<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cryptosmith &#187; passwords</title>
	<atom:link href="http://www.cryptosmith.com/archives/tag/passwords/feed" rel="self" type="application/rss+xml" />
	<link>http://www.cryptosmith.com</link>
	<description>Authentication, crypto, information security, and life with gadgets - Rick Smith</description>
	<lastBuildDate>Thu, 08 Jul 2010 19:50:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>Russian spycraft ain&#8217;t what it used to be</title>
		<link>http://www.cryptosmith.com/archives/1086</link>
		<comments>http://www.cryptosmith.com/archives/1086#comments</comments>
		<pubDate>Wed, 30 Jun 2010 13:26:43 +0000</pubDate>
		<dc:creator>Rick (l) Smith</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[spying]]></category>

		<guid isPermaLink="false">http://www.cryptosmith.com/?p=1086</guid>
		<description><![CDATA[A wise note written by Johannes Ulrich of SANS Institute outlines cyber security lessons from the recent russian spy arrests. Clearly, information security tradecraft has not made its way into spy schools, at least not in Russia. A lot of their failures trace back to a stealth search warrant a few years back that netted [...]]]></description>
		<wfw:commentRss>http://www.cryptosmith.com/archives/1086/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>9-year-old hacks the school superintendent</title>
		<link>http://www.cryptosmith.com/archives/990</link>
		<comments>http://www.cryptosmith.com/archives/990#comments</comments>
		<pubDate>Sun, 18 Apr 2010 22:38:11 +0000</pubDate>
		<dc:creator>Rick (l) Smith</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech Teaching]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[policy]]></category>

		<guid isPermaLink="false">http://www.cryptosmith.com/?p=990</guid>
		<description><![CDATA[Jeremy Epstein reported this terrific report to Peter Neumann&#8217;s Risks List: a school kid logged in as superintendent of schools. This was in Fairfax County, where I grew up. They use Blackboard, just like the college where I teach. And yes, we&#8217;re talking about a nine-year-old. It turned out to be a security policy problem. [...]]]></description>
		<wfw:commentRss>http://www.cryptosmith.com/archives/990/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RockYou and Password Choices</title>
		<link>http://www.cryptosmith.com/archives/947</link>
		<comments>http://www.cryptosmith.com/archives/947#comments</comments>
		<pubDate>Fri, 22 Jan 2010 15:06:48 +0000</pubDate>
		<dc:creator>Rick (l) Admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[rockyou.com]]></category>

		<guid isPermaLink="false">http://www.cryptosmith.com/?p=947</guid>
		<description><![CDATA[A social networking site called Rockyou.Com was hacked a few months ago, and someone was thoughtful enough to tell them about it in December. After some dithering, they announced it to their user community. Unfortunately, they were trying to do site aggregation stuff &#8211; using other site login credentials to link that site to theirs. [...]]]></description>
		<wfw:commentRss>http://www.cryptosmith.com/archives/947/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another plea for password sanity</title>
		<link>http://www.cryptosmith.com/archives/729</link>
		<comments>http://www.cryptosmith.com/archives/729#comments</comments>
		<pubDate>Sat, 15 Aug 2009 17:54:28 +0000</pubDate>
		<dc:creator>Dr. Rick Smith</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[password cracking]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[strong passwords]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.cryptosmith.com/?p=729</guid>
		<description><![CDATA[Here&#8217;s a recent posting on password problems that suggests 10 hard-to-follow rules. The author highlights an important problem: attackers can do systematic trial-and-error guessing attacks against on-line sites. She focuses on a Google Gmail problem recently reported on Full Disclosure. Here&#8217;s the point: use strong protection on high-value targets. Take the time to protect your [...]]]></description>
		<wfw:commentRss>http://www.cryptosmith.com/archives/729/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Password Recovery Speeds</title>
		<link>http://www.cryptosmith.com/archives/548</link>
		<comments>http://www.cryptosmith.com/archives/548#comments</comments>
		<pubDate>Fri, 13 Mar 2009 18:49:38 +0000</pubDate>
		<dc:creator>Dr. Rick Smith</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[dumb passwords]]></category>
		<category><![CDATA[passwords]]></category>

		<guid isPermaLink="false">http://www.cryptosmith.com/?p=548</guid>
		<description><![CDATA[Ivan Lucas of &#8220;Lockdown.co.uk&#8221; has posted an interesting summary of Password Recovery Speeds. These are scaled on the assumption that the attacker will do trial-and-error attempts of all possible permutations. I think it would be interesting to include a scale that considers &#8216;likely&#8217; password selections. I&#8217;ve been reviewing postings from the past few months that [...]]]></description>
		<wfw:commentRss>http://www.cryptosmith.com/archives/548/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Password Resetting Considered Harmful &#8211; duh!</title>
		<link>http://www.cryptosmith.com/archives/274</link>
		<comments>http://www.cryptosmith.com/archives/274#comments</comments>
		<pubDate>Mon, 01 Sep 2008 19:38:54 +0000</pubDate>
		<dc:creator>Rick (l) Smith</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[password resetting]]></category>
		<category><![CDATA[passwords]]></category>

		<guid isPermaLink="false">http://www.cryptosmith.com/?p=274</guid>
		<description><![CDATA[It used to be that the default password was your mother&#8217;s maiden name, your SSN, your birthdate, or something like that. Now you have to pick a password, and your &#8216;password recovery&#8217; questions are based on those old stand-by questions. So you can still break in to a person&#8217;s accounts by answering those classic questions. [...]]]></description>
		<wfw:commentRss>http://www.cryptosmith.com/archives/274/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Passwords, Open ID, and &#8220;Information Cards&#8221;</title>
		<link>http://www.cryptosmith.com/archives/215</link>
		<comments>http://www.cryptosmith.com/archives/215#comments</comments>
		<pubDate>Tue, 12 Aug 2008 14:48:52 +0000</pubDate>
		<dc:creator>Rick (l) Smith</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[information cards]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[policy]]></category>

		<guid isPermaLink="false">http://www.cryptosmith.com/?p=215</guid>
		<description><![CDATA[Randall Stross/Digital Domain has posted a NYT story on passwords, Open ID, and Information Cards. The &#8220;Information Card Foundation&#8221; is only a few weeks old, and the technique is trying to solve problems with both passwords and with Open ID. The posting roasts the old chestnuts about how bad passwords are (does anyone really need [...]]]></description>
		<wfw:commentRss>http://www.cryptosmith.com/archives/215/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Six Minute History of Information Security</title>
		<link>http://www.cryptosmith.com/archives/84</link>
		<comments>http://www.cryptosmith.com/archives/84#comments</comments>
		<pubDate>Sun, 03 Aug 2008 21:54:07 +0000</pubDate>
		<dc:creator>Rick (l) Smith</dc:creator>
				<category><![CDATA[History of Technology]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ACM]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[crypto]]></category>
		<category><![CDATA[curriculum]]></category>
		<category><![CDATA[firewalls]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Multics]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[red teams]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.cryptosmith.com/?p=84</guid>
		<description><![CDATA[I have been reading the ACM&#8217;s Model Curriculum on Information Technology (a prototype &#8220;IT&#8221; major) with a special eye towards the information security coverage. I&#8217;ve been teaching information security courses and recently developed a major in the area. The curriculum provides minimum times to cover major topics in the field, like 3 hours to cover [...]]]></description>
		<wfw:commentRss>http://www.cryptosmith.com/archives/84/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
