<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Security Alert for Windows XP Users</title>
	<atom:link href="http://krebsonsecurity.com/2010/06/security-alert-for-windows-xp-users/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/06/security-alert-for-windows-xp-users/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Sat, 11 Feb 2012 19:29:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: InfoSec Pro</title>
		<link>http://krebsonsecurity.com/2010/06/security-alert-for-windows-xp-users/comment-page-1/#comment-6896</link>
		<dc:creator>InfoSec Pro</dc:creator>
		<pubDate>Thu, 17 Jun 2010 13:38:27 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3552#comment-6896</guid>
		<description>@Bill, no Ormandy did not &quot;open the door to criminals to attack users&quot;, that was Microsoft&#039;s doing when they shipped flawed code.

Ormandy did users a valuable service by alerting them to the fact that the door was open, and not letting Microsoft keep that fact hidden from their customers.  

The criminals find the open attack vectors without needing security warnings to direct them!</description>
		<content:encoded><![CDATA[<p>@Bill, no Ormandy did not &#8220;open the door to criminals to attack users&#8221;, that was Microsoft&#8217;s doing when they shipped flawed code.</p>
<p>Ormandy did users a valuable service by alerting them to the fact that the door was open, and not letting Microsoft keep that fact hidden from their customers.  </p>
<p>The criminals find the open attack vectors without needing security warnings to direct them!</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6896" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6896', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6896-up" style="font-size:14px; color:#009933;">3</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6896" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6896', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6896-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Bill</title>
		<link>http://krebsonsecurity.com/2010/06/security-alert-for-windows-xp-users/comment-page-1/#comment-6890</link>
		<dc:creator>Bill</dc:creator>
		<pubDate>Thu, 17 Jun 2010 07:19:40 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3552#comment-6890</guid>
		<description>I don&#039;t agree with Google&#039;s Ormandy&#039;s action.  He may self-righteously justify his action by pretending to urge MS into action.  In fact, he opened the door to criminals to attack users.  I would suggest that instead, he publicize the fact that such an exploitable hole exists, via the many web sites and blogs (such as this one) that discuss such matters, so that users can take remedial action.  He should also warn MS that he will publish the code by a certain date - giving them time to craft a fix.  Then he could, with perhaps a better conscience, publish the exploit.  Personally, I don&#039;t think it&#039;s ever justified to publish the details of how to exploit holes, since that only benefits criminals, not users.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t agree with Google&#8217;s Ormandy&#8217;s action.  He may self-righteously justify his action by pretending to urge MS into action.  In fact, he opened the door to criminals to attack users.  I would suggest that instead, he publicize the fact that such an exploitable hole exists, via the many web sites and blogs (such as this one) that discuss such matters, so that users can take remedial action.  He should also warn MS that he will publish the code by a certain date &#8211; giving them time to craft a fix.  Then he could, with perhaps a better conscience, publish the exploit.  Personally, I don&#8217;t think it&#8217;s ever justified to publish the details of how to exploit holes, since that only benefits criminals, not users.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6890" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6890', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6890-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6890" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6890', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6890-down" style="font-size:14px; color:#990033;">3</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Dows</title>
		<link>http://krebsonsecurity.com/2010/06/security-alert-for-windows-xp-users/comment-page-1/#comment-6886</link>
		<dc:creator>Dave Dows</dc:creator>
		<pubDate>Thu, 17 Jun 2010 01:39:13 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3552#comment-6886</guid>
		<description>@xAdmin

That&#039;s why I prefaced my mention of Drop My Rights with the phrase &quot;If it’s too inconvenient to run XP as a non-admin&quot;.

I&#039;m one of those who spends almost as much time doing Admin tasks as anything else. Before Drop My Rights, all I could do was install the best FW/AV/AS available, work in a VM whenever possible and use products such as Sandboxie, BufferZone or DefenseWall. 

I find most HIPS products to be too cumbersome and chatty, but DMR or one of the three mentioned above seems more acceptable to me. 

Please note that I also limited my claim for DMR to say &quot;this offers  *SOME*  [new emphasis mine] of the protection of a Limited User Account&quot;, and prefaced it with the thought that some malware writers may find a way around DMR, if they haven&#039;t already.</description>
		<content:encoded><![CDATA[<p>@xAdmin</p>
<p>That&#8217;s why I prefaced my mention of Drop My Rights with the phrase &#8220;If it’s too inconvenient to run XP as a non-admin&#8221;.</p>
<p>I&#8217;m one of those who spends almost as much time doing Admin tasks as anything else. Before Drop My Rights, all I could do was install the best FW/AV/AS available, work in a VM whenever possible and use products such as Sandboxie, BufferZone or DefenseWall. </p>
<p>I find most HIPS products to be too cumbersome and chatty, but DMR or one of the three mentioned above seems more acceptable to me. </p>
<p>Please note that I also limited my claim for DMR to say &#8220;this offers  *SOME*  [new emphasis mine] of the protection of a Limited User Account&#8221;, and prefaced it with the thought that some malware writers may find a way around DMR, if they haven&#8217;t already.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6886" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6886', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6886-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6886" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6886', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6886-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Rick</title>
		<link>http://krebsonsecurity.com/2010/06/security-alert-for-windows-xp-users/comment-page-1/#comment-6883</link>
		<dc:creator>Rick</dc:creator>
		<pubDate>Wed, 16 Jun 2010 08:27:37 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3552#comment-6883</guid>
		<description>&#039;Google&#039;s Ormandy, who has privately alerted Microsoft to a large number of security flaws he found in the company&#039;s products over the years, indicated he was releasing the details of this bug publicly just five days after alerting Microsoft in an effort to force Microsoft to patch the flaw more quickly than it would have otherwise.&#039;

