<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: David Lichtfield in the Oracle cross-hairs (again…)</title>
	<atom:link href="http://www.slaviks-blog.com/2010/02/03/david-lichtfield-in-the-oracle-cross-hairs-again%e2%80%a6/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.slaviks-blog.com/2010/02/03/david-lichtfield-in-the-oracle-cross-hairs-again%e2%80%a6/</link>
	<description>Slavik&#039;s Blog</description>
	<lastBuildDate>Wed, 14 Dec 2011 10:35:06 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Slavik</title>
		<link>http://www.slaviks-blog.com/2010/02/03/david-lichtfield-in-the-oracle-cross-hairs-again%e2%80%a6/comment-page-1/#comment-4239</link>
		<dc:creator>Slavik</dc:creator>
		<pubDate>Thu, 11 Feb 2010 20:28:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=221#comment-4239</guid>
		<description>David, sorry for misinterpreting your intentions.
I completely understand how this might have happened.
Oracle usually communicates with the security researchers a few weeks ahead of the patch to tell them if their found vulnerability was patched in the upcoming CPU and I can see how this is not enough time to change speaking arrangements.
I&#039;m wondering if you had any communication with Oracle regarding the Black Hat. AFAIK, Oracle gives precedence to public (or would-be public) vulnerabilities.

Thanks for correcting my mistake,
Slavik</description>
		<content:encoded><![CDATA[<p>David, sorry for misinterpreting your intentions.<br />
I completely understand how this might have happened.<br />
Oracle usually communicates with the security researchers a few weeks ahead of the patch to tell them if their found vulnerability was patched in the upcoming CPU and I can see how this is not enough time to change speaking arrangements.<br />
I&#8217;m wondering if you had any communication with Oracle regarding the Black Hat. AFAIK, Oracle gives precedence to public (or would-be public) vulnerabilities.</p>
<p>Thanks for correcting my mistake,<br />
Slavik</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Litchfield</title>
		<link>http://www.slaviks-blog.com/2010/02/03/david-lichtfield-in-the-oracle-cross-hairs-again%e2%80%a6/comment-page-1/#comment-4234</link>
		<dc:creator>David Litchfield</dc:creator>
		<pubDate>Thu, 11 Feb 2010 09:05:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.slaviks-blog.com/?p=221#comment-4234</guid>
		<description>Actually you&#039;re wrong about why I spoke about the flaws. I informed Oracle of these flaws on October 11th (I said November in my speech off the top of my head). I just assumed they&#039;d get it fixed in time for the January CPU - it is a trivial fix afterall. So I submitted these as the basis of the Black Hat talk in November. And since I&#039;m retiring from the vulnerability research side of things I was clearing the decks so to speak. The process Oracle has with vuln researchers isn&#039;t broken - I wasn&#039;t dissatisified - but I&#039;d committed to speak about the issues. Simply that. I don&#039;t have a bone to pick with Oracle anymore.
Cheers,
David Litchfield</description>
		<content:encoded><![CDATA[<p>Actually you&#8217;re wrong about why I spoke about the flaws. I informed Oracle of these flaws on October 11th (I said November in my speech off the top of my head). I just assumed they&#8217;d get it fixed in time for the January CPU &#8211; it is a trivial fix afterall. So I submitted these as the basis of the Black Hat talk in November. And since I&#8217;m retiring from the vulnerability research side of things I was clearing the decks so to speak. The process Oracle has with vuln researchers isn&#8217;t broken &#8211; I wasn&#8217;t dissatisified &#8211; but I&#8217;d committed to speak about the issues. Simply that. I don&#8217;t have a bone to pick with Oracle anymore.<br />
Cheers,<br />
David Litchfield</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.254 seconds -->

