MIME-Version: 1.0
Content-Location: file:///C:/1EF44545/SolvingtheWebsecuritychallenge.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:v=3D"urn:schemas-microsoft-com:vml"
xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:w=3D"urn:schemas-microsoft-com:office:word"
xmlns:p=3D"urn:schemas-microsoft-com:office:powerpoint"
xmlns:oa=3D"urn:schemas-microsoft-com:office:activation"
xmlns:st1=3D"urn:schemas-microsoft-com:office:smarttags"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DWord.Document>
<meta name=3DGenerator content=3D"Microsoft Word 11">
<meta name=3DOriginator content=3D"Microsoft Word 11">
<link rel=3DFile-List href=3D"SolvingtheWebsecuritychallenge_files/filelist=
.xml">
<title>Solving the Web security challenge </title>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"PersonName"/>
<!--[if gte mso 9]><xml>
 <o:DocumentProperties>
  <o:Author>Vasana</o:Author>
  <o:Template>Normal</o:Template>
  <o:LastAuthor>Vasana</o:LastAuthor>
  <o:Revision>2</o:Revision>
  <o:TotalTime>47</o:TotalTime>
  <o:Created>2007-07-01T09:23:00Z</o:Created>
  <o:LastSaved>2007-07-01T09:23:00Z</o:LastSaved>
  <o:Pages>1</o:Pages>
  <o:Words>1945</o:Words>
  <o:Characters>11090</o:Characters>
  <o:Lines>92</o:Lines>
  <o:Paragraphs>26</o:Paragraphs>
  <o:CharactersWithSpaces>13009</o:CharactersWithSpaces>
  <o:Version>11.5606</o:Version>
 </o:DocumentProperties>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:WordDocument>
  <w:SpellingState>Clean</w:SpellingState>
  <w:GrammarState>Clean</w:GrammarState>
  <w:PunctuationKerning/>
  <w:ValidateAgainstSchemas/>
  <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>
  <w:IgnoreMixedContent>false</w:IgnoreMixedContent>
  <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>
  <w:Compatibility>
   <w:BreakWrappedTables/>
   <w:SnapToGridInCell/>
   <w:ApplyBreakingRules/>
   <w:WrapTextWithPunct/>
   <w:UseAsianBreakRules/>
   <w:DontGrowAutofit/>
  </w:Compatibility>
  <w:BrowserLevel>MicrosoftInternetExplorer4</w:BrowserLevel>
 </w:WordDocument>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:LatentStyles DefLockedState=3D"false" LatentStyleCount=3D"156">
 </w:LatentStyles>
</xml><![endif]--><!--[if !mso]><object
 classid=3D"clsid:38481807-CA0E-42D2-BF39-B33AF135CC4D" id=3Dieooui></objec=
t>
<style>
st1\:*{behavior:url(#ieooui) }
</style>
<![endif]-->
<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:"Angsana New";
	panose-1:2 2 6 3 5 4 5 2 3 4;
	mso-font-charset:0;
	mso-generic-font-family:roman;
	mso-font-pitch:variable;
	mso-font-signature:16777219 0 0 0 65537 0;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:1627421319 -2147483648 8 0 66047 0;}
@font-face
	{font-family:Verdana;
	panose-1:2 11 6 4 3 5 4 4 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:536871559 0 0 0 415 0;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-parent:"";
	margin:0cm;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	mso-bidi-font-size:14.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	mso-bidi-font-family:"Angsana New";}
h2
	{margin:0cm;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	mso-outline-level:2;
	font-size:9.0pt;
	font-family:Arial;
	mso-bidi-font-family:Tahoma;
	font-weight:bold;}
h3
	{margin-top:0cm;
	margin-right:0cm;
	margin-bottom:2.5pt;
	margin-left:0cm;
	mso-pagination:widow-orphan;
	mso-outline-level:3;
	font-size:10.0pt;
	font-family:Arial;
	mso-bidi-font-family:Tahoma;
	color:#66BB00;
	font-weight:normal;}
p
	{margin-top:0cm;
	margin-right:0cm;
	margin-bottom:5.0pt;
	margin-left:0cm;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:Tahoma;
	mso-fareast-font-family:"Times New Roman";}
span.SpellE
	{mso-style-name:"";
	mso-spl-e:yes;}
span.GramE
	{mso-style-name:"";
	mso-gram-e:yes;}
@page Section1
	{size:595.3pt 841.9pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;
	mso-header-margin:35.4pt;
	mso-footer-margin:35.4pt;
	mso-paper-source:0;}
div.Section1
	{page:Section1;}
-->
</style>
<!--[if gte mso 10]>
<style>
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
</style>
<![endif]-->
</head>

<body lang=3DEN-US style=3D'tab-interval:36.0pt'>

<div class=3DSection1>

<p class=3DMsoNormal style=3D'mso-outline-level:2'><b><span lang=3DEN
style=3D'font-size:9.0pt;font-family:Arial;mso-bidi-font-family:Tahoma;
mso-ansi-language:EN'>S<st1:PersonName w:st=3D"on">o</st1:PersonName>lving =
the
Web security challenge <o:p></o:p></span></b></p>

<p class=3DMsoNormal><span lang=3DEN style=3D'font-size:6.0pt;font-family:V=
erdana;
mso-bidi-font-family:Tahoma;mso-ansi-language:EN'>By <a
href=3D"mailto:letters@cnet.com"><span style=3D'color:#0048C0;text-decorati=
on:none;
text-underline:none'>Mike <span class=3DSpellE>Ricciuti</span> and <span
class=3DSpellE>Joris</span> Evers</span></a><br>
Staff writers, CNET News.c<st1:PersonName w:st=3D"on">o</st1:PersonName>m<b=
r>
June 28, 2007, 4:00 AM PDT<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><i><span lang=3DEN
style=3D'font-size:6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;
mso-ansi-language:EN'><o:p>&nbsp;</o:p></span></i></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><i><span lang=3DEN
style=3D'font-size:6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;
mso-ansi-language:EN'>Edit<st1:PersonName w:st=3D"on">o</st1:PersonName>rs'=
 n<st1:PersonName
w:st=3D"on">o</st1:PersonName>te: This is part f<st1:PersonName w:st=3D"on"=
>o</st1:PersonName>ur
<st1:PersonName w:st=3D"on">o</st1:PersonName>f a f<st1:PersonName w:st=3D"=
on">o</st1:PersonName>ur-day
series examining the <a
href=3D"http://news.com.com/Wardens+of+the+Web/2009-1002_3-6189122.html"
title=3D"Wardens of the Web -- Thursday, Jun 28, 2007"><span style=3D'color=
:#0048C0;
text-decoration:none;text-underline:none'>state and future of Web security<=
/span></a>.</span></i><span
lang=3DEN style=3D'font-size:6.0pt;font-family:Verdana;mso-bidi-font-family=
:Tahoma;
mso-ansi-language:EN'><o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><b><span lang=3DEN
style=3D'font-size:6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;
mso-ansi-language:EN'>The Web, f<st1:PersonName w:st=3D"on">o</st1:PersonNa=
me>r
better <st1:PersonName w:st=3D"on">o</st1:PersonName>r w<st1:PersonName w:s=
t=3D"on">o</st1:PersonName>rse,
has arguably bec<st1:PersonName w:st=3D"on">o</st1:PersonName>me the equiva=
lent <st1:PersonName
w:st=3D"on">o</st1:PersonName>f a massive public agency. It is the rep<st1:=
PersonName
w:st=3D"on">o</st1:PersonName>sit<st1:PersonName w:st=3D"on">o</st1:PersonN=
ame>ry f<st1:PersonName
