<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-2920277117928389647.post5773148797902897142..comments</id><updated>2007-09-10T16:01:11.576-05:00</updated><category term='password recovery systems'/><category term='PCI'/><category term='graphical passwords'/><category term='authentication'/><category term='password advice'/><category term='passwords'/><category term='password policies'/><category term='risk'/><category term='John Elwin'/><category term='FFIEC'/><category term='password guessing'/><category term='Egerstad'/><category term='password management'/><category term='incident'/><category term='password capture'/><category term='password cracking'/><category term='password sniffing'/><category term='challenge questions'/><category term='DEranged'/><category term='compliance'/><category term='email'/><category term='changing passwords'/><category term='Fox News'/><category term='passwords incident'/><category term='multi-factor authentication'/><category term='Nevada governor'/><category term='brute force attacks'/><category term='humor'/><category term='password entropy'/><title type='text'>Comments on PasswordResearch.com Authentication News: Embassy password hacker reveals his technique</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.passwordresearch.com/feeds/5773148797902897142/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2920277117928389647/5773148797902897142/comments/default'/><link rel='alternate' type='text/html' href='http://blog.passwordresearch.com/2007/09/embassy-password-hacker-reveals-his.html'/><author><name>Bruce K. Marshall</name><uri>http://www.blogger.com/profile/07397177700712500000</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2920277117928389647.post-629785779323971175</id><published>2007-09-10T16:01:00.000-05:00</published><updated>2007-09-10T16:01:00.000-05:00</updated><title type='text'>Dan's name is an anagram of "deranged" -- he goes ...</title><content type='html'>Dan's name is an anagram of "deranged" -- he goes by Dan in email he sent me.  He's a security researcher, and his point that people should use more encryption couldn't be more to the point.&lt;BR/&gt;&lt;BR/&gt;People in the security space have tried to make people aware of these issues over and over, but it always seems remote to the user.  Although in some blogs and news stories, Tor is taking the brunt of this story, I hope we can all embrace it as a teachable moment, which I feel is the spirit of your story.&lt;BR/&gt;&lt;BR/&gt;The Tor Network is set up with a security architecture that preserves anonymity to users who use end-to-end encryption and don't allow client-side tech to sidestep their privacy measures.  We are set up so that even if some of our network is in the hands of bad players, the prudent user is protected.&lt;BR/&gt;&lt;BR/&gt;However, we know all our users are not prudent.  Despite all our notices on our download page, our FAQ, our wiki, our documentation, in our technical articles, in interviews, and so on...despite this, people do not use our software as part of a comprehensive strategy and/or policy to best protect privacy and security.&lt;BR/&gt;&lt;BR/&gt;It took ages to get people in general to look for https or the lock icon on pages where they entered a credit card.  How much longer will it take, do you think, until they do the same with a password?&lt;BR/&gt;&lt;BR/&gt;Shava Nerad&lt;BR/&gt;Development Director&lt;BR/&gt;The Tor Project</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2920277117928389647/5773148797902897142/comments/default/629785779323971175'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2920277117928389647/5773148797902897142/comments/default/629785779323971175'/><link rel='alternate' type='text/html' href='http://blog.passwordresearch.com/2007/09/embassy-password-hacker-reveals-his.html?showComment=1189458060000#c629785779323971175' title=''/><author><name>Shava</name><uri>http://www.blogger.com/profile/10627239054521159514</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.passwordresearch.com/2007/09/embassy-password-hacker-reveals-his.html' ref='tag:blogger.com,1999:blog-2920277117928389647.post-5773148797902897142' source='http://www.blogger.com/feeds/2920277117928389647/posts/default/5773148797902897142' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-640138023'/></entry></feed>
