<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Xato</title><link>http://msmvps.com/blogs/xato/default.aspx</link><description /><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Pafwert: Now Open Source</title><link>http://msmvps.com/blogs/xato/archive/2013/04/17/pafwert-now-open-source.aspx</link><pubDate>Thu, 18 Apr 2013 04:04:41 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1827680</guid><dc:creator>Xato - Passwords &amp; Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1827680</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2013/04/17/pafwert-now-open-source.aspx#comments</comments><description>More than 15 years ago I started working on a unique password generator that eventually evolved into a small program I now call Pafwert. Pafwert is an unique tool to help you to select strong passwords that are easy to remember. Using strong entropy,...(&lt;a href="http://msmvps.com/blogs/xato/archive/2013/04/17/pafwert-now-open-source.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1827680" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Tools/default.aspx">Tools</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password/default.aspx">password</category><category domain="http://msmvps.com/blogs/xato/archive/tags/random/default.aspx">random</category><category domain="http://msmvps.com/blogs/xato/archive/tags/complexity/default.aspx">complexity</category><category domain="http://msmvps.com/blogs/xato/archive/tags/techniques/default.aspx">techniques</category><category domain="http://msmvps.com/blogs/xato/archive/tags/strong+passwords/default.aspx">strong passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password+manager/default.aspx">password manager</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password+generator/default.aspx">password generator</category><category domain="http://msmvps.com/blogs/xato/archive/tags/wordlists/default.aspx">wordlists</category></item><item><title>Email: The Security Industry’s Single Biggest Failure</title><link>http://msmvps.com/blogs/xato/archive/2012/11/29/email-the-security-industry-s-single-biggest-failure.aspx</link><pubDate>Thu, 29 Nov 2012 21:07:47 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1820152</guid><dc:creator>Xato - Passwords &amp; Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1820152</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/11/29/email-the-security-industry-s-single-biggest-failure.aspx#comments</comments><description>I still remember so clearly the frustration I felt back in the 90&amp;#8242;s when starting in the security industry and trying to sell my services. It was so difficult trying to emphasize just how much at risk potential clients were and then get them to...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/11/29/email-the-security-industry-s-single-biggest-failure.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1820152" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/security/default.aspx">security</category><category domain="http://msmvps.com/blogs/xato/archive/tags/hackers/default.aspx">hackers</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Cryptography/default.aspx">Cryptography</category><category domain="http://msmvps.com/blogs/xato/archive/tags/nsa/default.aspx">nsa</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Tools/default.aspx">Tools</category><category domain="http://msmvps.com/blogs/xato/archive/tags/policy/default.aspx">policy</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password/default.aspx">password</category><category domain="http://msmvps.com/blogs/xato/archive/tags/laws/default.aspx">laws</category><category domain="http://msmvps.com/blogs/xato/archive/tags/technology/default.aspx">technology</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Law/default.aspx">Law</category><category domain="http://msmvps.com/blogs/xato/archive/tags/hacker/default.aspx">hacker</category><category domain="http://msmvps.com/blogs/xato/archive/tags/legal/default.aspx">legal</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Authentication/default.aspx">Authentication</category><category domain="http://msmvps.com/blogs/xato/archive/tags/persona/default.aspx">persona</category><category domain="http://msmvps.com/blogs/xato/archive/tags/integrity/default.aspx">integrity</category><category domain="http://msmvps.com/blogs/xato/archive/tags/information/default.aspx">information</category><category domain="http://msmvps.com/blogs/xato/archive/tags/internet/default.aspx">internet</category><category domain="http://msmvps.com/blogs/xato/archive/tags/non-repudiation/default.aspx">non-repudiation</category><category domain="http://msmvps.com/blogs/xato/archive/tags/email/default.aspx">email</category><category domain="http://msmvps.com/blogs/xato/archive/tags/insecure+technology/default.aspx">insecure technology</category><category domain="http://msmvps.com/blogs/xato/archive/tags/secure/default.aspx">secure</category><category domain="http://msmvps.com/blogs/xato/archive/tags/two-factor/default.aspx">two-factor</category><category