w:st=3D"on">o</st1:PersonName>r c<st1:PersonName w:st=3D"on">o</st1:PersonN=
ame>nsumer
inf<st1:PersonName w:st=3D"on">o</st1:PersonName>rmati<st1:PersonName w:st=
=3D"on">o</st1:PersonName>n
and services <st1:PersonName w:st=3D"on">o</st1:PersonName>f the m<st1:Pers=
onName
w:st=3D"on">o</st1:PersonName>st sensitive and imp<st1:PersonName w:st=3D"o=
n">o</st1:PersonName>rtant
nature, ranging fr<st1:PersonName w:st=3D"on">o</st1:PersonName>m medical r=
ec<st1:PersonName
w:st=3D"on">o</st1:PersonName>rds t<st1:PersonName w:st=3D"on">o</st1:Perso=
nName>
financial investments.</span></b><span lang=3DEN style=3D'font-size:6.0pt;
font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'><o:p>=
</o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
><a
href=3D"http://www.webware.com/"><span style=3D'color:#0048C0;text-decorati=
on:none;
text-underline:none'>Web-based services</span></a> are supplanting traditi<=
st1:PersonName
w:st=3D"on">o</st1:PersonName>nal deskt<st1:PersonName w:st=3D"on">o</st1:P=
ersonName>p
s<st1:PersonName w:st=3D"on">o</st1:PersonName>ftware at a blinding pace, t=
aking <st1:PersonName
w:st=3D"on">o</st1:PersonName>ver terabytes <st1:PersonName w:st=3D"on">o</=
st1:PersonName>f
pers<st1:PersonName w:st=3D"on">o</st1:PersonName>nal data in the pr<st1:Pe=
rsonName
w:st=3D"on">o</st1:PersonName>cess. Unlimited e-mail st<st1:PersonName w:st=
=3D"on">o</st1:PersonName>rage
and Web 2.0-style start-ups will accelerate that trend even m<st1:PersonName
w:st=3D"on">o</st1:PersonName>re.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>Yet
access t<st1:PersonName w:st=3D"on">o</st1:PersonName> th<st1:PersonName w:=
st=3D"on">o</st1:PersonName>se
massive and indispensable res<st1:PersonName w:st=3D"on">o</st1:PersonName>=
urces
is generally gated by a handful <st1:PersonName w:st=3D"on">o</st1:PersonNa=
me>f
large, pr<st1:PersonName w:st=3D"on">o</st1:PersonName>fit-driven c<st1:Per=
sonName
w:st=3D"on">o</st1:PersonName>rp<st1:PersonName w:st=3D"on">o</st1:PersonNa=
me>rati<st1:PersonName
w:st=3D"on">o</st1:PersonName>ns. <a
href=3D"http://news.com.com/Microsofts+lessons+from+the+desktop/2009-1002_3=
-6189433.html"
title=3D"Microsoft's lessons from the desktop -- Wednesday, Jun 27, 2007"><=
span
style=3D'color:#0048C0;text-decoration:none;text-underline:none'>Microsoft<=
/span></a>,
<a
href=3D"http://news.com.com/Google+We+all+have+to+invent+the+wheel/2009-100=
2_3-6189397.html"
title=3D"Google: 'We all have to invent the wheel' -- Monday, Jun 25, 2007"=
><span
style=3D'color:#0048C0;text-decoration:none;text-underline:none'>Google</sp=
an></a>,
<a
href=3D"http://news.com.com/At+Yahoo%2C+being+paranoid+comes+with+the+job/2=
009-1002_3-6189429.html"
title=3D"At Yahoo, being paranoid comes with the job -- Tuesday, Jun 26, 20=
07"><span
style=3D'color:#0048C0;text-decoration:none;text-underline:none'>Yahoo</spa=
n></a>,
America Online and <st1:PersonName w:st=3D"on">o</st1:PersonName>ther leadi=
ng c<st1:PersonName
w:st=3D"on">o</st1:PersonName>mpanies have largely built the services that =
much <st1:PersonName
w:st=3D"on">o</st1:PersonName>f the w<st1:PersonName w:st=3D"on">o</st1:Per=
sonName>rld
has c<st1:PersonName w:st=3D"on">o</st1:PersonName>me t<st1:PersonName w:st=
=3D"on">o</st1:PersonName>
rely <st1:PersonName w:st=3D"on">o</st1:PersonName>n in everyday life--maki=
ng
them, in effect, the guardians <st1:PersonName w:st=3D"on">o</st1:PersonNam=
e>f <st1:PersonName
w:st=3D"on">o</st1:PersonName>ur m<st1:PersonName w:st=3D"on">o</st1:Person=
Name>st
sensitive inf<st1:PersonName w:st=3D"on">o</st1:PersonName>rmati<st1:Person=
Name
w:st=3D"on">o</st1:PersonName>n.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>Which
raises an <st1:PersonName w:st=3D"on">o</st1:PersonName>bvi<st1:PersonName =
w:st=3D"on">o</st1:PersonName>us
questi<st1:PersonName w:st=3D"on">o</st1:PersonName>n: Is that a g<st1:Pers=
onName
w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D"on">o</st1:PersonName=
>d idea?
The m<st1:PersonName w:st=3D"on">o</st1:PersonName>st disturbing answer, if=
 hist<st1:PersonName
w:st=3D"on">o</st1:PersonName>ry is any guide, is that we may n<st1:PersonN=
ame
w:st=3D"on">o</st1:PersonName>t have much <st1:PersonName w:st=3D"on">o</st=
1:PersonName>f
a ch<st1:PersonName w:st=3D"on">o</st1:PersonName>ice.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>It's
disturbing <st1:PersonName w:st=3D"on">o</st1:PersonName>n many levels, but=
 m<st1:PersonName
w:st=3D"on">o</st1:PersonName>stly because the industry is basically making=
 up
Web security as it g<st1:PersonName w:st=3D"on">o</st1:PersonName>es al<st1=
:PersonName
w:st=3D"on">o</st1:PersonName>ng. As security executives fr<st1:PersonName =
w:st=3D"on">o</st1:PersonName>m
Micr<st1:PersonName w:st=3D"on">o</st1:PersonName>s<st1:PersonName w:st=3D"=
on">o</st1:PersonName>ft,
G<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D"on">=
o</st1:PersonName>gle
and Yah<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=
=3D"on">o</st1:PersonName>
attest, the c<st1:PersonName w:st=3D"on">o</st1:PersonName>mpanies are in m=
any
cases adapting standard deskt<st1:PersonName w:st=3D"on">o</st1:PersonName>p
security techniques t<st1:PersonName w:st=3D"on">o</st1:PersonName> new Web
applicati<st1:PersonName w:st=3D"on">o</st1:PersonName>ns. S<st1:PersonName
w:st=3D"on">o</st1:PersonName>metimes that w<st1:PersonName w:st=3D"on">o</=
st1:PersonName>rks;
s<st1:PersonName w:st=3D"on">o</st1:PersonName>metimes it d<st1:PersonName =
w:st=3D"on">o</st1:PersonName>esn't.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>&quot;Data
is n<st1:PersonName w:st=3D"on">o</st1:PersonName>w available <st1:PersonNa=
me
w:st=3D"on">o</st1:PersonName>nline, all the time,&quot; said Billy H<st1:P=
ersonName
w:st=3D"on">o</st1:PersonName>ffman, lead researcher at Web security specia=
list
SPI Dynamics. &quot;It's a great big target.&quot;<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>H<st1:PersonName
w:st=3D"on">o</st1:PersonName>ffman's j<st1:PersonName w:st=3D"on">o</st1:P=
ersonName>b
is t<st1:PersonName w:st=3D"on">o</st1:PersonName> understand where Web sec=
urity
breaks d<st1:PersonName w:st=3D"on">o</st1:PersonName>wn. The way he sees i=
t, the
<a href=3D"http://news.com.com/Wardens+of+the+Web/2009-1002_3-6189122.html"
title=3D"Wardens of the Web -- Thursday, Jun 28, 2007"><span style=3D'color=
:#0048C0;
text-decoration:none;text-underline:none'>Big Three</span></a> Web pr<st1:P=
ersonName
w:st=3D"on">o</st1:PersonName>perties are d<st1:PersonName w:st=3D"on">o</s=
