<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress Plug-In &#8211; TweetBacks “Considered Harmful”</title>
	<atom:link href="http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/</link>
	<description>Small Business Internet Marketing Consultant</description>
	<lastBuildDate>Thu, 09 Jul 2009 06:25:38 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Cheri Sigmon, CISSP</title>
		<link>http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/comment-page-1/#comment-458</link>
		<dc:creator>Cheri Sigmon, CISSP</dc:creator>
		<pubDate>Mon, 09 Mar 2009 06:58:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/#comment-458</guid>
		<description>Interesting thread... esp&#039;ly this convo about &quot;responsible disclosure.&quot; As an information security professional, we discuss this often and we do have fiduciary and ethical responsibilities that an average &quot;consumer&quot; would NOT.

Therefore, Dave has no obligation to discuss a perceived security vulnerability with the developer FIRST. He CAN if he wishes, but the 1st step is to *contain* potential risks.
Hope it works out OK; plugins often equal attack vectors.

Cheri</description>
		<content:encoded><![CDATA[<p>Interesting thread&#8230; esp&#8217;ly this convo about &#8220;responsible disclosure.&#8221; As an information security professional, we discuss this often and we do have fiduciary and ethical responsibilities that an average &#8220;consumer&#8221; would NOT.</p>
<p>Therefore, Dave has no obligation to discuss a perceived security vulnerability with the developer FIRST. He CAN if he wishes, but the 1st step is to *contain* potential risks.<br />
Hope it works out OK; plugins often equal attack vectors.</p>
<p>Cheri</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Herb Stalk</title>
		<link>http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/comment-page-1/#comment-379</link>
		<dc:creator>Herb Stalk</dc:creator>
		<pubDate>Wed, 18 Feb 2009 04:33:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/#comment-379</guid>
		<description>Great catch! Probably saved a lot of people a lot of headaches</description>
		<content:encoded><![CDATA[<p>Great catch! Probably saved a lot of people a lot of headaches</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sheila</title>
		<link>http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/comment-page-1/#comment-375</link>
		<dc:creator>Sheila</dc:creator>
		<pubDate>Tue, 17 Feb 2009 20:43:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/#comment-375</guid>
		<description>First of All, Daiv, I love your blog. I don&#039;t think you did anything wrong  or punitive what your post, It&#039;s FREE. Just like any product/service free or paid for, there are going to be good reviews and bad reviews. 
It&#039;s your Blog and you can post anything you want. If you want to do a review on something you found faulty, why should you take YOUR time to call the developer. They should not have sent it out without first beta testing it with friends/family. My husband always beta test something before sending out to the world and we always go back to it and make sure it&#039;s working properly even after it&#039;s sent out to the world to use. 

I know that we have tried to contact a developer on a product/service that had a flaw and do you know that I spent &quot;4&quot; Freakin hours trying to get through to them, not to mention all the emails, Waste of my time to help someone out. So what ever!
Can we say REVIEW and that is exactly what you did, you reviewed a product/service. 
They need to fix it and get over it.
Just because of the smart asses that commented against you, I will NEVER use that plugin and I will let others know to not use it either.</description>
		<content:encoded><![CDATA[<p>First of All, Daiv, I love your blog. I don&#8217;t think you did anything wrong  or punitive what your post, It&#8217;s FREE. Just like any product/service free or paid for, there are going to be good reviews and bad reviews.<br />
It&#8217;s your Blog and you can post anything you want. If you want to do a review on something you found faulty, why should you take YOUR time to call the developer. They should not have sent it out without first beta testing it with friends/family. My husband always beta test something before sending out to the world and we always go back to it and make sure it&#8217;s working properly even after it&#8217;s sent out to the world to use. </p>
<p>I know that we have tried to contact a developer on a product/service that had a flaw and do you know that I spent &#8220;4&#8243; Freakin hours trying to get through to them, not to mention all the emails, Waste of my time to help someone out. So what ever!<br />
Can we say REVIEW and that is exactly what you did, you reviewed a product/service.<br />
They need to fix it and get over it.<br />
Just because of the smart asses that commented against you, I will NEVER use that plugin and I will let others know to not use it either.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Allen</title>
		<link>http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/comment-page-1/#comment-339</link>
		<dc:creator>Scott Allen</dc:creator>
		<pubDate>Fri, 06 Feb 2009 21:36:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/#comment-339</guid>
		<description>@Guillermo: If we were dealing with a car I would agree, but when there is a potential security issue, the procedure has to be different.