I&#039;m OK with that. Ormandy&#039;s one of the good guys too.</description>
		<content:encoded><![CDATA[<p>&#8216;Google&#8217;s Ormandy, who has privately alerted Microsoft to a large number of security flaws he found in the company&#8217;s products over the years, indicated he was releasing the details of this bug publicly just five days after alerting Microsoft in an effort to force Microsoft to patch the flaw more quickly than it would have otherwise.&#8217;</p>
<p>I&#8217;m OK with that. Ormandy&#8217;s one of the good guys too.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6883" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6883', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6883-up" style="font-size:14px; color:#009933;">4</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6883" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6883', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6883-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: xAdmin</title>
		<link>http://krebsonsecurity.com/2010/06/security-alert-for-windows-xp-users/comment-page-1/#comment-6866</link>
		<dc:creator>xAdmin</dc:creator>
		<pubDate>Tue, 15 Jun 2010 19:16:12 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3552#comment-6866</guid>
		<description>While I agree that Drop My Rights can provide a level of security, it is by no means a match for actually running as a limited user. Because, if some nasty does get past your limited run application, it still has complete full administrator access to do what it wants on the OS. The same cannot be said when logged in as a limited user where system wide changes cannot be implemented and the only possbile impact is to the currently logged in limited user. :)</description>
		<content:encoded><![CDATA[<p>While I agree that Drop My Rights can provide a level of security, it is by no means a match for actually running as a limited user. Because, if some nasty does get past your limited run application, it still has complete full administrator access to do what it wants on the OS. The same cannot be said when logged in as a limited user where system wide changes cannot be implemented and the only possbile impact is to the currently logged in limited user. <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6866" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6866', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6866-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6866" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6866', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6866-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: David</title>
		<link>http://krebsonsecurity.com/2010/06/security-alert-for-windows-xp-users/comment-page-1/#comment-6852</link>
		<dc:creator>David</dc:creator>
		<pubDate>Tue, 15 Jun 2010 16:52:43 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3552#comment-6852</guid>
		<description>Maybe Tavis Ormandy was within the box of acceptable behavior with this disclosure? A case for it adhering to one type of long established disclosure policy is made at my blog: http://sharpesecurity.blogspot.com/2010/06/was-tavis-ormandys-disclosure.html</description>
		<content:encoded><![CDATA[<p>Maybe Tavis Ormandy was within the box of acceptable behavior with this disclosure? A case for it adhering to one type of long established disclosure policy is made at my blog: <a href="http://sharpesecurity.blogspot.com/2010/06/was-tavis-ormandys-disclosure.html" rel="nofollow">http://sharpesecurity.blogspot.com/2010/06/was-tavis-ormandys-disclosure.html</a></p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6852" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6852', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6852-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6852" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6852', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6852-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: jerry</title>
		<link>http://krebsonsecurity.com/2010/06/security-alert-for-windows-xp-users/comment-page-1/#comment-6840</link>
		<dc:creator>jerry</dc:creator>
		<pubDate>Tue, 15 Jun 2010 14:10:45 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3552#comment-6840</guid>
		<description>Nice post XAdmin. I&#039;ve disabled the security and help center on my 2 pcs. Never used it anyway.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFFFCC !important"><p>Nice post XAdmin. I&#8217;ve disabled the security and help center on my 2 pcs. Never used it anyway.</p>
</div><div class="CommentRating">Well-loved. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6840" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6840', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6840-up" style="font-size:14px; color:#009933;">5</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6840" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6840', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6840-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: AJNorth</title>
		<link>http://krebsonsecurity.com/2010/06/security-alert-for-windows-xp-users/comment-page-1/#comment-6837</link>
		<dc:creator>AJNorth</dc:creator>
		<pubDate>Tue, 15 Jun 2010 12:51:24 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3552#comment-6837</guid>
		<description>Hello Brian,

Just a minor suggestion: rather than your alerts having the Subject of &quot;[Krebs on Security] Once Hourly Digest Email,&quot; might you instead replace the portion following the bracket with the descriptor, which in the case of this alert is &quot;Security Alert for Windows XP Users&quot;?

Your Post columns continue to be missed (along with the monthly chat sessions).