t1:PersonName>ing
a fairly g<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonName w:s=
t=3D"on">o</st1:PersonName>d
j<st1:PersonName w:st=3D"on">o</st1:PersonName>b with security, at least <s=
t1:PersonName
w:st=3D"on">o</st1:PersonName>n the server end <st1:PersonName w:st=3D"on">=
o</st1:PersonName>f
the equati<st1:PersonName w:st=3D"on">o</st1:PersonName>n. The wild card is=
 what
happens t<st1:PersonName w:st=3D"on">o</st1:PersonName> that data <st1:Pers=
onName
w:st=3D"on">o</st1:PersonName>nce it leaves the <span class=3DSpellE>G<st1:=
PersonName
w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D"on">o</st1:PersonName=
>gleplex</span>,
travels acr<st1:PersonName w:st=3D"on">o</st1:PersonName>ss the netw<st1:Pe=
rsonName
w:st=3D"on">o</st1:PersonName>rk, and gets cached <st1:PersonName w:st=3D"o=
n">o</st1:PersonName>n
users' deskt<st1:PersonName w:st=3D"on">o</st1:PersonName>ps.<o:p></o:p></s=
pan></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>Since
1999, m<st1:PersonName w:st=3D"on">o</st1:PersonName>re than 90 percent <st=
1:PersonName
w:st=3D"on">o</st1:PersonName>f all d<st1:PersonName w:st=3D"on">o</st1:Per=
sonName>cuments
have been pr<st1:PersonName w:st=3D"on">o</st1:PersonName>duced digitally; =
m<st1:PersonName
w:st=3D"on">o</st1:PersonName>re than 42 percent <st1:PersonName w:st=3D"on=
">o</st1:PersonName>f
all U.S. Internet users have Web-based banking services; and m<st1:PersonNa=
me
w:st=3D"on">o</st1:PersonName>re than 160 billi<st1:PersonName w:st=3D"on">=
o</st1:PersonName>n
e-mail messages are sent daily, acc<st1:PersonName w:st=3D"on">o</st1:Perso=
nName>rding
t<st1:PersonName w:st=3D"on">o</st1:PersonName> c<st1:PersonName w:st=3D"on=
">o</st1:PersonName>mputer
services firm CSC and <st1:PersonName w:st=3D"on">o</st1:PersonName>ther s<=
st1:PersonName
w:st=3D"on">o</st1:PersonName>urces. As the data piles up, it bec<st1:Perso=
nName
w:st=3D"on">o</st1:PersonName>mes harder t<st1:PersonName w:st=3D"on">o</st=
1:PersonName>
secure bits fl<st1:PersonName w:st=3D"on">o</st1:PersonName>wing between se=
rvers
and deskt<st1:PersonName w:st=3D"on">o</st1:PersonName>p Web applicati<st1:=
PersonName
w:st=3D"on">o</st1:PersonName>ns, n<st1:PersonName w:st=3D"on">o</st1:Perso=
nName>t
t<st1:PersonName w:st=3D"on">o</st1:PersonName> menti<st1:PersonName w:st=
=3D"on">o</st1:PersonName>n
the additi<st1:PersonName w:st=3D"on">o</st1:PersonName>nal c<st1:PersonName
w:st=3D"on">o</st1:PersonName>mplexity <st1:PersonName w:st=3D"on">o</st1:P=
ersonName>f
<span class=3DSpellE>mashups</span> and <st1:PersonName w:st=3D"on">o</st1:=
PersonName>ther
Web 2.0 techn<st1:PersonName w:st=3D"on">o</st1:PersonName>l<st1:PersonName
w:st=3D"on">o</st1:PersonName>gies. Simultane<st1:PersonName w:st=3D"on">o<=
/st1:PersonName>usly,
<a href=3D"http://news.com.com/8301-10784_3-9731018-7.html"><span
style=3D'color:#0048C0;text-decoration:none;text-underline:none'>attacks ar=
e on
the rise</span></a>.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>The
b<st1:PersonName w:st=3D"on">o</st1:PersonName>tt<st1:PersonName w:st=3D"on=
">o</st1:PersonName>m
line is that we're entering unexpl<st1:PersonName w:st=3D"on">o</st1:Person=
Name>red
territ<st1:PersonName w:st=3D"on">o</st1:PersonName>ry where an unprecedent=
ed
number <st1:PersonName w:st=3D"on">o</st1:PersonName>f pe<st1:PersonName w:=
st=3D"on">o</st1:PersonName>ple
depend <st1:PersonName w:st=3D"on">o</st1:PersonName>n a gr<st1:PersonName =
w:st=3D"on">o</st1:PersonName>wing
number <st1:PersonName w:st=3D"on">o</st1:PersonName>f relatively new appli=
cati<st1:PersonName
w:st=3D"on">o</st1:PersonName>ns, s<st1:PersonName w:st=3D"on">o</st1:Perso=
nName>me
built with still-ev<st1:PersonName w:st=3D"on">o</st1:PersonName>lving tech=
n<st1:PersonName
w:st=3D"on">o</st1:PersonName>l<st1:PersonName w:st=3D"on">o</st1:PersonNam=
e>gies,
t<st1:PersonName w:st=3D"on">o</st1:PersonName> handle en<st1:PersonName w:=
st=3D"on">o</st1:PersonName>rm<st1:PersonName
w:st=3D"on">o</st1:PersonName>us am<st1:PersonName w:st=3D"on">o</st1:Perso=
nName>unts
<st1:PersonName w:st=3D"on">o</st1:PersonName>f pers<st1:PersonName w:st=3D=
"on">o</st1:PersonName>nal
data fragmented acr<st1:PersonName w:st=3D"on">o</st1:PersonName>ss a
multiplicity <st1:PersonName w:st=3D"on">o</st1:PersonName>f servers and ne=
tw<st1:PersonName
w:st=3D"on">o</st1:PersonName>rks w<st1:PersonName w:st=3D"on">o</st1:Perso=
nName>rldwide.
Against this daunting backdr<st1:PersonName w:st=3D"on">o</st1:PersonName>p=
--and
amid c<st1:PersonName w:st=3D"on">o</st1:PersonName>ncerns <st1:PersonName =
w:st=3D"on">o</st1:PersonName>ver
c<st1:PersonName w:st=3D"on">o</st1:PersonName>rp<st1:PersonName w:st=3D"on=
">o</st1:PersonName>rate
c<st1:PersonName w:st=3D"on">o</st1:PersonName>ntr<st1:PersonName w:st=3D"o=
n">o</st1:PersonName>l--calls
f<st1:PersonName w:st=3D"on">o</st1:PersonName>r s<st1:PersonName w:st=3D"o=
n">o</st1:PersonName>me
kind <st1:PersonName w:st=3D"on">o</st1:PersonName>f independent <st1:Perso=
nName
w:st=3D"on">o</st1:PersonName>versight are inevitable.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>&quot;We
have inf<st1:PersonName w:st=3D"on">o</st1:PersonName>rmati<st1:PersonName =
w:st=3D"on">o</st1:PersonName>n
<st1:PersonName w:st=3D"on">o</st1:PersonName>n security practices <st1:Per=
sonName
w:st=3D"on">o</st1:PersonName>ut there. The disc<st1:PersonName w:st=3D"on"=
>o</st1:PersonName>nnect
is that we d<st1:PersonName w:st=3D"on">o</st1:PersonName>n't have an inter=
mediary
that says h<st1:PersonName w:st=3D"on">o</st1:PersonName>w these things app=
ly t<st1:PersonName
w:st=3D"on">o</st1:PersonName> y<st1:PersonName w:st=3D"on">o</st1:PersonNa=
me>u as
y<st1:PersonName w:st=3D"on">o</st1:PersonName>u build Web 2.0 <st1:PersonN=
ame
w:st=3D"on">o</st1:PersonName>r <st1:PersonName w:st=3D"on">o</st1:PersonNa=
me>ther
applicati<st1:PersonName w:st=3D"on">o</st1:PersonName>ns,&quot; H<st1:Pers=
onName
w:st=3D"on">o</st1:PersonName>ffman said. &quot;Will a n<st1:PersonName w:s=
t=3D"on">o</st1:PersonName>npr<st1:PersonName
w:st=3D"on">o</st1:PersonName>fit <st1:PersonName w:st=3D"on">o</st1:Person=
Name>r s<st1:PersonName
w:st=3D"on">o</st1:PersonName>me <st1:PersonName w:st=3D"on">o</st1:PersonN=
ame>ther
gr<st1:PersonName w:st=3D"on">o</st1:PersonName>up arise that tries t<st1:P=
ersonName
w:st=3D"on">o</st1:PersonName> publish standards? <span class=3DGramE>Pr<st=
1:PersonName
w:st=3D"on">o</st1:PersonName>bably.</span> We definitely need a central cl=
earing
