<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	>
<channel>
	<title>Comments on: A Tale of Two Vendors or Security Sells</title>
	<atom:link href="http://www.securitycatalyst.com/a-tale-of-two-vendors-or-security-sells/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitycatalyst.com/a-tale-of-two-vendors-or-security-sells/</link>
	<description>Michael Santarcangelo delivers Awareness that Works™</description>
	<lastBuildDate>Wed, 01 Sep 2010 14:21:57 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Bill Pennington</title>
		<link>http://www.securitycatalyst.com/a-tale-of-two-vendors-or-security-sells/comment-page-1/#comment-889</link>
		<dc:creator>Bill Pennington</dc:creator>
		<pubDate>Mon, 30 Mar 2009 19:52:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=1126#comment-889</guid>
		<description>@Vincent: Yes they seemed rather naive about the whole process and defensive to the point of aggression. Them: &quot;This can&#039;t happen cause of 1,2,3!&quot;   Us: &quot;Click here and tell me if that is data from your DB.&quot; Them: &quot;But you have to be logged in...&quot; Painful

@Michael - Good point and one that I had not thought about before but yes #1 was much larger than #2.</description>
		<content:encoded><![CDATA[<p>@Vincent: Yes they seemed rather naive about the whole process and defensive to the point of aggression. Them: &#8220;This can&#8217;t happen cause of 1,2,3!&#8221;   Us: &#8220;Click here and tell me if that is data from your DB.&#8221; Them: &#8220;But you have to be logged in&#8230;&#8221; Painful</p>
<p>@Michael &#8211; Good point and one that I had not thought about before but yes #1 was much larger than #2.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Dickey</title>
		<link>http://www.securitycatalyst.com/a-tale-of-two-vendors-or-security-sells/comment-page-1/#comment-888</link>
		<dc:creator>Michael Dickey</dc:creator>
		<pubDate>Mon, 30 Mar 2009 19:04:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=1126#comment-888</guid>
		<description>I just wanted to post back my kudos for valuing security and sticking with a vendor who responded who I think we wish all vendors did. Too often, I think many decisions like this would still go with vendor #1 because they had better features...which keeps us all in the hole trying to dig out.

So, good job!

As a second thought, I wonder if the size of the two vendors had any bearing on the response? For instance, if Vender #1 is large and slow-moving and Vendor #2 smaller and more agile.</description>
		<content:encoded><![CDATA[<p>I just wanted to post back my kudos for valuing security and sticking with a vendor who responded who I think we wish all vendors did. Too often, I think many decisions like this would still go with vendor #1 because they had better features&#8230;which keeps us all in the hole trying to dig out.</p>
<p>So, good job!</p>
<p>As a second thought, I wonder if the size of the two vendors had any bearing on the response? For instance, if Vender #1 is large and slow-moving and Vendor #2 smaller and more agile.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vincent Ray</title>
		<link>http://www.securitycatalyst.com/a-tale-of-two-vendors-or-security-sells/comment-page-1/#comment-885</link>
		<dc:creator>Vincent Ray</dc:creator>
		<pubDate>Mon, 30 Mar 2009 18:00:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=1126#comment-885</guid>
		<description>Bill,

Excellent write-up.  It&#039;s refreshing to see both vendor and customer working together to improve a product.  Especially in the area of security!  More often than not, collaboration between vendors and customers is limited to feature requests.  It&#039;s a rare find to have someone submit feedback on security.

I can&#039;t help but feel that Vendor #1 had an inexperienced sales/development team.  Security is not to be taken lightly.  If you are getting feedback about SQL injection with hard results sitting in front of you, any good developer would take that to heart and do something about it.  

I&#039;d just like to commend you for being so upfront and positive about help Vendor #2 move forward.


Vincent
MHelpdesk - &lt;a href=&quot;http://www.mhelpdesk.com/service-management-software.aspx&quot; rel=&quot;nofollow&quot;&gt;Service Management Software&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Bill,</p>
<p>Excellent write-up.  It&#8217;s refreshing to see both vendor and customer working together to improve a product.  Especially in the area of security!  More often than not, collaboration between vendors and customers is limited to feature requests.  It&#8217;s a rare find to have someone submit feedback on security.</p>
<p>I can&#8217;t help but feel that Vendor #1 had an inexperienced sales/development team.  Security is not to be taken lightly.  If you are getting feedback about SQL injection with hard results sitting in front of you, any good developer would take that to heart and do something about it.  </p>
<p>I&#8217;d just like to commend you for being so upfront and positive about help Vendor #2 move forward.</p>
<p>Vincent<br />
MHelpdesk &#8211; <a href="http://www.mhelpdesk.com/service-management-software.aspx" rel="nofollow">Service Management Software</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Interesting Information Security Bits for 03/30/2009 &#124; Infosec Ramblings</title>
		<link>http://www.securitycatalyst.com/a-tale-of-two-vendors-or-security-sells/comment-page-1/#comment-884</link>
		<dc:creator>Interesting Information Security Bits for 03/30/2009 &#124; Infosec Ramblings</dc:creator>
		<pubDate>Mon, 30 Mar 2009 13:33:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=1126#comment-884</guid>
		<description>[...] to an important point. We don&#8217;t have to be perfect, but we have to be willing to try to be. A Tale of Two Vendors or Security Sells : The Security Catalyst Tags: ( general [...]</description>
		<content:encoded><![CDATA[<p>[...] to an important point. We don&#8217;t have to be perfect, but we have to be willing to try to be. A Tale of Two Vendors or Security Sells : The Security Catalyst Tags: ( general [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
