<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Security Anti-Pattern: MLS for Guards</title>
	<atom:link href="http://securityblog.org/brindle/2008/05/18/security-anti-pattern-mls-for-guards/feed/" rel="self" type="application/rss+xml" />
	<link>http://securityblog.org/brindle/2008/05/18/security-anti-pattern-mls-for-guards/</link>
	<description>The ramblings of security neophyte Joshua Brindle</description>
	<pubDate>Fri, 21 Nov 2008 11:10:03 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Mariann Mckenzie</title>
		<link>http://securityblog.org/brindle/2008/05/18/security-anti-pattern-mls-for-guards/#comment-49300</link>
		<dc:creator>Mariann Mckenzie</dc:creator>
		<pubDate>Wed, 12 Nov 2008 21:47:30 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.org/brindle/?p=24#comment-49300</guid>
		<description>ivr99vesq70xlz51</description>
		<content:encoded><![CDATA[<p>ivr99vesq70xlz51</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spencer</title>
		<link>http://securityblog.org/brindle/2008/05/18/security-anti-pattern-mls-for-guards/#comment-33395</link>
		<dc:creator>Spencer</dc:creator>
		<pubDate>Tue, 27 May 2008 13:42:52 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.org/brindle/?p=24#comment-33395</guid>
		<description>Good read.  Why don't you go over one of those situations where BLP/MLS is the better solution in a second article?  Perhaps a CMW?

Of course the scenario would be different - where BLP isn't strictly needed and TE alone is sufficient here (CDS) the reverse wouldn't be true as BLP and TE would both should be used.

Finally just want to mention releasability.  You alluded to it but that is a major differentiator between the two models.  Expressing releasability in a TE policy is mathematically possible but it isn't easy or appropriate.</description>
		<content:encoded><![CDATA[<p>Good read.  Why don&#8217;t you go over one of those situations where BLP/MLS is the better solution in a second article?  Perhaps a CMW?</p>
<p>Of course the scenario would be different - where BLP isn&#8217;t strictly needed and TE alone is sufficient here (CDS) the reverse wouldn&#8217;t be true as BLP and TE would both should be used.</p>
<p>Finally just want to mention releasability.  You alluded to it but that is a major differentiator between the two models.  Expressing releasability in a TE policy is mathematically possible but it isn&#8217;t easy or appropriate.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