h<st1:PersonName w:st=3D"on">o</st1:PersonName>use <st1:PersonName w:st=3D"=
on">o</st1:PersonName>f
g<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D"on">=
o</st1:PersonName>d
inf<st1:PersonName w:st=3D"on">o</st1:PersonName>rmati<st1:PersonName w:st=
=3D"on">o</st1:PersonName>n,
because there is a l<st1:PersonName w:st=3D"on">o</st1:PersonName>t <st1:Pe=
rsonName
w:st=3D"on">o</st1:PersonName>f bad inf<st1:PersonName w:st=3D"on">o</st1:P=
ersonName>rmati<st1:PersonName
w:st=3D"on">o</st1:PersonName>n <st1:PersonName w:st=3D"on">o</st1:PersonNa=
me>ut
there.&quot;<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>Even
s<st1:PersonName w:st=3D"on">o</st1:PersonName>me executives at the c<st1:P=
ersonName
w:st=3D"on">o</st1:PersonName>mpanies that n<st1:PersonName w:st=3D"on">o</=
st1:PersonName>w
c<st1:PersonName w:st=3D"on">o</st1:PersonName>ntr<st1:PersonName w:st=3D"o=
n">o</st1:PersonName>l
the bulk <st1:PersonName w:st=3D"on">o</st1:PersonName>f Web security say m=
<st1:PersonName
w:st=3D"on">o</st1:PersonName>re industry c<st1:PersonName w:st=3D"on">o</s=
t1:PersonName><st1:PersonName
w:st=3D"on">o</st1:PersonName>perati<st1:PersonName w:st=3D"on">o</st1:Pers=
onName>n
is needed. <o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>&quot;Security
is in the best interest <st1:PersonName w:st=3D"on">o</st1:PersonName>f the=
 wh<st1:PersonName
w:st=3D"on">o</st1:PersonName>le industry,&quot; said <a
href=3D"http://news.com.com/2300-1002_3-6192278-1.html"
title=3D"Photos: A peek at Yahoo 'Paranoids' -- Tuesday, Jun 26, 2007"><span
style=3D'color:#0048C0;text-decoration:none;text-underline:none'>Arturo <sp=
an
class=3DSpellE>Bejar</span>, the &quot;Chief Paranoid Yahoo.&quot;</span></=
a>
&quot;We're evaluating ways t<st1:PersonName w:st=3D"on">o</st1:PersonName>=
 share
either kn<st1:PersonName w:st=3D"on">o</st1:PersonName>wledge <st1:PersonNa=
me
w:st=3D"on">o</st1:PersonName>r t<st1:PersonName w:st=3D"on">o</st1:PersonN=
ame><st1:PersonName
w:st=3D"on">o</st1:PersonName>ls t<st1:PersonName w:st=3D"on">o</st1:Person=
Name>
give back t<st1:PersonName w:st=3D"on">o</st1:PersonName> the c<st1:PersonN=
ame
w:st=3D"on">o</st1:PersonName>mmunity.&quot;<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>A
seemingly <st1:PersonName w:st=3D"on">o</st1:PersonName>bvi<st1:PersonName =
w:st=3D"on">o</st1:PersonName>us
c<st1:PersonName w:st=3D"on">o</st1:PersonName>urse t<st1:PersonName w:st=
=3D"on">o</st1:PersonName>
pursue, sh<st1:PersonName w:st=3D"on">o</st1:PersonName>rt <st1:PersonName =
w:st=3D"on">o</st1:PersonName>f
g<st1:PersonName w:st=3D"on">o</st1:PersonName>vernment interventi<st1:Pers=
onName
w:st=3D"on">o</st1:PersonName>n, w<st1:PersonName w:st=3D"on">o</st1:Person=
Name>uld
be s<st1:PersonName w:st=3D"on">o</st1:PersonName>me f<st1:PersonName w:st=
=3D"on">o</st1:PersonName>rm
<st1:PersonName w:st=3D"on">o</st1:PersonName>f industry-wide c<st1:PersonN=
ame
w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D"on">o</st1:PersonName=
>perati<st1:PersonName
w:st=3D"on">o</st1:PersonName>n <st1:PersonName w:st=3D"on">o</st1:PersonNa=
me>stensibly
designed t<st1:PersonName w:st=3D"on">o</st1:PersonName> av<st1:PersonName =
w:st=3D"on">o</st1:PersonName>id
the devel<st1:PersonName w:st=3D"on">o</st1:PersonName>pment <st1:PersonName
w:st=3D"on">o</st1:PersonName>f a m<st1:PersonName w:st=3D"on">o</st1:Perso=
nName>n<st1:PersonName
w:st=3D"on">o</st1:PersonName>p<st1:PersonName w:st=3D"on">o</st1:PersonNam=
e>ly <st1:PersonName
w:st=3D"on">o</st1:PersonName>r cartel. That appr<st1:PersonName w:st=3D"on=
">o</st1:PersonName>ach,
th<st1:PersonName w:st=3D"on">o</st1:PersonName>ugh, is easier said than d<=
st1:PersonName
w:st=3D"on">o</st1:PersonName>ne: it's been tried many times bef<st1:Person=
Name
w:st=3D"on">o</st1:PersonName>re with <st1:PersonName w:st=3D"on">o</st1:Pe=
rsonName>ther
digital techn<st1:PersonName w:st=3D"on">o</st1:PersonName>l<st1:PersonName
w:st=3D"on">o</st1:PersonName>gies, <st1:PersonName w:st=3D"on">o</st1:Pers=
onName>nly
t<st1:PersonName w:st=3D"on">o</st1:PersonName> end up in disarray <st1:Per=
sonName
w:st=3D"on">o</st1:PersonName>r under the de fact<st1:PersonName w:st=3D"on=
">o</st1:PersonName>
c<st1:PersonName w:st=3D"on">o</st1:PersonName>ntr<st1:PersonName w:st=3D"o=
n">o</st1:PersonName>l
<st1:PersonName w:st=3D"on">o</st1:PersonName>f a principal stakeh<st1:Pers=
onName
w:st=3D"on">o</st1:PersonName>lder <st1:PersonName w:st=3D"on">o</st1:Perso=
nName>r
gr<st1:PersonName w:st=3D"on">o</st1:PersonName>up <st1:PersonName w:st=3D"=
on">o</st1:PersonName>f
interested parties.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>In
a w<st1:PersonName w:st=3D"on">o</st1:PersonName>rd, think Wind<st1:PersonN=
ame
w:st=3D"on">o</st1:PersonName>ws. M<st1:PersonName w:st=3D"on">o</st1:Perso=
nName>re
than a decade <st1:PersonName w:st=3D"on">o</st1:PersonName>f <a
href=3D"http://news.com.com/Microsoft+resolves+class-action+suit/2100-1001_=
3-980269.html"
title=3D"Microsoft resolves class-action suit -- Friday, Jan 10, 2003"><span
style=3D'color:#0048C0;text-decoration:none;text-underline:none'>litigation=
</span></a>
and unt<st1:PersonName w:st=3D"on">o</st1:PersonName>ld milli<st1:PersonName
w:st=3D"on">o</st1:PersonName>ns in taxpayer m<st1:PersonName w:st=3D"on">o=
</st1:PersonName>ney
has d<st1:PersonName w:st=3D"on">o</st1:PersonName>ne little t<st1:PersonNa=
me
w:st=3D"on">o</st1:PersonName> l<st1:PersonName w:st=3D"on">o</st1:PersonNa=
me><st1:PersonName
w:st=3D"on">o</st1:PersonName>sen Micr<st1:PersonName w:st=3D"on">o</st1:Pe=
rsonName>s<st1:PersonName
w:st=3D"on">o</st1:PersonName>ft's c<st1:PersonName w:st=3D"on">o</st1:Pers=
onName>ntr<st1:PersonName
w:st=3D"on">o</st1:PersonName>l <st1:PersonName w:st=3D"on">o</st1:PersonNa=
me>ver
the <st1:PersonName w:st=3D"on">o</st1:PersonName>perating system that m<st=
1:PersonName
w:st=3D"on">o</st1:PersonName>re than 90 percent <st1:PersonName w:st=3D"on=
">o</st1:PersonName>f
the w<st1:PersonName w:st=3D"on">o</st1:PersonName>rld's pers<st1:PersonName
w:st=3D"on">o</st1:PersonName>nal c<st1:PersonName w:st=3D"on">o</st1:Perso=
nName>mputer
users rely <st1:PersonName w:st=3D"on">o</st1:PersonName>n daily.<o:p></o:p=
></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>In
the early days <st1:PersonName w:st=3D"on">o</st1:PersonName>f the Web, a n=
<st1:PersonName
w:st=3D"on">o</st1:PersonName>npr<st1:PersonName w:st=3D"on">o</st1:PersonN=
ame>fit
agency called the <a href=3D"http://www.w3.org/"><span style=3D'color:#0048=
C0;
