<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Protecting the protection code</title>
	<atom:link href="http://rdist.root.org/2007/03/23/protecting-the-protection-code/feed/" rel="self" type="application/rss+xml" />
	<link>http://rdist.root.org/2007/03/23/protecting-the-protection-code/</link>
	<description>Embedded security, crypto, software protection</description>
	<lastBuildDate>Tue, 16 Mar 2010 03:16:39 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Nate Lawson</title>
		<link>http://rdist.root.org/2007/03/23/protecting-the-protection-code/#comment-6</link>
		<dc:creator>Nate Lawson</dc:creator>
		<pubDate>Wed, 28 Mar 2007 23:10:20 +0000</pubDate>
		<guid isPermaLink="false">http://rdist.root.org/2007/03/23/protecting-the-protection-code/#comment-6</guid>
		<description>Thanks for the comments.  Sorry for the delay -- I wasn&#039;t checking for moderation requests because I didn&#039;t think I needed to.  I&#039;ll keep on it in the future.

Regarding malware targeting forensic tools, there&#039;s some active research in that area, and I expect to see more in the future.  It is somewhat mitigated by the fact that attackers only have one shot at compromising the tools so it&#039;s not as tempting in terms of controlling the forensic computer.  However, in terms of hiding from forensic tools, that seems more interesting since the tool vendors would have to be actively involved in more investigations to find these exploits.</description>
		<content:encoded><![CDATA[<p>Thanks for the comments.  Sorry for the delay &#8212; I wasn&#8217;t checking for moderation requests because I didn&#8217;t think I needed to.  I&#8217;ll keep on it in the future.</p>
<p>Regarding malware targeting forensic tools, there&#8217;s some active research in that area, and I expect to see more in the future.  It is somewhat mitigated by the fact that attackers only have one shot at compromising the tools so it&#8217;s not as tempting in terms of controlling the forensic computer.  However, in terms of hiding from forensic tools, that seems more interesting since the tool vendors would have to be actively involved in more investigations to find these exploits.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Bowie</title>
		<link>http://rdist.root.org/2007/03/23/protecting-the-protection-code/#comment-3</link>
		<dc:creator>Jon Bowie</dc:creator>
		<pubDate>Sat, 24 Mar 2007 14:30:31 +0000</pubDate>
		<guid isPermaLink="false">http://rdist.root.org/2007/03/23/protecting-the-protection-code/#comment-3</guid>
		<description>And once again a layered approach to solving security problems prevails as best practice.  Excellent series of posts so far, I look forward to reading more of them.</description>
		<content:encoded><![CDATA[<p>And once again a layered approach to solving security problems prevails as best practice.  Excellent series of posts so far, I look forward to reading more of them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Rohlf</title>
		<link>http://rdist.root.org/2007/03/23/protecting-the-protection-code/#comment-2</link>
		<dc:creator>Chris Rohlf</dc:creator>
		<pubDate>Sat, 24 Mar 2007 13:42:56 +0000</pubDate>
		<guid isPermaLink="false">http://rdist.root.org/2007/03/23/protecting-the-protection-code/#comment-2</guid>
		<description>Great post Nate. Your comments section even has a built in spell checker, sweet.

Research into defeating analysis tools doesn&#039;t get the recognition it deserves. I write about it here and there on my blog. We rely heavily on analysis tools to pick apart malware, the second malware targets our tools were in for a rude awakening. Keep the posts coming :)</description>
		<content:encoded><![CDATA[<p>Great post Nate. Your comments section even has a built in spell checker, sweet.</p>
<p>Research into defeating analysis tools doesn&#8217;t get the recognition it deserves. I write about it here and there on my blog. We rely heavily on analysis tools to pick apart malware, the second malware targets our tools were in for a rude awakening. Keep the posts coming :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
