<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Passwords</title>
	<atom:link href="http://www.thespanner.co.uk/2007/05/11/passwords/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/05/11/passwords/</link>
	<description>Javascript blog with messed up syntax inside</description>
	<lastBuildDate>Thu, 26 Jan 2012 01:38:34 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/05/11/passwords/#comment-154</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Mon, 14 May 2007 08:19:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/05/11/passwords/#comment-154</guid>
		<description>@ambush commander

Yes of course I could have encrypted the data but as I said in the post I did it because I couldn&#039;t sleep not to write a full comprehensive solution. The idea in my head enabled the user to remember a small pin number but provide enough security that their account couldn&#039;t easily be compromised.

The system could also prevent Phishing using browser clipboard checks; I&#039;ve released the code/concept as GPL so anyone can improve it.

Agreed I will change the plugin I wrote to warn javascript is required.</description>
		<content:encoded><![CDATA[<p>@ambush commander</p>
<p>Yes of course I could have encrypted the data but as I said in the post I did it because I couldn&#8217;t sleep not to write a full comprehensive solution. The idea in my head enabled the user to remember a small pin number but provide enough security that their account couldn&#8217;t easily be compromised.</p>
<p>The system could also prevent Phishing using browser clipboard checks; I&#8217;ve released the code/concept as GPL so anyone can improve it.</p>
<p>Agreed I will change the plugin I wrote to warn javascript is required.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ambush Commander</title>
		<link>http://www.thespanner.co.uk/2007/05/11/passwords/#comment-153</link>
		<dc:creator>Ambush Commander</dc:creator>
		<pubDate>Fri, 11 May 2007 18:38:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/05/11/passwords/#comment-153</guid>
		<description>By the way, you should probably warn your users that JavaScript is required to use the comment forms, as well as the fact that their comment won&#039;t show up immediately due to moderation.</description>
		<content:encoded><![CDATA[<p>By the way, you should probably warn your users that JavaScript is required to use the comment forms, as well as the fact that their comment won&#8217;t show up immediately due to moderation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ambush Commander</title>
		<link>http://www.thespanner.co.uk/2007/05/11/passwords/#comment-152</link>
		<dc:creator>Ambush Commander</dc:creator>
		<pubDate>Fri, 11 May 2007 18:11:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/05/11/passwords/#comment-152</guid>
		<description>If you&#039;re going to go as far as suggesting text keys and browser support, why not go the whole kaboodle and have browser implement public key authentication like SSH?</description>
		<content:encoded><![CDATA[<p>If you&#8217;re going to go as far as suggesting text keys and browser support, why not go the whole kaboodle and have browser implement public key authentication like SSH?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