text-decoration:none;text-underline:none'>World Wide Web Consortium</span><=
/a>
was b<st1:PersonName w:st=3D"on">o</st1:PersonName>rn <st1:PersonName w:st=
=3D"on">o</st1:PersonName>f
the altruistic n<st1:PersonName w:st=3D"on">o</st1:PersonName>ti<st1:Person=
Name
w:st=3D"on">o</st1:PersonName>n that all interested parties c<st1:PersonName
w:st=3D"on">o</st1:PersonName>uld c<st1:PersonName w:st=3D"on">o</st1:Perso=
nName><st1:PersonName
w:st=3D"on">o</st1:PersonName>perate and c<st1:PersonName w:st=3D"on">o</st=
1:PersonName>mpr<st1:PersonName
w:st=3D"on">o</st1:PersonName>mise as needed f<st1:PersonName w:st=3D"on">o=
</st1:PersonName>r
the g<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D"=
on">o</st1:PersonName>d
<st1:PersonName w:st=3D"on">o</st1:PersonName>f the medium. The s<st1:Perso=
nName
w:st=3D"on">o</st1:PersonName>-called W3C has d<st1:PersonName w:st=3D"on">=
o</st1:PersonName>ne
much g<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D=
"on">o</st1:PersonName>d
in defining Web standards where n<st1:PersonName w:st=3D"on">o</st1:PersonN=
ame>ne
existed and by serving as a trusted auth<st1:PersonName w:st=3D"on">o</st1:=
PersonName>rity
in the Internet's Wild West beginnings. At the same time, much <st1:PersonN=
ame
w:st=3D"on">o</st1:PersonName>f the W3C's activity is f<st1:PersonName w:st=
=3D"on">o</st1:PersonName>cused
<st1:PersonName w:st=3D"on">o</st1:PersonName>n standards defined by the ve=
ry c<st1:PersonName
w:st=3D"on">o</st1:PersonName>mpanies that in many instances m<st1:PersonNa=
me
w:st=3D"on">o</st1:PersonName>st benefit fr<st1:PersonName w:st=3D"on">o</s=
t1:PersonName>m
their creati<st1:PersonName w:st=3D"on">o</st1:PersonName>n.<o:p></o:p></sp=
an></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>The
W3C pr<st1:PersonName w:st=3D"on">o</st1:PersonName>bably isn't the right <=
st1:PersonName
w:st=3D"on">o</st1:PersonName>rganizati<st1:PersonName w:st=3D"on">o</st1:P=
ersonName>n
t<st1:PersonName w:st=3D"on">o</st1:PersonName> be charged with Web securit=
y <st1:PersonName
w:st=3D"on">o</st1:PersonName>versight anyway because it essentially define=
s t<st1:PersonName
w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D"on">o</st1:PersonName=
>ls used
by <st1:PersonName w:st=3D"on">o</st1:PersonName>thers. Security breaches u=
sually
inv<st1:PersonName w:st=3D"on">o</st1:PersonName>lve h<st1:PersonName w:st=
=3D"on">o</st1:PersonName>w
th<st1:PersonName w:st=3D"on">o</st1:PersonName>se techn<st1:PersonName w:s=
t=3D"on">o</st1:PersonName>l<st1:PersonName
w:st=3D"on">o</st1:PersonName>gies are used, n<st1:PersonName w:st=3D"on">o=
</st1:PersonName>t
necessarily the t<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonN=
ame
w:st=3D"on">o</st1:PersonName>ls themselves. <o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>&quot;Standard
b<st1:PersonName w:st=3D"on">o</st1:PersonName>dies sh<st1:PersonName w:st=
=3D"on">o</st1:PersonName>uld
f<st1:PersonName w:st=3D"on">o</st1:PersonName>cus <st1:PersonName w:st=3D"=
on">o</st1:PersonName>n
making very clear standards that set g<st1:PersonName w:st=3D"on">o</st1:Pe=
rsonName><st1:PersonName
w:st=3D"on">o</st1:PersonName>d baselines,&quot; H<st1:PersonName w:st=3D"o=
n">o</st1:PersonName>ffman
said. &quot;The w<st1:PersonName w:st=3D"on">o</st1:PersonName>rst thing in=
 the w<st1:PersonName
w:st=3D"on">o</st1:PersonName>rld that a standard can d<st1:PersonName w:st=
=3D"on">o</st1:PersonName>
is t<st1:PersonName w:st=3D"on">o</st1:PersonName> be ambigu<st1:PersonName
w:st=3D"on">o</st1:PersonName>us, and there are a number <st1:PersonName w:=
st=3D"on">o</st1:PersonName>f
standards <st1:PersonName w:st=3D"on">o</st1:PersonName>ut there that are a=
mbigu<st1:PersonName
w:st=3D"on">o</st1:PersonName>us.&quot;<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>Other
<st1:PersonName w:st=3D"on">o</st1:PersonName>rganizati<st1:PersonName w:st=
=3D"on">o</st1:PersonName>ns,
like the <a href=3D"http://www.webappsec.org/"><span style=3D'color:#0048C0;
text-decoration:none;text-underline:none'>Web Application Security Consorti=
um</span></a>,
are attempting t<st1:PersonName w:st=3D"on">o</st1:PersonName> define the m=
<st1:PersonName
w:st=3D"on">o</st1:PersonName>st secure ways t<st1:PersonName w:st=3D"on">o=
</st1:PersonName>
devel<st1:PersonName w:st=3D"on">o</st1:PersonName>p applicati<st1:PersonNa=
me
w:st=3D"on">o</st1:PersonName>ns. In additi<st1:PersonName w:st=3D"on">o</s=
t1:PersonName>n,
Web devel<st1:PersonName w:st=3D"on">o</st1:PersonName>pers thr<st1:PersonN=
ame
w:st=3D"on">o</st1:PersonName>ugh<st1:PersonName w:st=3D"on">o</st1:PersonN=
ame>ut
the industry are sharing m<st1:PersonName w:st=3D"on">o</st1:PersonName>re
research and security &quot;best practices&quot; thr<st1:PersonName w:st=3D=
"on">o</st1:PersonName>ugh
sites like <a
href=3D"http://news.com.com/Solving+the+Web+security+challenge/www.xssed.or=
g"><span
style=3D'color:#0048C0;text-decoration:none;text-underline:none'>XSSed.org<=
/span></a>,
which publishes inf<st1:PersonName w:st=3D"on">o</st1:PersonName>rmati<st1:=
PersonName
w:st=3D"on">o</st1:PersonName>n <st1:PersonName w:st=3D"on">o</st1:PersonNa=
me>n new
cr<st1:PersonName w:st=3D"on">o</st1:PersonName>ss-site scripting vulnerabi=
lities
and h<st1:PersonName w:st=3D"on">o</st1:PersonName>w t<st1:PersonName w:st=
=3D"on">o</st1:PersonName>
fix them.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>But
such eff<st1:PersonName w:st=3D"on">o</st1:PersonName>rts can g<st1:PersonN=
ame
w:st=3D"on">o</st1:PersonName> <st1:PersonName w:st=3D"on">o</st1:PersonNam=
e>nly s<st1:PersonName
w:st=3D"on">o</st1:PersonName> far. The Web giants have built <st1:PersonNa=
me
w:st=3D"on">o</st1:PersonName>ut their pr<st1:PersonName w:st=3D"on">o</st1=
:PersonName>perties
<st1:PersonName w:st=3D"on">o</st1:PersonName>ver the years despite securit=
y pr<st1:PersonName
w:st=3D"on">o</st1:PersonName>blems, and new bugs c<st1:PersonName w:st=3D"=
on">o</st1:PersonName>ntinue
t<st1:PersonName w:st=3D"on">o</st1:PersonName> arise alm<st1:PersonName w:=
st=3D"on">o</st1:PersonName>st
daily. Micr<st1:PersonName w:st=3D"on">o</st1:PersonName>s<st1:PersonName w=
:st=3D"on">o</st1:PersonName>ft,
f<st1:PersonName w:st=3D"on">o</st1:PersonName>r example, came late t<st1:P=
ersonName
w:st=3D"on">o</st1:PersonName> Web security--and t<st1:PersonName w:st=3D"o=
n">o</st1:PersonName>
digital security in general. Until well int<st1:PersonName w:st=3D"on">o</s=
t1:PersonName>
the 1990s, security was largely an afterth<st1:PersonName w:st=3D"on">o</st=
