<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Black Cards (a.k.a. Evil Stories)</title>
	<atom:link href="http://blog.m.artins.net/black-cards-aka-evil-stories/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.m.artins.net/black-cards-aka-evil-stories/</link>
	<description>On software &#38; technology</description>
	<lastBuildDate>Tue, 27 Jul 2010 14:49:52 -0600</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Carlos Villela</title>
		<link>http://blog.m.artins.net/black-cards-aka-evil-stories/comment-page-1/#comment-576</link>
		<dc:creator>Carlos Villela</dc:creator>
		<pubDate>Tue, 02 Dec 2008 14:58:58 +0000</pubDate>
		<guid isPermaLink="false">http://blog.m.artins.net/?p=124#comment-576</guid>
		<description>One interesting estimate to keep track of in those cards is the likelihood. We used a betting system on an app earlier this year (developers would place simple bets on which problem was more likely to occur first - in pints of beer).

My favourite so far has been &quot;in order to increase the visits to my &#039;herbal viagra&#039; site, I want to use XSS to embed links to it in the system&quot;, because it&#039;s incredibly simple to prevent in most sites and yet we rarely do it well.</description>
		<content:encoded><![CDATA[<p>One interesting estimate to keep track of in those cards is the likelihood. We used a betting system on an app earlier this year (developers would place simple bets on which problem was more likely to occur first &#8211; in pints of beer).</p>
<p>My favourite so far has been &#8220;in order to increase the visits to my &#8216;herbal viagra&#8217; site, I want to use XSS to embed links to it in the system&#8221;, because it&#8217;s incredibly simple to prevent in most sites and yet we rarely do it well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alexandre</title>
		<link>http://blog.m.artins.net/black-cards-aka-evil-stories/comment-page-1/#comment-574</link>
		<dc:creator>alexandre</dc:creator>
		<pubDate>Tue, 02 Dec 2008 14:19:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.m.artins.net/?p=124#comment-574</guid>
		<description>Thanks Mr. Coombes!
Just updated the story to the one you provided. Actually we used a story similar to the one you wrote.</description>
		<content:encoded><![CDATA[<p>Thanks Mr. Coombes!<br />
Just updated the story to the one you provided. Actually we used a story similar to the one you wrote.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave C</title>
		<link>http://blog.m.artins.net/black-cards-aka-evil-stories/comment-page-1/#comment-573</link>
		<dc:creator>Dave C</dc:creator>
		<pubDate>Tue, 02 Dec 2008 11:24:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.m.artins.net/?p=124#comment-573</guid>
		<description>IIRC the original idea behind the black story cards was to write them from the point of view of an actor for whom the &#039;value&#039; realised from the story, would result in some undesirable overall system effect. For example, 

&quot;As a disgruntled employee, I want to use SQL injection so that I can embezzle my cruel overlord employer by increasing my bonus in the database tenfold&quot;

So they represented a way of thinking about making the system do something it was not intended to do, and using its powers for evil!!!! I think the &#039;black&#039; bit came from de Bono six hat thinking.</description>
		<content:encoded><![CDATA[<p>IIRC the original idea behind the black story cards was to write them from the point of view of an actor for whom the &#8216;value&#8217; realised from the story, would result in some undesirable overall system effect. For example, </p>
<p>&#8220;As a disgruntled employee, I want to use SQL injection so that I can embezzle my cruel overlord employer by increasing my bonus in the database tenfold&#8221;</p>
<p>So they represented a way of thinking about making the system do something it was not intended to do, and using its powers for evil!!!! I think the &#8216;black&#8217; bit came from de Bono six hat thinking.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
