Earlier today I published a lengthy blog post questioning some of the sensationalist conclusions raised in press coverage of a paper presented by Alexander Sotirov and Mark Dowd at last week’s Black Hat Conference in Las Vegas. This afternoon, I received an e-mail from Sotirov, who says he was "horrified by the lack of understanding displayed by the tech press when they covered the paper." He agreed to a follow-up interview, in which we discussed Microsoft's reaction to their research, how Windows users should respond to this news, and how they conducted field research into whether girls really are impressed by browser memory protection bypasses. ...