1:PersonName>ught
in Wind<st1:PersonName w:st=3D"on">o</st1:PersonName>ws, which was n<st1:Pe=
rsonName
w:st=3D"on">o</st1:PersonName>t designed with persistent netw<st1:PersonName
w:st=3D"on">o</st1:PersonName>rk c<st1:PersonName w:st=3D"on">o</st1:Person=
Name>nnectivity
in mind.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>Once
it fully underst<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonNa=
me
w:st=3D"on">o</st1:PersonName>d the issue's imp<st1:PersonName w:st=3D"on">=
o</st1:PersonName>rtance,
h<st1:PersonName w:st=3D"on">o</st1:PersonName>wever, Micr<st1:PersonName w=
:st=3D"on">o</st1:PersonName>s<st1:PersonName
w:st=3D"on">o</st1:PersonName>ft p<st1:PersonName w:st=3D"on">o</st1:Person=
Name>ured
billi<st1:PersonName w:st=3D"on">o</st1:PersonName>ns <st1:PersonName w:st=
=3D"on">o</st1:PersonName>f
d<st1:PersonName w:st=3D"on">o</st1:PersonName>llars int<st1:PersonName w:s=
t=3D"on">o</st1:PersonName>
the pr<st1:PersonName w:st=3D"on">o</st1:PersonName>tecti<st1:PersonName w:=
st=3D"on">o</st1:PersonName>n
<st1:PersonName w:st=3D"on">o</st1:PersonName>f client and server s<st1:Per=
sonName
w:st=3D"on">o</st1:PersonName>ftware. That eff<st1:PersonName w:st=3D"on">o=
</st1:PersonName>rt
has been expanded t<st1:PersonName w:st=3D"on">o</st1:PersonName> include W=
eb
security as the c<st1:PersonName w:st=3D"on">o</st1:PersonName>mpany has m<=
st1:PersonName
w:st=3D"on">o</st1:PersonName>ved m<st1:PersonName w:st=3D"on">o</st1:Perso=
nName>re
deeply int<st1:PersonName w:st=3D"on">o</st1:PersonName> Web services with =
its
&quot;live&quot; initiative--Micr<st1:PersonName w:st=3D"on">o</st1:PersonN=
ame>s<st1:PersonName
w:st=3D"on">o</st1:PersonName>ft's marketing-speak f<st1:PersonName w:st=3D=
"on">o</st1:PersonName>r
its new <st1:PersonName w:st=3D"on">o</st1:PersonName>nline pr<st1:PersonNa=
me
w:st=3D"on">o</st1:PersonName>perties--which includes <a
href=3D"http://news.com.com/Windows+Live+hits+second+generation/2100-1046_3=
-6193447.html"
title=3D"Windows Live hits second generation -- Tuesday, Jun 26, 2007"><span
style=3D'color:windowtext;text-decoration:none;text-underline:none'>Windows=
 Live</span></a>,
the <st1:PersonName w:st=3D"on">o</st1:PersonName>nline c<st1:PersonName w:=
st=3D"on">o</st1:PersonName>mplement
t<st1:PersonName w:st=3D"on">o</st1:PersonName> s<st1:PersonName w:st=3D"on=
">o</st1:PersonName>ftware
<st1:PersonName w:st=3D"on">o</st1:PersonName>n the PC's hard drive.<o:p></=
o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>It's
understandable why Micr<st1:PersonName w:st=3D"on">o</st1:PersonName>s<st1:=
PersonName
w:st=3D"on">o</st1:PersonName>ft w<st1:PersonName w:st=3D"on">o</st1:Person=
Name>uld
think it kn<st1:PersonName w:st=3D"on">o</st1:PersonName>ws best h<st1:Pers=
onName
w:st=3D"on">o</st1:PersonName>w t<st1:PersonName w:st=3D"on">o</st1:PersonN=
ame>
address a pr<st1:PersonName w:st=3D"on">o</st1:PersonName>blem as big as Web
security. N<st1:PersonName w:st=3D"on">o</st1:PersonName>t <st1:PersonName =
w:st=3D"on">o</st1:PersonName>nly
is it the w<st1:PersonName w:st=3D"on">o</st1:PersonName>rld's largest s<st=
1:PersonName
w:st=3D"on">o</st1:PersonName>ftware c<st1:PersonName w:st=3D"on">o</st1:Pe=
rsonName>mpany,
but many veterans there believe they have seen it all years bef<st1:PersonN=
ame
w:st=3D"on">o</st1:PersonName>re. Back then, they say, it was called deskt<=
st1:PersonName
w:st=3D"on">o</st1:PersonName>p security.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>&quot;If
y<st1:PersonName w:st=3D"on">o</st1:PersonName>u classified Web vulnerabili=
ties
and t<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D"=
on">o</st1:PersonName>k
<st1:PersonName w:st=3D"on">o</st1:PersonName>ut all <st1:PersonName w:st=
=3D"on">o</st1:PersonName>f
th<st1:PersonName w:st=3D"on">o</st1:PersonName>se that are related in s<st=
1:PersonName
w:st=3D"on">o</st1:PersonName>me f<st1:PersonName w:st=3D"on">o</st1:Person=
Name>rm
t<st1:PersonName w:st=3D"on">o</st1:PersonName> input validati<st1:PersonNa=
me
w:st=3D"on">o</st1:PersonName>n, I think y<st1:PersonName w:st=3D"on">o</st=
1:PersonName>u'd
have a very small number <st1:PersonName w:st=3D"on">o</st1:PersonName>f
vulnerabilities left,&quot; he said. &quot;I c<st1:PersonName w:st=3D"on">o=
</st1:PersonName>ntend
that 80 percent <st1:PersonName w:st=3D"on">o</st1:PersonName>f the
vulnerabilities that we see are input validati<st1:PersonName w:st=3D"on">o=
</st1:PersonName>n
err<st1:PersonName w:st=3D"on">o</st1:PersonName>rs.&quot;<o:p></o:p></span=
></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>As
a result, <span class=3DSpellE>B<st1:PersonName w:st=3D"on">o</st1:PersonNa=
me>den</span>
believes that Micr<st1:PersonName w:st=3D"on">o</st1:PersonName>s<st1:Perso=
nName
w:st=3D"on">o</st1:PersonName>ft has a leg up <st1:PersonName w:st=3D"on">o=
</st1:PersonName>n
the c<st1:PersonName w:st=3D"on">o</st1:PersonName>mpetiti<st1:PersonName w=
:st=3D"on">o</st1:PersonName>n,
having learned quickly ab<st1:PersonName w:st=3D"on">o</st1:PersonName>ut W=
eb
security because <st1:PersonName w:st=3D"on">o</st1:PersonName>f its l<st1:=
PersonName
w:st=3D"on">o</st1:PersonName>ng s<st1:PersonName w:st=3D"on">o</st1:Person=
Name>ftware
hist<st1:PersonName w:st=3D"on">o</st1:PersonName>ry and <a
href=3D"http://news.com.com/Gates+memo+We+can+and+must+do+better/2009-1001_=
3-817210.html"
title=3D"Gates memo: 'We can and must do better' -- Thursday, Jan 17, 2002"=
><span
style=3D'color:windowtext;text-decoration:none;text-underline:none'>Trustwo=
rthy
Computing</span></a> experience. Like its main rivals, Micr<st1:PersonName
w:st=3D"on">o</st1:PersonName>s<st1:PersonName w:st=3D"on">o</st1:PersonNam=
e>ft has
created t<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=
=3D"on">o</st1:PersonName>ls
t<st1:PersonName w:st=3D"on">o</st1:PersonName> help devel<st1:PersonName w=
:st=3D"on">o</st1:PersonName>pers
quash bugs and test the quality <st1:PersonName w:st=3D"on">o</st1:PersonNa=
me>f c<st1:PersonName
w:st=3D"on">o</st1:PersonName>de, such as a pr<st1:PersonName w:st=3D"on">o=
</st1:PersonName>gram
called Anti-XSS that finds cr<st1:PersonName w:st=3D"on">o</st1:PersonName>=
ss-site
scripting vulnerabilities.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>&quot;It
wasn't as daunting here as it may have been in s<st1:PersonName w:st=3D"on"=
>o</st1:PersonName>me
<st1:PersonName w:st=3D"on">o</st1:PersonName>ther places,&quot; <span
class=3DSpellE>B<st1:PersonName w:st=3D"on">o</st1:PersonName>den</span> sa=
id.
