<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Passwords, Open ID, and &#8220;Information Cards&#8221;</title>
	<atom:link href="http://www.cryptosmith.com/archives/215/feed" rel="self" type="application/rss+xml" />
	<link>http://www.cryptosmith.com/archives/215</link>
	<description>Authentication, crypto, information security, and life with gadgets - Rick Smith</description>
	<lastBuildDate>Thu, 19 Nov 2009 04:27:20 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bluebee</title>
		<link>http://www.cryptosmith.com/archives/215/comment-page-1#comment-5865</link>
		<dc:creator>Bluebee</dc:creator>
		<pubDate>Wed, 13 Aug 2008 20:54:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.cryptosmith.com/?p=215#comment-5865</guid>
		<description>Thank you for mentioning rootkits!
But there is more!

Information Cards will only be secure if there are real separate cards, using embedded cryptography, in use: every security measure running directly on a PC only is vulnerable (see rootkits), and virtual Information-Cards (which are only data stored on your computer), are an invitation to pishers! They only have to upload this Information-Card Data from your Computer, and pishers get everything they like to have! 

Why? There is a not curable flaw:
Everything running directly on a PC (specially with MS-Software) can be faked or spied on. 

The only thing which helps is an external ID (Card or USB-Dongle) with embedded Microprocessor which handles all the communication with embedded cryptography and refuses to be spied on. 

Everybody involved, but specially a readership that is no expert in security and privacy has to know this! People should know the limits and drawbacks of security. Otherwise a new circle of Insecurities and Security Breaches and even loss of personal identity Data may follow.

And, bye the way:
Information Card Users give their essential personal identity data to the companies which are issuing the Information Card - that is another vulnerability. These Companies have all the personal identity data and the possibility to access all WEB-based connections. Who is supervising these Companies? Remember lost data reported in the press?</description>
		<content:encoded><![CDATA[<p>Thank you for mentioning rootkits!<br />
But there is more!</p>
<p>Information Cards will only be secure if there are real separate cards, using embedded cryptography, in use: every security measure running directly on a PC only is vulnerable (see rootkits), and virtual Information-Cards (which are only data stored on your computer), are an invitation to pishers! They only have to upload this Information-Card Data from your Computer, and pishers get everything they like to have! </p>
<p>Why? There is a not curable flaw:<br />
Everything running directly on a PC (specially with MS-Software) can be faked or spied on. </p>
<p>The only thing which helps is an external ID (Card or USB-Dongle) with embedded Microprocessor which handles all the communication with embedded cryptography and refuses to be spied on. </p>
<p>Everybody involved, but specially a readership that is no expert in security and privacy has to know this! People should know the limits and drawbacks of security. Otherwise a new circle of Insecurities and Security Breaches and even loss of personal identity Data may follow.</p>
<p>And, bye the way:<br />
Information Card Users give their essential personal identity data to the companies which are issuing the Information Card &#8211; that is another vulnerability. These Companies have all the personal identity data and the possibility to access all WEB-based connections. Who is supervising these Companies? Remember lost data reported in the press?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