By all means disable what you feel is the problem. You own the site, you are free to do as you please. But when dealing with a potential security flaw, you have to contact the developer first and give them a few days to investigate and if fix it if the problem is legit. By posting before doing that, you give unethical people several days head start to exploit the issue before the developer can fix it. This causes more problems because then a LOT more people can get exploited. I would say if the developer didn&#039;t respond after a couple days (and you&#039;ve made a thorough attempt to contact them), then by all means post about it. Otherwise the post should wait to come until the developer has had a fair chance to fix it.

Like I said, security issues are different than other kinds of problems with web apps.</description>
		<content:encoded><![CDATA[<p>@Guillermo: If we were dealing with a car I would agree, but when there is a potential security issue, the procedure has to be different.</p>
<p>By all means disable what you feel is the problem. You own the site, you are free to do as you please. But when dealing with a potential security flaw, you have to contact the developer first and give them a few days to investigate and if fix it if the problem is legit. By posting before doing that, you give unethical people several days head start to exploit the issue before the developer can fix it. This causes more problems because then a LOT more people can get exploited. I would say if the developer didn&#8217;t respond after a couple days (and you&#8217;ve made a thorough attempt to contact them), then by all means post about it. Otherwise the post should wait to come until the developer has had a fair chance to fix it.</p>
<p>Like I said, security issues are different than other kinds of problems with web apps.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Guillermo</title>
		<link>http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/comment-page-1/#comment-338</link>
		<dc:creator>Guillermo</dc:creator>
		<pubDate>Fri, 06 Feb 2009 18:40:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/#comment-338</guid>
		<description>You did the right thing. I&#039;ve been in the developer&#039;s position before, and my initial response was
similar to his; but the fact of the matter is this: This is the real world. If you were in a Ford, and your wheels came off without warning, you&#039;d be within your rights to complain to the entire known world before even sending as much as a tweet to the company.
Developers (again, myself included) want to be taken seriously, and want for their industry to be taken seriously, but many aren&#039;t mature enough for the sort
responsibility and scrutiny that comes with creating a product. So... don&#039;t worry. Daiv still rawks.</description>
		<content:encoded><![CDATA[<p>You did the right thing. I&#8217;ve been in the developer&#8217;s position before, and my initial response was<br />
similar to his; but the fact of the matter is this: This is the real world. If you were in a Ford, and your wheels came off without warning, you&#8217;d be within your rights to complain to the entire known world before even sending as much as a tweet to the company.<br />
Developers (again, myself included) want to be taken seriously, and want for their industry to be taken seriously, but many aren&#8217;t mature enough for the sort<br />
responsibility and scrutiny that comes with creating a product. So&#8230; don&#8217;t worry. Daiv still rawks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kyle Reddoch</title>
		<link>http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/comment-page-1/#comment-322</link>
		<dc:creator>Kyle Reddoch</dc:creator>
		<pubDate>Fri, 06 Feb 2009 02:17:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/#comment-322</guid>
		<description>Okay, I have now uninstalled the Tweetback plugin for WP...

