<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Alberta Budget 2010 website &#8211; security through obscurity</title>
	<atom:link href="http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/</link>
	<description>The official blog of Mack D. Male, an Edmonton blogger.</description>
	<lastBuildDate>Sun, 12 Feb 2012 05:00:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Open Government &#8211; Embargoed in Alberta &#124; fusedlogic</title>
		<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/comment-page-1/#comment-154164</link>
		<dc:creator>Open Government &#8211; Embargoed in Alberta &#124; fusedlogic</dc:creator>
		<pubDate>Fri, 09 Apr 2010 04:58:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/#comment-154164</guid>
		<description>[...]  [...]</description>
		<content:encoded><![CDATA[<p>[...]  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christmas Charity Auction Dinner at Ric&#8217;s Grill at MasterMaq&#39;s Blog</title>
		<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/comment-page-1/#comment-149695</link>
		<dc:creator>Christmas Charity Auction Dinner at Ric&#8217;s Grill at MasterMaq&#39;s Blog</dc:creator>
		<pubDate>Thu, 18 Feb 2010 02:41:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/#comment-149695</guid>
		<description>[...] number of Edmontonians do! We talked a little about memorable blogging moments, given that the Alberta budget website thing had just happened, and of course about how Sharon and I got into [...]</description>
		<content:encoded><![CDATA[<p>[...] number of Edmontonians do! We talked a little about memorable blogging moments, given that the Alberta budget website thing had just happened, and of course about how Sharon and I got into [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anon</title>
		<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/comment-page-1/#comment-149194</link>
		<dc:creator>Anon</dc:creator>
		<pubDate>Thu, 11 Feb 2010 18:13:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/#comment-149194</guid>
		<description>You managed to access a placeholder website that did not contain budget materials.  When budget materials were subsequently added, the security was updated and you could no longer access the site.  How is this news?</description>
		<content:encoded><![CDATA[<p>You managed to access a placeholder website that did not contain budget materials.  When budget materials were subsequently added, the security was updated and you could no longer access the site.  How is this news?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kathleen</title>
		<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/comment-page-1/#comment-149149</link>
		<dc:creator>Kathleen</dc:creator>
		<pubDate>Wed, 10 Feb 2010 18:48:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/#comment-149149</guid>
		<description>Mack,

What I&#039;m trying to say there is that we&#039;d make fun of it, of course we would. However, you&#039;re right that we would probably want to help it, too.

Thanks.</description>
		<content:encoded><![CDATA[<p>Mack,</p>
<p>What I&#8217;m trying to say there is that we&#8217;d make fun of it, of course we would. However, you&#8217;re right that we would probably want to help it, too.</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mack D. Male</title>
		<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/comment-page-1/#comment-149140</link>
		<dc:creator>Mack D. Male</dc:creator>
		<pubDate>Wed, 10 Feb 2010 15:41:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/#comment-149140</guid>
		<description>Alain is right - we&#039;re lucky that this time it was just some placeholder text. And of course I absolutely did NOT have any malicious intent. I didn&#039;t expect to find anything at the site, except maybe details on the press release and such.</description>
		<content:encoded><![CDATA[<p>Alain is right &#8211; we&#8217;re lucky that this time it was just some placeholder text. And of course I absolutely did NOT have any malicious intent. I didn&#8217;t expect to find anything at the site, except maybe details on the press release and such.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alain Saffel</title>
		<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/comment-page-1/#comment-149124</link>
		<dc:creator>Alain Saffel</dc:creator>
		<pubDate>Wed, 10 Feb 2010 08:19:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/#comment-149124</guid>
		<description>To &quot;Fred&quot; and &quot;T&quot;

Information security is something that is important to every citizen of Alberta and if Mack discovered something like this, good for him reporting it to the rest of us. 

These things need to be made public so we can embarrass the government into protecting our information properly.

This time it was only the budget. Next time it could be enough information to steal your identity.

This isn&#039;t the first time that websites are open to exploit, laptops are stolen, files are tossed into regular trash, etc.

FYI, there is a major difference between Mack trying THE most obvious hack ever and SQL attacks, and that is intent. I don&#039;t believe for a minute there was any malicious intent on Mack&#039;s part.

If you&#039;re going to make accusations, why not sign your full name to them instead of hiding behind an initial or first name? Make me wonder about your intent.</description>
		<content:encoded><![CDATA[<p>To &#8220;Fred&#8221; and &#8220;T&#8221;</p>
<p>Information security is something that is important to every citizen of Alberta and if Mack discovered something like this, good for him reporting it to the rest of us. </p>
<p>These things need to be made public so we can embarrass the government into protecting our information properly.</p>
<p>This time it was only the budget. Next time it could be enough information to steal your identity.</p>
<p>This isn&#8217;t the first time that websites are open to exploit, laptops are stolen, files are tossed into regular trash, etc.</p>
<p>FYI, there is a major difference between Mack trying THE most obvious hack ever and SQL attacks, and that is intent. I don&#8217;t believe for a minute there was any malicious intent on Mack&#8217;s part.</p>
<p>If you&#8217;re going to make accusations, why not sign your full name to them instead of hiding behind an initial or first name? Make me wonder about your intent.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: T</title>
		<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/comment-page-1/#comment-149097</link>
		<dc:creator>T</dc:creator>
		<pubDate>Tue, 09 Feb 2010 22:27:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/#comment-149097</guid>
		<description>Is this no different than someone who does SQL attacks with the intent of finding some information?

Weak passwords aside, If you came public with this first before attempting to contact someone to fix it I hope there is some form of justice/punishment comes to you.

