can pass your tests because it isn't a virus for himself, it's only a website-fetching script. True?

And, what are you doing to solve it and this attack can't be repeated?

You say: "As a result of this incident, we’re implementing additional vulnerability scans at regular intervals after an add-on has been uploaded to help mitigate similar problems going forward." but, you didn't explain how it works.

Thank's for your time ;-)</description>
		<content:encoded><![CDATA[<p>@Asa, it can pass your tests because it isn&#8217;t a virus for himself, it&#8217;s only a website-fetching script. True?</p>
<p>And, what are you doing to solve it and this attack can&#8217;t be repeated?</p>
<p>You say: &#8220;As a result of this incident, we’re implementing additional vulnerability scans at regular intervals after an add-on has been uploaded to help mitigate similar problems going forward.&#8221; but, you didn&#8217;t explain how it works.</p>
<p>Thank&#8217;s for your time ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Asa</title>
		<link>http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-320</link>
		<dc:creator>Asa</dc:creator>
		<pubDate>Fri, 09 May 2008 22:57:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-320</guid>
		<description>@Marc Handelman, this post was "in response to a few of the misunderstandings that I came across in some of those articles and blogs." 

I don't think I accused you specifically of misunderstanding, though I'd personally dispute your characterization of the Wired blog post as "an exposé" :-)

As for users checking their machines thoroughly, of course they should; but that's really irrespective of this issue and should apply to every single internet connected computer and not just the tiny subset that you called out. Wouldn't you agree?</description>
		<content:encoded><![CDATA[<p>@Marc Handelman, this post was &#8220;in response to a few of the misunderstandings that I came across in some of those articles and blogs.&#8221; </p>
<p>I don&#8217;t think I accused you specifically of misunderstanding, though I&#8217;d personally dispute your characterization of the Wired blog post as &#8220;an exposé&#8221; :-)</p>
<p>As for users checking their machines thoroughly, of course they should; but that&#8217;s really irrespective of this issue and should apply to every single internet connected computer and not just the tiny subset that you called out. Wouldn&#8217;t you agree?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marc Handelman</title>
		<link>http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-319</link>
		<dc:creator>Marc Handelman</dc:creator>
		<pubDate>Fri, 09 May 2008 22:46:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-319</guid>
		<description>Thanks for discussing issues in your code base openly, no matter how crufty it may be...... Always a welcome, though, compared to closed source...on the other hand, there was no misunderstanding, regarding the issue at hand, or what was published on our site:  infosecurity.us, or the source site: Ryan Singels' wired.com blog 27bstroke6/. We suggested, in a very thoughtful manner, which you obviously missed, that everyone check their machines thoroughly. Always wise advise. Don't you agree?</description>
		<content:encoded><![CDATA[<p>Thanks for discussing issues in your code base openly, no matter how crufty it may be&#8230;&#8230; Always a welcome, though, compared to closed source&#8230;on the other hand, there was no misunderstanding, regarding the issue at hand, or what was published on our site:  infosecurity.us, or the source site: Ryan Singels&#8217; wired.com blog 27bstroke6/. We suggested, in a very thoughtful manner, which you obviously missed, that everyone check their machines thoroughly. Always wise advise. Don&#8217;t you agree?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Asa</title>
		<link>http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-318</link>
		<dc:creator>Asa</dc:creator>
		<pubDate>Fri, 09 May 2008 22:37:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-318</guid>
		<description>@ajay and @Fav Browser, no problem. I figure people deserve to see the coverage I saw if I'm going to call out press and blog coverage broadly.

@Morbus, market share is a priority for Mozilla. It's not _the priority_ for Mozilla but it absolutely is a priority. I don't think this incident hurts Firefox growth though. A very small number of people were impacted and the impact wasn't terrible. 

@tend, I think that's a more accurate description, but for most people, I don't think it works very well because the overwhelming majority of users don't understand the differences between viruses, worms, and trojans and many assume that trojan is just another word for virus when it's not. 

@Aljullu, if you read the original article and you read this post a bit more carefully, I think you'll  be able to answer that question for yourself.</description>
		<content:encoded><![CDATA[<p>@ajay and @Fav Browser, no problem. I figure people deserve to see the coverage I saw if I&#8217;m going to call out press and blog coverage broadly.</p>
<p>@Morbus, market share is a priority for Mozilla. It&#8217;s not _the priority_ for Mozilla but it absolutely is a priority. I don&#8217;t think this incident hurts Firefox growth though. A very small number of people were impacted and the impact wasn&#8217;t terrible. </p>
<p>@tend, I think that&#8217;s a more accurate description, but for most people, I don&#8217;t think it works very well because the overwhelming majority of users don&#8217;t understand the differences between viruses, worms, and trojans and many assume that trojan is just another word for virus when it&#8217;s not. </p>
<p>@Aljullu, if you read the original article and you read this post a bit more carefully, I think you&#8217;ll  be able to answer that question for yourself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aljullu</title>
		<link>http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-316</link>
		<dc:creator>Aljullu</dc:creator>
		<pubDate>Fri, 09 May 2008 20:22:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-316</guid>
		<description>Why can the malicious code pass your security tests?
http://firefoxcat.blogspot.com/2008/05/el-firefox-en-vietnamita-contenia-codi.html</description>
		<content:encoded><![CDATA[<p>Why can the malicious code pass your security tests?<br />
<a href="http://firefoxcat.blogspot.com/2008/05/el-firefox-en-vietnamita-contenia-codi.html" rel="nofollow">http://firefoxcat.blogspot.com/2008/05/el-firefox-en-vietnamita-contenia-codi.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fav Browser</title>
		<link>http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-315</link>
		<dc:creator>Fav Browser</dc:creator>
		<pubDate>Fri, 09 May 2008 19:57:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-315</guid>
		<description>Thanks for Fav as well.</description>
		<content:encoded><![CDATA[<p>Thanks for Fav as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tend</title>
		<link>http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-313</link>
		<dc:creator>tend</dc:creator>
		<pubDate>Fri, 09 May 2008 18:56:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/ftr/2008/05/08/vietnamese-language-pack-faq/#comment-313</guid>
		<description>it's not a virus, but it's a trojan because it loads contents from remote without user's consent: "This usually results in the user seeing unwanted ads, but may be used for more malicious actions."
http://blog.mozilla.com/security/2008/05/07/compromised-file-in-vietnamese-language-pack-for-firefox-2/</description>
		<content:encoded><![CDATA[<p>it&#8217;s not a virus, but it&#8217;s a trojan because it loads contents from remote without user&#8217;s consent: &#8220;This usually results in the user seeing unwanted ads, but may be used for more malicious actions.&#8221;<br />
<a href="http://blog.mozilla.com/security/2008/05/07/compromised-file-in-vietnamese-language-pack-for-firefox-2/" rel="nofollow">http://blog.mozilla.com/security/2008/05/07/compromised-file-in-vietnamese-language-pack-for-firefox-2/</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