Thanks for the advanced warning again!</description>
		<content:encoded><![CDATA[<p>Okay, I have now uninstalled the Tweetback plugin for WP&#8230;</p>
<p>Thanks for the advanced warning again!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: So Much More Than A Mom</title>
		<link>http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/comment-page-1/#comment-321</link>
		<dc:creator>So Much More Than A Mom</dc:creator>
		<pubDate>Fri, 06 Feb 2009 02:17:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/#comment-321</guid>
		<description>I can&#039;t even begin to imagine how anyone could take offense to anything in this post.</description>
		<content:encoded><![CDATA[<p>I can&#8217;t even begin to imagine how anyone could take offense to anything in this post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JenniferBhalaHansen</title>
		<link>http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/comment-page-1/#comment-320</link>
		<dc:creator>JenniferBhalaHansen</dc:creator>
		<pubDate>Fri, 06 Feb 2009 02:10:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/#comment-320</guid>
		<description>I was about to use tweetback. Not any more. Thanks for the warning</description>
		<content:encoded><![CDATA[<p>I was about to use tweetback. Not any more. Thanks for the warning</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen</title>
		<link>http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/comment-page-1/#comment-313</link>
		<dc:creator>Stephen</dc:creator>
		<pubDate>Thu, 05 Feb 2009 21:32:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/#comment-313</guid>
		<description>I am as befuddled as you and others at the response of the developer here.

While I&#039;m very happy that you&#039;ve both made contact with one another and that this will likely be very productive, I can&#039;t see how the average blogger - one who&#039;s NOT a tech geek, in my case  - would be obligated to track down the developer and start &quot;talking tech&quot; about the issues behind it. (I&#039;m so low-tech, I use blogger, actually)

As a consumer, I simply consume. The creator of a product is responsible for flaws in their products or services, and, on occasion, suffers bad publicity about it, as they surely did when you recommended NOT to install this particular version of  the plug-in.

The customer should never be made to feel that its his or her job  to hunt down the developer and for THEM to apologize for a flaw in THEIR product. 

I think someone&#039;s got that backwards if they feel otherwise.

@nhprman on twitter</description>
		<content:encoded><![CDATA[<p>I am as befuddled as you and others at the response of the developer here.</p>
<p>While I&#8217;m very happy that you&#8217;ve both made contact with one another and that this will likely be very productive, I can&#8217;t see how the average blogger &#8211; one who&#8217;s NOT a tech geek, in my case  &#8211; would be obligated to track down the developer and start &#8220;talking tech&#8221; about the issues behind it. (I&#8217;m so low-tech, I use blogger, actually)</p>
<p>As a consumer, I simply consume. The creator of a product is responsible for flaws in their products or services, and, on occasion, suffers bad publicity about it, as they surely did when you recommended NOT to install this particular version of  the plug-in.</p>
<p>The customer should never be made to feel that its his or her job  to hunt down the developer and for THEM to apologize for a flaw in THEIR product. </p>
<p>I think someone&#8217;s got that backwards if they feel otherwise.</p>
<p>@nhprman on twitter</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dr. Gianmichael Salvato</title>
		<link>http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/comment-page-1/#comment-312</link>
		<dc:creator>Dr. Gianmichael Salvato</dc:creator>
		<pubDate>Thu, 05 Feb 2009 20:37:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.Ninja-Nerd.com/wordpress-plug-in-tweetbacks-considered-harmful/#comment-312</guid>
		<description>Thanks, Daiv. I think it&#039;s patently ABSURD that anyone suggest that you were being &quot;punitive&quot;. Like it or not, when the author of a plug-in releases a plug-in with vulnerabilities, they are culpable for the vulnerability. 

There was nothing malicious or unprofessional about your post. You provide a valuable b2b service and I&#039;m certain I am not the only one who hopes you&#039;ll continue, undaunted. 

-- Gianmichael
@gianmichael on twitter</description>
		<content:encoded><![CDATA[<p>Thanks, Daiv. I think it&#8217;s patently ABSURD that anyone suggest that you were being &#8220;punitive&#8221;. Like it or not, when the author of a plug-in releases a plug-in with vulnerabilities, they are culpable for the vulnerability. </p>
<p>There was nothing malicious or unprofessional about your post. You provide a valuable b2b service and I&#8217;m certain I am not the only one who hopes you&#8217;ll continue, undaunted. </p>
<p>&#8211; Gianmichael<br />
@gianmichael on twitter</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic page generated in 0.192 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2010-07-30 11:47:39 -->