domain="http://msmvps.com/blogs/xato/archive/tags/hack/default.aspx">hack</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Email+Security/default.aspx">Email Security</category></item><item><title>Now eBay Wants in on Password Patents</title><link>http://msmvps.com/blogs/xato/archive/2012/11/13/now-ebay-wants-in-on-password-patents.aspx</link><pubDate>Tue, 13 Nov 2012 17:16:45 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1819163</guid><dc:creator>Xato - Passwords &amp; Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1819163</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/11/13/now-ebay-wants-in-on-password-patents.aspx#comments</comments><description>I wrote a couple months ago about the many attempts to patent various methods of checking passwords. Now eBay wants in on the game with United States Patent Application 20120284783. Here&amp;#8217;s their summary: A proposed password is decomposed into basic...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/11/13/now-ebay-wants-in-on-password-patents.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1819163" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password/default.aspx">password</category><category domain="http://msmvps.com/blogs/xato/archive/tags/abuse/default.aspx">abuse</category><category domain="http://msmvps.com/blogs/xato/archive/tags/application/default.aspx">application</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Law/default.aspx">Law</category><category domain="http://msmvps.com/blogs/xato/archive/tags/rules/default.aspx">rules</category><category domain="http://msmvps.com/blogs/xato/archive/tags/intellectual+property/default.aspx">intellectual property</category><category domain="http://msmvps.com/blogs/xato/archive/tags/patent+trolls/default.aspx">patent trolls</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Patents/default.aspx">Patents</category></item><item><title>About The US Government’s Absured Filing in a Megaupload-Related Case</title><link>http://msmvps.com/blogs/xato/archive/2012/11/03/about-the-us-government-s-absured-filing-in-a-megaupload-related-case.aspx</link><pubDate>Sat, 03 Nov 2012 19:55:27 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1818776</guid><dc:creator>Xato - Passwords &amp; Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1818776</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/11/03/about-the-us-government-s-absured-filing-in-a-megaupload-related-case.aspx#comments</comments><description>You&amp;#8217;d think the US Government has been embarrassed enough with their abuse of power and disregard for procedure in the Megaupload case that they would just let it all quietly die. No, as evidenced by a recent filing in the Kyle Goodwin case, they...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/11/03/about-the-us-government-s-absured-filing-in-a-megaupload-related-case.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1818776" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://msmvps.com/blogs/xato/archive/tags/laws/default.aspx">laws</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Piracy/default.aspx">Piracy</category><category domain="http://msmvps.com/blogs/xato/archive/tags/abuse/default.aspx">abuse</category><category domain="http://msmvps.com/blogs/xato/archive/tags/entertainment+industry/default.aspx">entertainment industry</category><category domain="http://msmvps.com/blogs/xato/archive/tags/users/default.aspx">users</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Law/default.aspx">Law</category><category domain="http://msmvps.com/blogs/xato/archive/tags/legal/default.aspx">legal</category><category domain="http://msmvps.com/blogs/xato/archive/tags/information/default.aspx">information</category><category domain="http://msmvps.com/blogs/xato/archive/tags/coypright/default.aspx">coypright</category><category domain="http://msmvps.com/blogs/xato/archive/tags/megauploa/default.aspx">megauploa</category><category domain="http://msmvps.com/blogs/xato/archive/tags/internet/default.aspx">internet</category></item><item><title>RSA’s Distributed Credential Protection: Yeah They Are Overselling it a Bit.</title><link>http://msmvps.com/blogs/xato/archive/2012/10/19/rsa-s-distributed-credential-protection-yeah-they-are-overselling-it-a-bit.aspx</link><pubDate>Fri, 19 Oct 2012 20:59:47 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1818228</guid><dc:creator>Xato - Passwords &amp; Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1818228</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/10/19/rsa-s-distributed-credential-protection-yeah-they-are-overselling-it-a-bit.aspx#comments</comments><description>RSA recently announced their new Distributed Credential Protection (DCP) product which they proudly tout as a &amp;#8220;revolutionary&amp;#8221; way to secure user credentials. But looking closer (especially at that $160,000 per license price tag), I&amp;#8217;m...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/10/19/rsa-s-distributed-credential-protection-yeah-they-are-overselling-it-a-bit.