Regards,

AJ</description>
		<content:encoded><![CDATA[<p>Hello Brian,</p>
<p>Just a minor suggestion: rather than your alerts having the Subject of &#8220;[Krebs on Security] Once Hourly Digest Email,&#8221; might you instead replace the portion following the bracket with the descriptor, which in the case of this alert is &#8220;Security Alert for Windows XP Users&#8221;?</p>
<p>Your Post columns continue to be missed (along with the monthly chat sessions).</p>
<p>Regards,</p>
<p>AJ</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6837" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6837', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6837-up" style="font-size:14px; color:#009933;">3</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6837" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6837', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6837-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Dows</title>
		<link>http://krebsonsecurity.com/2010/06/security-alert-for-windows-xp-users/comment-page-1/#comment-6827</link>
		<dc:creator>Dave Dows</dc:creator>
		<pubDate>Tue, 15 Jun 2010 03:09:04 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3552#comment-6827</guid>
		<description>If it&#039;s too inconvenient to run XP as a non-admin, there is another relatively easy way to browse and read email without administrative rights. 

You just start ALL browsers, email clients or any other internet enabled apps from specially modified shortcuts that invoke &quot;Down My Rights&quot; which then invokes the target app with limited rights. 

The following link is for a user group&#039;s page with links to the Microsoft download page for DMR and a zip file with shortcuts already modified to use DMR.

http://cybercoyote.org/security/drop.shtml

However, to be protected, you must not use any desktop URL shortcuts, because they would circumvent the solution. Favorites or Bookmarks should only be opened from within a browser invoked by &quot;Down My Rights&quot;.

Another slight adjustment is that any Setup executable, which would require Admin rights, cannot be &quot;Run&quot; from the internet. It must be &quot;Saved&quot;, then run from a folder opened in Windows Explorer, not directly from within IE or any other browser running from DMR.

If you use DMR with Firefox, it will even block you from running an installation from DownThemAll, but it&#039;s easy enough to right-click and &quot;Open (the) directory&quot;. Because Windows Explorer is already running with your full rights, you can then install the downloaded item from within its folder.

Unless the bad guys have figured out how to write their malware to invoke themselves from Windows Explorer instead of the browser&#039;s context, this offers some of the protection of a Limited User Account. Does anyone know of any malware designed to get around DMR this way?</description>
		<content:encoded><![CDATA[<p>If it&#8217;s too inconvenient to run XP as a non-admin, there is another relatively easy way to browse and read email without administrative rights. </p>
<p>You just start ALL browsers, email clients or any other internet enabled apps from specially modified shortcuts that invoke &#8220;Down My Rights&#8221; which then invokes the target app with limited rights. </p>
<p>The following link is for a user group&#8217;s page with links to the Microsoft download page for DMR and a zip file with shortcuts already modified to use DMR.</p>
<p><a href="http://cybercoyote.org/security/drop.shtml" rel="nofollow">http://cybercoyote.org/security/drop.shtml</a></p>
<p>However, to be protected, you must not use any desktop URL shortcuts, because they would circumvent the solution. Favorites or Bookmarks should only be opened from within a browser invoked by &#8220;Down My Rights&#8221;.</p>
<p>Another slight adjustment is that any Setup executable, which would require Admin rights, cannot be &#8220;Run&#8221; from the internet. It must be &#8220;Saved&#8221;, then run from a folder opened in Windows Explorer, not directly from within IE or any other browser running from DMR.</p>
<p>If you use DMR with Firefox, it will even block you from running an installation from DownThemAll, but it&#8217;s easy enough to right-click and &#8220;Open (the) directory&#8221;. Because Windows Explorer is already running with your full rights, you can then install the downloaded item from within its folder.</p>
<p>Unless the bad guys have figured out how to write their malware to invoke themselves from Windows Explorer instead of the browser&#8217;s context, this offers some of the protection of a Limited User Account. Does anyone know of any malware designed to get around DMR this way?</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6827" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6827', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6827-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6827" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6827', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6827-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://krebsonsecurity.com/2010/06/security-alert-for-windows-xp-users/comment-page-1/#comment-6826</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Tue, 15 Jun 2010 02:18:15 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3552#comment-6826</guid>
		<description>As a non-geek, I always (try to) surf the net on a user account because security blogs say so. If you drive XP and haven&#039;t created a user account for surfing the net, please do so. It&#039;s like seatbelts - they came with the car but to get the protection, you have to exercise the option (put them on) every(!) time you get in the car.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFFFCC !important"><p>As a non-geek, I always (try to) surf the net on a user account because security blogs say so. If you drive XP and haven&#8217;t created a user account for surfing the net, please do so. It&#8217;s like seatbelts &#8211; they came with the car but to get the protection, you have to exercise the option (put them on) every(!) time you get in the car.</p>
</div><div class="CommentRating">Well-loved. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6826" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6826', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6826-up" style="font-size:14px; color:#009933;">8</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6826" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6826', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6826-down" style="font-size:14px; color:#990033;">3</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 4/20 queries in 0.012 seconds using memcached
Object Caching 947/959 objects using memcached

Served from: krebsonsecurity.com @ 2012-02-11 23:21:23 -->
