<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Another Reminder About Passwords</title>
	<atom:link href="http://pthree.org/2012/06/08/another-reminder-about-passwords/feed/" rel="self" type="application/rss+xml" />
	<link>http://pthree.org/2012/06/08/another-reminder-about-passwords/</link>
	<description>Linux.  GNU.  Freedom.</description>
	<lastBuildDate>Fri, 17 May 2013 20:46:35 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.6-beta2-24176</generator>
	<item>
		<title>By: Joe Julian</title>
		<link>http://pthree.org/2012/06/08/another-reminder-about-passwords/#comment-116819</link>
		<dc:creator>Joe Julian</dc:creator>
		<pubDate>Tue, 31 Jul 2012 06:20:20 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2392#comment-116819</guid>
		<description><![CDATA[Also think about your exposure. You touched on it briefly in your first point but it&#039;s not at all necessary to have a different password for every forum on the internet. Partition your security into several sections. If someone finds your jokeforum.com password and it also gets them into thedailykitten.com, do you care?

If they hack your fitbit.com password and it gets them into facebook, that might be a little more of a problem.

If they download passwords from your credit card company and that lets them into your bank, that&#039;s a much bigger problem.

On an unrelated node, changing your password every 30 to 90 days does nothing to increase that entropy like some companies force you to do. Quite the opposite, it generally forces people into using password schemes that decrease entropy or causes people to write down passwords in an easily comprimised place (like stuck to your monitor with a sticky note).]]></description>
		<content:encoded><![CDATA[<p>Also think about your exposure. You touched on it briefly in your first point but it&#8217;s not at all necessary to have a different password for every forum on the internet. Partition your security into several sections. If someone finds your jokeforum.com password and it also gets them into thedailykitten.com, do you care?</p>
<p>If they hack your fitbit.com password and it gets them into facebook, that might be a little more of a problem.</p>
<p>If they download passwords from your credit card company and that lets them into your bank, that&#8217;s a much bigger problem.</p>
<p>On an unrelated node, changing your password every 30 to 90 days does nothing to increase that entropy like some companies force you to do. Quite the opposite, it generally forces people into using password schemes that decrease entropy or causes people to write down passwords in an easily comprimised place (like stuck to your monitor with a sticky note).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: atmosx</title>
		<link>http://pthree.org/2012/06/08/another-reminder-about-passwords/#comment-116609</link>
		<dc:creator>atmosx</dc:creator>
		<pubDate>Fri, 15 Jun 2012 15:00:10 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2392#comment-116609</guid>
		<description><![CDATA[Hello,

Nice post. I use 1Passwd on my Macintosh machines. Since it syncs with the iPhone I have all my passwords stored in the iPhone. The problem here is that I use 2-passwords. But if you find those you can access all my data at once. (scary). I wish there was some sort of security measure like &#039;10 wrong passwords erases the db&#039;.]]></description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>Nice post. I use 1Passwd on my Macintosh machines. Since it syncs with the iPhone I have all my passwords stored in the iPhone. The problem here is that I use 2-passwords. But if you find those you can access all my data at once. (scary). I wish there was some sort of security measure like &#8217;10 wrong passwords erases the db&#8217;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron Toponce</title>
		<link>http://pthree.org/2012/06/08/another-reminder-about-passwords/#comment-116592</link>
		<dc:creator>Aaron Toponce</dc:creator>
		<pubDate>Tue, 12 Jun 2012 11:56:34 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2392#comment-116592</guid>
		<description><![CDATA[You still have the problem of remembering each password for all of your sites. Even with the XKCD approach, unless you&#039;re using &quot;correcthorsebatterystaple&quot; for every password, how do you know which password belongs to which site?]]></description>
		<content:encoded><![CDATA[<p>You still have the problem of remembering each password for all of your sites. Even with the XKCD approach, unless you&#8217;re using &#8220;correcthorsebatterystaple&#8221; for every password, how do you know which password belongs to which site?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: outa</title>
		<link>http://pthree.org/2012/06/08/another-reminder-about-passwords/#comment-116591</link>
		<dc:creator>outa</dc:creator>
		<pubDate>Mon, 11 Jun 2012 16:57:52 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2392#comment-116591</guid>
		<description><![CDATA[The problem with password managers like KeePass is that they confine your passwords to your own machine, so you can&#039;t log in from a friend&#039;s computer for example.