&quot;There is a ramp and a learning curve we have t<st1:PersonName w:st=3D=
"on">o</st1:PersonName>
climb, but I think the learning curve f<st1:PersonName w:st=3D"on">o</st1:P=
ersonName>r
us is steep because <st1:PersonName w:st=3D"on">o</st1:PersonName>f the pri=
<st1:PersonName
w:st=3D"on">o</st1:PersonName>r investment we've made in <st1:PersonName w:=
st=3D"on">o</st1:PersonName>ur
resp<st1:PersonName w:st=3D"on">o</st1:PersonName>nse pr<st1:PersonName w:s=
t=3D"on">o</st1:PersonName>cess
and <st1:PersonName w:st=3D"on">o</st1:PersonName>ur security pr<st1:Person=
Name
w:st=3D"on">o</st1:PersonName>gram acr<st1:PersonName w:st=3D"on">o</st1:Pe=
rsonName>ss
the c<st1:PersonName w:st=3D"on">o</st1:PersonName>mpany.&quot;<o:p></o:p><=
/span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>Still,
d<st1:PersonName w:st=3D"on">o</st1:PersonName>ubts linger. This is the c<s=
t1:PersonName
w:st=3D"on">o</st1:PersonName>mpany, after all, that misjudged the <a
href=3D"http://news.com.com/Victor+Software+empire+pays+high+price/2009-103=
2_3-995681.html"
title=3D"Victor: Software empire pays high price -- Tuesday, Apr 15, 2003">=
<span
style=3D'color:windowtext;text-decoration:none;text-underline:none'>signifi=
cance
of the Internet</span></a> back in the mid-1990s and later underestimated t=
he
value <st1:PersonName w:st=3D"on">o</st1:PersonName>f Internet search and d=
igital
music.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>Will
Micr<st1:PersonName w:st=3D"on">o</st1:PersonName>s<st1:PersonName w:st=3D"=
on">o</st1:PersonName>ft
get it right with Web security? There's a g<st1:PersonName w:st=3D"on">o</s=
t1:PersonName><st1:PersonName
w:st=3D"on">o</st1:PersonName>d chance that it will, simply because there's=
 t<st1:PersonName
w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D"on">o</st1:PersonName=
> much
at stake f<st1:PersonName w:st=3D"on">o</st1:PersonName>r the c<st1:PersonN=
ame
w:st=3D"on">o</st1:PersonName>mpany as business m<st1:PersonName w:st=3D"on=
">o</st1:PersonName>ves
increasingly t<st1:PersonName w:st=3D"on">o</st1:PersonName> the Web. M<st1=
:PersonName
w:st=3D"on">o</st1:PersonName>re<st1:PersonName w:st=3D"on">o</st1:PersonNa=
me>ver,
regardless <st1:PersonName w:st=3D"on">o</st1:PersonName>f h<st1:PersonName
w:st=3D"on">o</st1:PersonName>w effective Micr<st1:PersonName w:st=3D"on">o=
</st1:PersonName>s<st1:PersonName
w:st=3D"on">o</st1:PersonName>ft's <st1:PersonName w:st=3D"on">o</st1:Perso=
nName>perati<st1:PersonName
w:st=3D"on">o</st1:PersonName>ns are, milli<st1:PersonName w:st=3D"on">o</s=
t1:PersonName>ns
<st1:PersonName w:st=3D"on">o</st1:PersonName>f c<st1:PersonName w:st=3D"on=
">o</st1:PersonName>nsumers
and devel<st1:PersonName w:st=3D"on">o</st1:PersonName>pers will maintain
pressure <st1:PersonName w:st=3D"on">o</st1:PersonName>n the c<st1:PersonNa=
me
w:st=3D"on">o</st1:PersonName>mpany t<st1:PersonName w:st=3D"on">o</st1:Per=
sonName>
plug security h<st1:PersonName w:st=3D"on">o</st1:PersonName>les.<o:p></o:p=
></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>Others
c<st1:PersonName w:st=3D"on">o</st1:PersonName>nfr<st1:PersonName w:st=3D"o=
n">o</st1:PersonName>nting
the Web security issue aren't s<st1:PersonName w:st=3D"on">o</st1:PersonNam=
e>
sanguine. G<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonName w:=
st=3D"on">o</st1:PersonName>gle,
f<st1:PersonName w:st=3D"on">o</st1:PersonName>r <st1:PersonName w:st=3D"on=
">o</st1:PersonName>ne,
sees all this as f<st1:PersonName w:st=3D"on">o</st1:PersonName>reign terra=
in
filled with p<st1:PersonName w:st=3D"on">o</st1:PersonName>tential land min=
es
that may n<st1:PersonName w:st=3D"on">o</st1:PersonName>t even be kn<st1:Pe=
rsonName
w:st=3D"on">o</st1:PersonName>wn yet.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
><a
href=3D"http://news.com.com/2300-1002_3-6192280-1.html"
title=3D"Photos: Google security team at work, play -- Monday, Jun 25, 2007=
"><span
style=3D'color:windowtext;text-decoration:none;text-underline:none'>Douglas
Merrill, Google's vice president of engineering</span></a>, says that a
scatter-sh<st1:PersonName w:st=3D"on">o</st1:PersonName>t appr<st1:PersonNa=
me
w:st=3D"on">o</st1:PersonName>ach is <st1:PersonName w:st=3D"on">o</st1:Per=
sonName>ften
the best bet in this hazy envir<st1:PersonName w:st=3D"on">o</st1:PersonNam=
e>nment.
Merrill trusts his c<st1:PersonName w:st=3D"on">o</st1:PersonName>mpany's s=
ervers
m<st1:PersonName w:st=3D"on">o</st1:PersonName>re than the Mac in his <st1:=
PersonName
w:st=3D"on">o</st1:PersonName>ffice t<st1:PersonName w:st=3D"on">o</st1:Per=
sonName>
safeguard his pers<st1:PersonName w:st=3D"on">o</st1:PersonName>nal inf<st1=
:PersonName
w:st=3D"on">o</st1:PersonName>rmati<st1:PersonName w:st=3D"on">o</st1:Perso=
nName>n
because G<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=
=3D"on">o</st1:PersonName>gle
builds m<st1:PersonName w:st=3D"on">o</st1:PersonName>re layers <st1:Person=
Name
w:st=3D"on">o</st1:PersonName>f security ar<st1:PersonName w:st=3D"on">o</s=
t1:PersonName>und
its data centers than ar<st1:PersonName w:st=3D"on">o</st1:PersonName>und
individual c<st1:PersonName w:st=3D"on">o</st1:PersonName>mputers.<o:p></o:=
p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>&quot;Obvi<st1:PersonName
w:st=3D"on">o</st1:PersonName>usly there are c<st1:PersonName w:st=3D"on">o=
</st1:PersonName>rner
cases in each m<st1:PersonName w:st=3D"on">o</st1:PersonName>del that y<st1=
:PersonName
w:st=3D"on">o</st1:PersonName>u sh<st1:PersonName w:st=3D"on">o</st1:Person=
Name>uldn't
g<st1:PersonName w:st=3D"on">o</st1:PersonName> t<st1:PersonName w:st=3D"on=
">o</st1:PersonName>,&quot;
he said. &quot;We dev<st1:PersonName w:st=3D"on">o</st1:PersonName>te vast
quantities <st1:PersonName w:st=3D"on">o</st1:PersonName>f res<st1:PersonNa=
me
w:st=3D"on">o</st1:PersonName>urces t<st1:PersonName w:st=3D"on">o</st1:Per=
sonName>
securing the cl<st1:PersonName w:st=3D"on">o</st1:PersonName>ud.&quot;<o:p>=
</o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>Perhaps,
but n<st1:PersonName w:st=3D"on">o</st1:PersonName> system is f<st1:PersonN=
ame
w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D"on">o</st1:PersonName=
>lpr<st1:PersonName
w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D"on">o</st1:PersonName=
>f. G<st1:PersonName
w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D"on">o</st1:PersonName=
>gle,
Micr<st1:PersonName w:st=3D"on">o</st1:PersonName>s<st1:PersonName w:st=3D"=
on">o</st1:PersonName>ft
and Yah<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=
=3D"on">o</st1:PersonName>
have all argued that they have hardened servers t<st1:PersonName w:st=3D"on=
">o</st1:PersonName>
withstand attacks, but e-mail w<st1:PersonName w:st=3D"on">o</st1:PersonNam=
e>rms,
<span class=3DSpellE>phishing</span> attacks and <st1:PersonName w:st=3D"on=
">o</st1:PersonName>ther
assaults are still <span class=3DGramE>r<st1:PersonName w:st=3D"on">o</st1:=
