Quote
you are obviously just some forum jerk who enjoys the anonymity
signed,
Sestus
Oh the irony.. and did your boss 'instruct' the world in general, or just you?
Let me go ahead and re-cap what has gone on here, for archival sake:
You posted:
Quote
Had the above user performed the same test the following day, he would have seen that there are no SQL injection issues related to the product.
Which lucky for me, I copied it before you edited your own post, and then I made the comment of:
Quote
Sounds to me like a new policy needs to be in place for doing server updates/upgrades. There's absolutely 0 chance that I would turn off the majority of protections to my public facing servers to do an upgrade.
You replied with:
Quote
Our demo website is just that, a simple demo website. No financial, customer, or other sensitive information can be accessed from this demo website.
and then some babble about not needing to be as secure as the real thing, blah blah blah...
I then wrote:
Quote
Attacker finds demo site, demo site vulnerable. Attacker injects malware, malware then gets transferred to admins machine due to vulnerable browser, admin then visits 'live site' logging in with 'admin' credentials, admin gets called away to one of those really interesting meetings, attacker sees idle time, attacker takes control of browser and 'admin session'..
Of course there was no direct response from you, but then you began to insult the users of this forum by posting this:
Quote
This forum serves as a sounding board for individuals who claim an understanding of security, yet it is clear that many cannot differentiate between security method and application. One does not install a two ton magnetic-lock vault door to protect access to a backyard storage shed.
Then I mention how I was still laughing so hard that I could barely type, then again you went on the offensive and posted this:
Quote
We're sorry that you took offense at our response. We were sincerely trying to assist you with understanding the proper application of security techniques. There is such a thing as too much security and when a process does not warrant a certain level of security, adding that security becomes counter-productive.
To which I responded to this:
Quote
There could never be too much security for a company that claims to know security and privacy. But then that's the difference between those who know security and the managers that just quote snippets from press releases.
And then your ignorant response was this:
Quote
By your misguided logic, every website in the would must employ SSL certificates, challenge questions, risk-based analysis, geo-location analysis, hardware and software tokens, captchas, and anything else you can think of. After all, you believe "There could never be too much security".
and then ranted about considering this thread closed a few times.. A couple of other people also commented on your ignorant statements, and then you chose to insult them as well:
Quote
You seem to be missing the basic point. Perhaps this concept is beyond you, but I will make one last attempt to explain....
And then you ranted about bologna and the space shuttle, and all the while I was not posting at all, but then you posted this:
Quote
We're through with this. There are just some people you can't reach.
Post away folks. If anyone has a legitimate question re: PhishCops(R), you may contact us through our regular websites.
And:
Quote
I am required to maintain (as much as possible) a civil tone, but sometimes that is very difficult when dealing with such idiots.
And at this point I pointed out the fact that these forums, along with other sites, are dedicated to Web App Security and not product support for your product. Regardless of who started the thread, and what their question was, this site remains a WebAppSec forum, not PhishCops(R) support or Q&A. I am almost positive that the user who requested OUR opinion on your software was fully aware that he could contact you for a WebEx demonstration, but instead wanted to get input from members of this forum, which unfortunately for you, includes me.
As for the anonymity you claim I am hiding behind, my name is [censored], you can see my picture
HERE and if you want my Cell Phone number, just let me know and I will gladly send you a private message on this board, and if you are ever in Sunnyvale or Mountain View, California areas, please by all means look me up.
Now with whom have I had the pleasure of rolling in the mud with?
--thrill
---
It is not the degrees you hold, but the mind you possess. - thrill
Edited 1 time(s). Last edit at 06/14/2008 12:19AM by thrill.