Again if you blogged about this without contacting someone first you just crave attention.

Find an exploit? Contact the admin to have it patched. You actions are no different than people trying to steal corporate secrets.</description>
		<content:encoded><![CDATA[<p>Is this no different than someone who does SQL attacks with the intent of finding some information?</p>
<p>Weak passwords aside, If you came public with this first before attempting to contact someone to fix it I hope there is some form of justice/punishment comes to you.</p>
<p>Again if you blogged about this without contacting someone first you just crave attention.</p>
<p>Find an exploit? Contact the admin to have it patched. You actions are no different than people trying to steal corporate secrets.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Jackson</title>
		<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/comment-page-1/#comment-149095</link>
		<dc:creator>Justin Jackson</dc:creator>
		<pubDate>Tue, 09 Feb 2010 21:47:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/#comment-149095</guid>
		<description>I think this is a real security issue.  I would say two things:

1) A site that hasn&#039;t gone live yet shouldn&#039;t default to a login screen.  It looks bad, and invites visitors to try logging in.

2) A site should never have an account where &quot;administrator&quot; and &quot;password&quot; provides access.

Even though there was nothing really &quot;there&quot; once Mack got in, it still represents a breach.</description>
		<content:encoded><![CDATA[<p>I think this is a real security issue.  I would say two things:</p>
<p>1) A site that hasn&#8217;t gone live yet shouldn&#8217;t default to a login screen.  It looks bad, and invites visitors to try logging in.</p>
<p>2) A site should never have an account where &#8220;administrator&#8221; and &#8220;password&#8221; provides access.</p>
<p>Even though there was nothing really &#8220;there&#8221; once Mack got in, it still represents a breach.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Keith</title>
		<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/comment-page-1/#comment-149094</link>
		<dc:creator>Keith</dc:creator>
		<pubDate>Tue, 09 Feb 2010 21:47:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/#comment-149094</guid>
		<description>Just excellent work. We are watching the budget for one reason only here in Saskatchewan...&quot;Are they going to &#039;thaw&#039; the job &#039;freeze&#039;?! My fiance is waiting to get a call to start work in Alberta, but they cannot make that call until this &quot;hiring freeze&quot; is over. 

Just bad luck/timing on us I guess!

Thanks Mack</description>
		<content:encoded><![CDATA[<p>Just excellent work. We are watching the budget for one reason only here in Saskatchewan&#8230;&#8221;Are they going to &#8216;thaw&#8217; the job &#8216;freeze&#8217;?! My fiance is waiting to get a call to start work in Alberta, but they cannot make that call until this &#8220;hiring freeze&#8221; is over. </p>
<p>Just bad luck/timing on us I guess!</p>
<p>Thanks Mack</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sally</title>
		<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/comment-page-1/#comment-149093</link>
		<dc:creator>sally</dc:creator>
		<pubDate>Tue, 09 Feb 2010 21:30:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/#comment-149093</guid>
		<description>wow, mack, you&#039;re the best. this made my day.</description>
		<content:encoded><![CDATA[<p>wow, mack, you&#8217;re the best. this made my day.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mack D. Male</title>
		<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/comment-page-1/#comment-149084</link>
		<dc:creator>Mack D. Male</dc:creator>
		<pubDate>Tue, 09 Feb 2010 20:20:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/#comment-149084</guid>
		<description>You&#039;re right Fred, not much...just the theme of the budget, and the breakdown in documents and charts that we can expect to see later today.

The point is that they got lucky this time. We need to ensure this sort of mistake isn&#039;t repeated!</description>
		<content:encoded><![CDATA[<p>You&#8217;re right Fred, not much&#8230;just the theme of the budget, and the breakdown in documents and charts that we can expect to see later today.</p>
<p>The point is that they got lucky this time. We need to ensure this sort of mistake isn&#8217;t repeated!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fred</title>
		<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/comment-page-1/#comment-149083</link>
		<dc:creator>Fred</dc:creator>
		<pubDate>Tue, 09 Feb 2010 20:18:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/#comment-149083</guid>
		<description>What exactly did you see except a placeholder site with nothing on it.  All I see is someone who wants his name in the media.</description>
		<content:encoded><![CDATA[<p>What exactly did you see except a placeholder site with nothing on it.  All I see is someone who wants his name in the media.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason</title>
		<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/comment-page-1/#comment-149082</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Tue, 09 Feb 2010 20:16:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/#comment-149082</guid>
		<description>Wow, I can&#039;t believe that... I used to work for one of the ministries and we never had any security on our sites that lax...</description>
		<content:encoded><![CDATA[<p>Wow, I can&#8217;t believe that&#8230; I used to work for one of the ministries and we never had any security on our sites that lax&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jenn</title>
		<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/comment-page-1/#comment-149081</link>
		<dc:creator>Jenn</dc:creator>
		<pubDate>Tue, 09 Feb 2010 20:11:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/#comment-149081</guid>
		<description>Mack,

You win.</description>
		<content:encoded><![CDATA[<p>Mack,</p>
<p>You win.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Colin</title>
		<link>http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/comment-page-1/#comment-149075</link>
		<dc:creator>Colin</dc:creator>
		<pubDate>Tue, 09 Feb 2010 18:28:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mastermaq.ca/2010/02/09/alberta-budget-2010-website-security-through-obscurity/#comment-149075</guid>
		<description>You may have fallen fowl of the Computer Misuse Act has you done this in the UK ;)</description>
		<content:encoded><![CDATA[<p>You may have fallen fowl of the Computer Misuse Act has you done this in the UK <img src='http://blog.mastermaq.ca/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