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1818228" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Hacking/default.aspx">Hacking</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Cryptography/default.aspx">Cryptography</category><category domain="http://msmvps.com/blogs/xato/archive/tags/integrity/default.aspx">integrity</category><category domain="http://msmvps.com/blogs/xato/archive/tags/credentials/default.aspx">credentials</category><category domain="http://msmvps.com/blogs/xato/archive/tags/RSA/default.aspx">RSA</category><category domain="http://msmvps.com/blogs/xato/archive/tags/database+security/default.aspx">database security</category><category domain="http://msmvps.com/blogs/xato/archive/tags/intrusion/default.aspx">intrusion</category></item><item><title>Is Mozilla’s Persona the Authentication System That We’ve All Been Waiting For? Probably Not.</title><link>http://msmvps.com/blogs/xato/archive/2012/10/01/is-mozilla-s-persona-the-authentication-system-that-we-ve-all-been-waiting-for-probably-not.aspx</link><pubDate>Mon, 01 Oct 2012 15:06:51 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1817664</guid><dc:creator>Xato - Passwords &amp; Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1817664</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/10/01/is-mozilla-s-persona-the-authentication-system-that-we-ve-all-been-waiting-for-probably-not.aspx#comments</comments><description>Last week, Mozilla announced the first beta release of Persona. Persona, formerly called BrowserID, is a personal authentication system that aims to eliminate passwords to log in to web sites. Of course, you still need one master password to log in to...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/10/01/is-mozilla-s-persona-the-authentication-system-that-we-ve-all-been-waiting-for-probably-not.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1817664" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Cryptography/default.aspx">Cryptography</category><category domain="http://msmvps.com/blogs/xato/archive/tags/openid/default.aspx">openid</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Authentication/default.aspx">Authentication</category><category domain="http://msmvps.com/blogs/xato/archive/tags/browserid/default.aspx">browserid</category><category domain="http://msmvps.com/blogs/xato/archive/tags/persona/default.aspx">persona</category><category domain="http://msmvps.com/blogs/xato/archive/tags/access+control/default.aspx">access control</category><category domain="http://msmvps.com/blogs/xato/archive/tags/mozilla/default.aspx">mozilla</category></item><item><title>6 New Password Rules</title><link>http://msmvps.com/blogs/xato/archive/2012/09/05/6-new-password-rules.aspx</link><pubDate>Wed, 05 Sep 2012 22:12:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1815918</guid><dc:creator>Xato - Passwords &amp; Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1815918</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/09/05/6-new-password-rules.aspx#comments</comments><description>Considering the increasing attention passwords have been getting lately, I thought it was about time we sit down and establish some new rules to define exactly what is a password. After all, so much of our personal lives, finances, and identities rely...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/09/05/6-new-password-rules.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1815918" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Hacking/default.aspx">Hacking</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/policy/default.aspx">policy</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password/default.aspx">password</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password+length/default.aspx">password length</category><category domain="http://msmvps.com/blogs/xato/archive/tags/random/default.aspx">random</category><category domain="http://msmvps.com/blogs/xato/archive/tags/rules/default.aspx">rules</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password+manager/default.aspx">password manager</category></item><item><title>My Advice: Just use a Password Manager</title><link>http://msmvps.com/blogs/xato/archive/2012/08/27/my-advice-just-use-a-password-manager.aspx</link><pubDate>Tue, 28 Aug 2012 04:14:01 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1815578</guid><dc:creator>Xato - Passwords &amp; Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1815578</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/08/27/my-advice-just-use-a-password-manager.aspx#comments</comments><description>For years I have advocated using long, memorable passwords using a variety of different memorization techniques. Humor, repetition, common suffixes, memorable phrases, and other methods are great for creating long passwords that are easy to remember....(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/08/27/my-advice-just-use-a-password-manager.