As for the card, I&#039;m a bit skeptical. You still need to remember color, symbol, direction, and length for each password. I would guess that is rather hard, especially because you don&#039;t have any association with these combinations (unlike with normal passwords). So far the xkcd approach seems easiest for me.]]></description>
		<content:encoded><![CDATA[<p>The problem with password managers like KeePass is that they confine your passwords to your own machine, so you can&#8217;t log in from a friend&#8217;s computer for example.</p>
<p>As for the card, I&#8217;m a bit skeptical. You still need to remember color, symbol, direction, and length for each password. I would guess that is rather hard, especially because you don&#8217;t have any association with these combinations (unlike with normal passwords). So far the xkcd approach seems easiest for me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ron</title>
		<link>http://pthree.org/2012/06/08/another-reminder-about-passwords/#comment-116589</link>
		<dc:creator>Ron</dc:creator>
		<pubDate>Fri, 08 Jun 2012 16:18:52 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2392#comment-116589</guid>
		<description><![CDATA[https://www.us-cert.gov/cas/tips/ST04-002.html covers a good deal about passwords. For myself, I use alpha-numeric characters with symbols in a rhyming scheme thaqt are at least 15 characters long - and I memorize them. Each unique to every place I visit.

$3g4t6brt#173xdd rhymes like so $ 3g 4t 6brt # 173xdd]]></description>
		<content:encoded><![CDATA[<p><a href="https://www.us-cert.gov/cas/tips/ST04-002.html" rel="nofollow">https://www.us-cert.gov/cas/tips/ST04-002.html</a> covers a good deal about passwords. For myself, I use alpha-numeric characters with symbols in a rhyming scheme thaqt are at least 15 characters long &#8211; and I memorize them. Each unique to every place I visit.</p>
<p>$3g4t6brt#173xdd rhymes like so $ 3g 4t 6brt # 173xdd</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Name</title>
		<link>http://pthree.org/2012/06/08/another-reminder-about-passwords/#comment-116588</link>
		<dc:creator>Name</dc:creator>
		<pubDate>Fri, 08 Jun 2012 15:54:00 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2392#comment-116588</guid>
		<description><![CDATA[Also obligatory: https://www.pwdhash.com/]]></description>
		<content:encoded><![CDATA[<p>Also obligatory: <a href="https://www.pwdhash.com/" rel="nofollow">https://www.pwdhash.com/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron Toponce</title>
		<link>http://pthree.org/2012/06/08/another-reminder-about-passwords/#comment-116587</link>
		<dc:creator>Aaron Toponce</dc:creator>
		<pubDate>Fri, 08 Jun 2012 14:44:59 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2392#comment-116587</guid>
		<description><![CDATA[Yes, except 44 bits of entropy won&#039;t get you far. If you&#039;re not north of 64 bits, your haystack is pretty small.]]></description>
		<content:encoded><![CDATA[<p>Yes, except 44 bits of entropy won&#8217;t get you far. If you&#8217;re not north of 64 bits, your haystack is pretty small.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Prateek</title>
		<link>http://pthree.org/2012/06/08/another-reminder-about-passwords/#comment-116586</link>
		<dc:creator>Prateek</dc:creator>
		<pubDate>Fri, 08 Jun 2012 13:25:31 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=2392#comment-116586</guid>
		<description><![CDATA[Obligatory link: http://xkcd.com/936/]]></description>
		<content:encoded><![CDATA[<p>Obligatory link: <a href="http://xkcd.com/936/" rel="nofollow">http://xkcd.com/936/</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
