<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Followup:  Hannaford Used Rapid7 for Security</title>
	<atom:link href="http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/</link>
	<description>tech, science, news and social issues for geeks</description>
	<lastBuildDate>Mon, 22 Mar 2010 02:14:51 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bobby</title>
		<link>http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-52105</link>
		<dc:creator>Bobby</dc:creator>
		<pubDate>Thu, 20 Mar 2008 21:44:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-52105</guid>
		<description>Rapid7 is a joke.  They have been pitching this crap software to me for months.  Their product demo was the most absurd call I have ever been apart of.  I have been blowing off their sales calls recently, but now I hope they call and try to sell me on their program!</description>
		<content:encoded><![CDATA[<p>Rapid7 is a joke.  They have been pitching this crap software to me for months.  Their product demo was the most absurd call I have ever been apart of.  I have been blowing off their sales calls recently, but now I hope they call and try to sell me on their program!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; Security vendor removes Hannaford as a client on their site after data breach is revealed! - Blogger News Network</title>
		<link>http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-52060</link>
		<dc:creator>&#187; Security vendor removes Hannaford as a client on their site after data breach is revealed! - Blogger News Network</dc:creator>
		<pubDate>Thu, 20 Mar 2008 14:21:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-52060</guid>
		<description>[...] the blog post on geeksaresexy.net: Instead, Rapid7 scrubbed all mentions of Hannaford from their client list. [...]</description>
		<content:encoded><![CDATA[<p>[...] the blog post on geeksaresexy.net: Instead, Rapid7 scrubbed all mentions of Hannaford from their client list. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PatB</title>
		<link>http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-51941</link>
		<dc:creator>PatB</dc:creator>
		<pubDate>Wed, 19 Mar 2008 20:46:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-51941</guid>
		<description>Berr, thanks for the handy link.  the article is changing with updates.  It seems that Rapid7 took it down, and then made sure it was okay with hannaford, but then someone at the company said it was no need to purge the info.  Sounds like pandemonium at rapid7.

From the updated article:  &quot;Regarding why the Hannaford materials reappeared hours ago, Matthews says: &quot;When I got involved yesterday afternoon I said, &#039;Well, there&#039;s no reason to do this; no one has actually asked us to do this. We should just put it back up the way it was.&quot;

Regarding how the breach actually happened?  You are right, the investigation is not yet complete.  I never blamed Rapid7 or its product for the failure of Hannaford&#039;s security.  The failure is ultimately Hannaford&#039;s, as they assume the risk to ensure their network is secure.  

I do blame Rapid7 for shooting themselves in the foot by screwing around with their website in light of the breach.  It makes them look very amateurish.</description>
		<content:encoded><![CDATA[<p>Berr, thanks for the handy link.  the article is changing with updates.  It seems that Rapid7 took it down, and then made sure it was okay with hannaford, but then someone at the company said it was no need to purge the info.  Sounds like pandemonium at rapid7.</p>
<p>From the updated article:  &#8220;Regarding why the Hannaford materials reappeared hours ago, Matthews says: &#8220;When I got involved yesterday afternoon I said, &#8216;Well, there&#8217;s no reason to do this; no one has actually asked us to do this. We should just put it back up the way it was.&#8221;</p>
<p>Regarding how the breach actually happened?  You are right, the investigation is not yet complete.  I never blamed Rapid7 or its product for the failure of Hannaford&#8217;s security.  The failure is ultimately Hannaford&#8217;s, as they assume the risk to ensure their network is secure.  </p>
<p>I do blame Rapid7 for shooting themselves in the foot by screwing around with their website in light of the breach.  It makes them look very amateurish.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HSO</title>
		<link>http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-51922</link>
		<dc:creator>HSO</dc:creator>
		<pubDate>Wed, 19 Mar 2008 19:29:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-51922</guid>
		<description>I think it&#039;s more likely that Hannaford&#039;s asked to be removed from the web site, which would be consistent with standard business practice after an incident... Maybe. I don&#039;t know.</description>
		<content:encoded><![CDATA[<p>I think it&#8217;s more likely that Hannaford&#8217;s asked to be removed from the web site, which would be consistent with standard business practice after an incident&#8230; Maybe. I don&#8217;t know.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Berr</title>
		<link>http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-51921</link>
		<dc:creator>Berr</dc:creator>
		<pubDate>Wed, 19 Mar 2008 19:01:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-51921</guid>
		<description>Apparently (according to the vendor, anyways) Hannaford asked the vendor to correct the information on their website:

http://www.networkworld.com/community/node/26143

So the breach happened in a retail system which was not scanned by the vendor...although if TJX taught us anything, I think we should not rush to judgement until the investigation is done (remember how the story with TJX kept changing every week for a couple months)</description>
		<content:encoded><![CDATA[<p>Apparently (according to the vendor, anyways) Hannaford asked the vendor to correct the information on their website:</p>
<p><a href="http://www.networkworld.com/community/node/26143" rel="nofollow">http://www.networkworld.com/community/node/26143</a></p>
<p>So the breach happened in a retail system which was not scanned by the vendor&#8230;although if TJX taught us anything, I think we should not rush to judgement until the investigation is done (remember how the story with TJX kept changing every week for a couple months)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PatB</title>
		<link>http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-51917</link>
		<dc:creator>PatB</dc:creator>
		<pubDate>Wed, 19 Mar 2008 18:12:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-51917</guid>
		<description>I guess they are testing their backup and restore solution.  ;-)</description>
		<content:encoded><![CDATA[<p>I guess they are testing their backup and restore solution.  ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kiltak</title>
		<link>http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-51916</link>
		<dc:creator>Kiltak</dc:creator>
		<pubDate>Wed, 19 Mar 2008 18:01:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-51916</guid>
		<description>LOL, they added it back, along with their name in the list :)</description>
		<content:encoded><![CDATA[<p>LOL, they added it back, along with their name in the list :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robb</title>
		<link>http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-51915</link>
		<dc:creator>Robb</dc:creator>
		<pubDate>Wed, 19 Mar 2008 17:37:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-51915</guid>
		<description>I see a Hannaford logo on the right-hand side of their client list.  Probably a haxor broke into their site and re-added it.....</description>
		<content:encoded><![CDATA[<p>I see a Hannaford logo on the right-hand side of their client list.  Probably a haxor broke into their site and re-added it&#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BelchSpeak &#187; Post Topic &#187; Hannaford Data Breach Tied to Rapid7</title>
		<link>http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-51902</link>
		<dc:creator>BelchSpeak &#187; Post Topic &#187; Hannaford Data Breach Tied to Rapid7</dc:creator>
		<pubDate>Wed, 19 Mar 2008 16:49:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/19/followup-hannaford-used-rapid7-for-security/#comment-51902</guid>
		<description>[...] I have provided an update to the Hannaford Hack story over at [GAS] here. [...]</description>
		<content:encoded><![CDATA[<p>[...] I have provided an update to the Hannaford Hack story over at [GAS] here. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