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1815578" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Security+Policy/default.aspx">Security Policy</category><category domain="http://msmvps.com/blogs/xato/archive/tags/advice/default.aspx">advice</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password+managers/default.aspx">password managers</category><category domain="http://msmvps.com/blogs/xato/archive/tags/strong+passwords/default.aspx">strong passwords</category></item><item><title>Analyzing the XKCD Passphrase Comic</title><link>http://msmvps.com/blogs/xato/archive/2012/06/12/analyzing-the-xkcd-passphrase-comic.aspx</link><pubDate>Tue, 12 Jun 2012 21:52:58 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1810971</guid><dc:creator>Xato</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1810971</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/06/12/analyzing-the-xkcd-passphrase-comic.aspx#comments</comments><description>I rarely see any discussion of password strength without seeing th XKCD comic below brought up to illustrate that a long pass phrase is better than a shorter random jumble of characters. Since this is something I have been arguing for fifteen years, this...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/06/12/analyzing-the-xkcd-passphrase-comic.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1810971" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Security+Policy/default.aspx">Security Policy</category><category domain="http://msmvps.com/blogs/xato/archive/tags/cracking/default.aspx">cracking</category><category domain="http://msmvps.com/blogs/xato/archive/tags/complexity/default.aspx">complexity</category><category domain="http://msmvps.com/blogs/xato/archive/tags/techniques/default.aspx">techniques</category><category domain="http://msmvps.com/blogs/xato/archive/tags/xkcd/default.aspx">xkcd</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Brute+Force/default.aspx">Brute Force</category><category domain="http://msmvps.com/blogs/xato/archive/tags/pass+phrases/default.aspx">pass phrases</category></item><item><title>Despite the Hyperbole, Flame is Kind of Lame</title><link>http://msmvps.com/blogs/xato/archive/2012/06/08/despite-the-hyperbole-flame-is-kind-of-lame.aspx</link><pubDate>Fri, 08 Jun 2012 21:40:56 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1810787</guid><dc:creator>Xato</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1810787</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/06/08/despite-the-hyperbole-flame-is-kind-of-lame.aspx#comments</comments><description>We have all been hearing quite a bit of hyperbole concerning the sophistication of the Flame malware. It&amp;#8217;s hard to find any headline about the malware that doesn&amp;#8217;t involve the adjectives massive, sophisticated, elaborate, impressive, or scarey...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/06/08/despite-the-hyperbole-flame-is-kind-of-lame.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1810787" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Hacking/default.aspx">Hacking</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Malware/default.aspx">Malware</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password/default.aspx">password</category><category domain="http://msmvps.com/blogs/xato/archive/tags/programmer/default.aspx">programmer</category><category domain="http://msmvps.com/blogs/xato/archive/tags/control+servers/default.aspx">control servers</category><category domain="http://msmvps.com/blogs/xato/archive/tags/hacker/default.aspx">hacker</category><category domain="http://msmvps.com/blogs/xato/archive/tags/reverse+engineering/default.aspx">reverse engineering</category><category domain="http://msmvps.com/blogs/xato/archive/tags/sophistication/default.aspx">sophistication</category><category domain="http://msmvps.com/blogs/xato/archive/tags/antivirus+companies/default.aspx">antivirus companies</category></item><item><title>93% of the Top 10,000 in the LinkedIn List</title><link>http://msmvps.com/blogs/xato/archive/2012/06/07/93-of-the-top-10-000-in-the-linkedin-list.aspx</link><pubDate>Thu, 07 Jun 2012 23:27:35 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1810728</guid><dc:creator>Xato</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1810728</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/06/07/93-of-the-top-10-000-in-the-linkedin-list.aspx#comments</comments><description>I would like to welcome LinkedIn to the not-so-exclusive club of major web sites that have experienced major password leaks. Like any other major leak it is hard to visit any forum or tech blog without seeing some mention of it. And like any other leak...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/06/07/93-of-the-top-10-000-in-the-linkedin-list.