PersonName>utine</span>.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>That's
why Yah<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=
=3D"on">o</st1:PersonName>'s
<span class=3DSpellE>Bejar</span> argues that m<st1:PersonName w:st=3D"on">=
o</st1:PersonName>re
industry c<st1:PersonName w:st=3D"on">o</st1:PersonName>llab<st1:PersonName
w:st=3D"on">o</st1:PersonName>rati<st1:PersonName w:st=3D"on">o</st1:Person=
Name>n
is needed. As an example <st1:PersonName w:st=3D"on">o</st1:PersonName>f a
successful c<st1:PersonName w:st=3D"on">o</st1:PersonName>rp<st1:PersonName
w:st=3D"on">o</st1:PersonName>rate arrangement, he cites Yah<st1:PersonName
w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D"on">o</st1:PersonName=
>'s
partnerships with eBay and <span class=3DSpellE>PayPal</span>, and he w<st1=
:PersonName
w:st=3D"on">o</st1:PersonName>uld like t<st1:PersonName w:st=3D"on">o</st1:=
PersonName>
reach <st1:PersonName w:st=3D"on">o</st1:PersonName>ut m<st1:PersonName w:s=
t=3D"on">o</st1:PersonName>re
t<st1:PersonName w:st=3D"on">o</st1:PersonName> MSN and G<st1:PersonName w:=
st=3D"on">o</st1:PersonName><st1:PersonName
w:st=3D"on">o</st1:PersonName>gle as well as <st1:PersonName w:st=3D"on">o<=
/st1:PersonName>ther
industry gr<st1:PersonName w:st=3D"on">o</st1:PersonName>ups.<o:p></o:p></s=
pan></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>It
isn't just Web sites and <st1:PersonName w:st=3D"on">o</st1:PersonName>nline
applicati<st1:PersonName w:st=3D"on">o</st1:PersonName>ns that need better
security, <span class=3DSpellE>Bejar</span> argues. Other fact<st1:PersonNa=
me
w:st=3D"on">o</st1:PersonName>rs, such as str<st1:PersonName w:st=3D"on">o<=
/st1:PersonName>nger
br<st1:PersonName w:st=3D"on">o</st1:PersonName>wser security, c<st1:Person=
Name
w:st=3D"on">o</st1:PersonName>uld make a huge difference.<o:p></o:p></span>=
</p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>There's
just <st1:PersonName w:st=3D"on">o</st1:PersonName>ne pr<st1:PersonName w:s=
t=3D"on">o</st1:PersonName>blem:
Yah<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D"on=
">o</st1:PersonName>
d<st1:PersonName w:st=3D"on">o</st1:PersonName>esn't c<st1:PersonName w:st=
=3D"on">o</st1:PersonName>ntr<st1:PersonName
w:st=3D"on">o</st1:PersonName>l the br<st1:PersonName w:st=3D"on">o</st1:Pe=
rsonName>wser.
&quot;There are challenges being presented by the br<st1:PersonName w:st=3D=
"on">o</st1:PersonName>wser
security m<st1:PersonName w:st=3D"on">o</st1:PersonName>del that we as an
industry need t<st1:PersonName w:st=3D"on">o</st1:PersonName> w<st1:PersonN=
ame
w:st=3D"on">o</st1:PersonName>rk <st1:PersonName w:st=3D"on">o</st1:PersonN=
ame>n t<st1:PersonName
w:st=3D"on">o</st1:PersonName>gether,&quot; <span class=3DSpellE>Bejar</spa=
n> said.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>G<st1:PersonName
w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=3D"on">o</st1:PersonName=
>gle is
attempting t<st1:PersonName w:st=3D"on">o</st1:PersonName> w<st1:PersonName
w:st=3D"on">o</st1:PersonName>rk ar<st1:PersonName w:st=3D"on">o</st1:Perso=
nName>und
that pr<st1:PersonName w:st=3D"on">o</st1:PersonName>blem by <a
href=3D"http://news.com.com/8301-10784_3-9723273-7.html"><span style=3D'col=
or:windowtext;
text-decoration:none;text-underline:none'>acquiring some technology</span><=
/a>
that c<st1:PersonName w:st=3D"on">o</st1:PersonName>uld make Web br<st1:Per=
sonName
w:st=3D"on">o</st1:PersonName>wsing safer. Micr<st1:PersonName w:st=3D"on">=
o</st1:PersonName>s<st1:PersonName
w:st=3D"on">o</st1:PersonName>ft has <a
href=3D"http://news.com.com/With+IE+7%2C+green+means+go+for+legit+sites/210=
0-1029_3-6134647.html"
title=3D"With IE 7, green means go for legit sites -- Monday, Nov 13, 2006"=
><span
style=3D'color:windowtext;text-decoration:none;text-underline:none'>develop=
ed
features</span></a> such as the green bar in Internet Expl<st1:PersonName
w:st=3D"on">o</st1:PersonName>rer 7 t<st1:PersonName w:st=3D"on">o</st1:Per=
sonName>
indicate &quot;trusted&quot; Web sites, part <st1:PersonName w:st=3D"on">o<=
/st1:PersonName>f
an initiative that als<st1:PersonName w:st=3D"on">o</st1:PersonName> inv<st=
1:PersonName
w:st=3D"on">o</st1:PersonName>lves KDE, <span class=3DSpellE>M<st1:PersonNa=
me
w:st=3D"on">o</st1:PersonName>zilla</span>, Opera S<st1:PersonName w:st=3D"=
on">o</st1:PersonName>ftware
and <st1:PersonName w:st=3D"on">o</st1:PersonName>ther br<st1:PersonName w:=
st=3D"on">o</st1:PersonName>wser
makers.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>All
this is a g<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonName w:=
st=3D"on">o</st1:PersonName>d
start, but it's m<st1:PersonName w:st=3D"on">o</st1:PersonName>stly reactiv=
e.
Security experts at the Big Three c<st1:PersonName w:st=3D"on">o</st1:Perso=
nName>mpanies
believe that m<st1:PersonName w:st=3D"on">o</st1:PersonName>re needs t<st1:=
PersonName
w:st=3D"on">o</st1:PersonName> be d<st1:PersonName w:st=3D"on">o</st1:Perso=
nName>ne
at the r<st1:PersonName w:st=3D"on">o</st1:PersonName><st1:PersonName w:st=
=3D"on">o</st1:PersonName>t
level <st1:PersonName w:st=3D"on">o</st1:PersonName>f s<st1:PersonName w:st=
=3D"on">o</st1:PersonName>ftware
devel<st1:PersonName w:st=3D"on">o</st1:PersonName>pment, starting at the
university level t<st1:PersonName w:st=3D"on">o</st1:PersonName> teach secu=
rity t<st1:PersonName
w:st=3D"on">o</st1:PersonName> the inc<st1:PersonName w:st=3D"on">o</st1:Pe=
rsonName>ming
w<st1:PersonName w:st=3D"on">o</st1:PersonName>rkf<st1:PersonName w:st=3D"o=
n">o</st1:PersonName>rce
as early as p<st1:PersonName w:st=3D"on">o</st1:PersonName>ssible.<o:p></o:=
p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>Universities
sh<st1:PersonName w:st=3D"on">o</st1:PersonName>uld <st1:PersonName w:st=3D=
"on">o</st1:PersonName>ffer
m<st1:PersonName w:st=3D"on">o</st1:PersonName>re c<st1:PersonName w:st=3D"=
on">o</st1:PersonName>urses
that bridge the gap between what applicati<st1:PersonName w:st=3D"on">o</st=
1:PersonName>ns
sh<st1:PersonName w:st=3D"on">o</st1:PersonName>uld d<st1:PersonName w:st=
=3D"on">o</st1:PersonName>
and what they can d<st1:PersonName w:st=3D"on">o</st1:PersonName>--an appr<=
st1:PersonName
w:st=3D"on">o</st1:PersonName>ach t<st1:PersonName w:st=3D"on">o</st1:Perso=
nName>
engineering that isn't widely taught t<st1:PersonName w:st=3D"on">o</st1:Pe=
rsonName>day.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
>Simply
put, <span class=3DSpellE>Bejar</span> says, &quot;We need t<st1:PersonName
w:st=3D"on">o</st1:PersonName> make sure that we're <st1:PersonName w:st=3D=
"on">o</st1:PersonName>n
the same page.&quot; <o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
><o:p>&nbsp;</o:p></span></p>

<p class=3DMsoNormal style=3D'margin-bottom:5.0pt'><span lang=3DEN style=3D=
'font-size:
6.0pt;font-family:Verdana;mso-bidi-font-family:Tahoma;mso-ansi-language:EN'=
><o:p>&nbsp;</o:p></span></p>

</div>

</body>

</html>