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1810728" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Hacking/default.aspx">Hacking</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/security/default.aspx">security</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password/default.aspx">password</category><category domain="http://msmvps.com/blogs/xato/archive/tags/hash/default.aspx">hash</category><category domain="http://msmvps.com/blogs/xato/archive/tags/linkedin/default.aspx">linkedin</category></item><item><title>If You Drew a Line From San Francisco to New York</title><link>http://msmvps.com/blogs/xato/archive/2012/05/24/if-you-drew-a-line-from-san-francisco-to-new-york.aspx</link><pubDate>Fri, 25 May 2012 01:23:20 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1810274</guid><dc:creator>Xato</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1810274</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/05/24/if-you-drew-a-line-from-san-francisco-to-new-york.aspx#comments</comments><description>One of the difficulties of expressing just how much stronger one password is than another is that we as humans have such a hard time visualizing large numbers. Can we really, for example, truly comprehend the difference between a strong password and a...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/05/24/if-you-drew-a-line-from-san-francisco-to-new-york.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1810274" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/statistics/default.aspx">statistics</category><category domain="http://msmvps.com/blogs/xato/archive/tags/policy/default.aspx">policy</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password+length/default.aspx">password length</category><category domain="http://msmvps.com/blogs/xato/archive/tags/analogy/default.aspx">analogy</category></item><item><title>If a Strong Passwords is 2,573 Miles, How Long is Yours?</title><link>http://msmvps.com/blogs/xato/archive/2012/05/24/if-a-strong-passwords-is-2-573-miles-how-long-is-yours.aspx</link><pubDate>Fri, 25 May 2012 01:23:20 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1815807</guid><dc:creator>Xato - Passwords &amp; Security</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1815807</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/05/24/if-a-strong-passwords-is-2-573-miles-how-long-is-yours.aspx#comments</comments><description>One of the difficulties of expressing just how much stronger one password is than another is that we as humans have such a hard time visualizing large numbers. Can we really, for example, truly comprehend the difference between a strong password and a...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/05/24/if-a-strong-passwords-is-2-573-miles-how-long-is-yours.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1815807" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/statistics/default.aspx">statistics</category><category domain="http://msmvps.com/blogs/xato/archive/tags/policy/default.aspx">policy</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password+length/default.aspx">password length</category><category domain="http://msmvps.com/blogs/xato/archive/tags/analogy/default.aspx">analogy</category></item><item><title>Updated Thoughts on CISPA</title><link>http://msmvps.com/blogs/xato/archive/2012/04/27/updated-thoughts-on-cispa.aspx</link><pubDate>Fri, 27 Apr 2012 21:55:24 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1809268</guid><dc:creator>Xato</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1809268</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/04/27/updated-thoughts-on-cispa.aspx#comments</comments><description>Since I wrote my last post on CISPA a few weeks ago, a number of things have changed and my own opinion has evolved some as well. I still feel that the EFF&amp;#8217;s interpretation was perpetuation a great amount of FUD, but that doesn&amp;#8217;t really justify...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/04/27/updated-thoughts-on-cispa.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1809268" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/fbi/default.aspx">fbi</category><category domain="http://msmvps.com/blogs/xato/archive/tags/nsa/default.aspx">nsa</category><category domain="http://msmvps.com/blogs/xato/archive/tags/sopa/default.aspx">sopa</category><category domain="http://msmvps.com/blogs/xato/archive/tags/cispa/default.aspx">cispa</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Law/default.aspx">Law</category><category domain="http://msmvps.com/blogs/xato/archive/tags/cybersecurity/default.aspx">cybersecurity</category></item><item><title>My Favorite Passwords of the Month</title><link>http://msmvps.com/blogs/xato/archive/2012/04/26/my-favorite-passwords-of-the-month.aspx</link><pubDate>Thu, 26 Apr 2012 08:55:26 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1809218</guid><dc:creator>Xato</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1809218</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/04/26/my-favorite-passwords-of-the-month.aspx#comments</comments><description>Okay so I deal with passwords quite a bit and people tend to eagerly share their passwords with me way more than they should. And although most passwords I come across are pretty weak, I do sometimes come across some true greats, either for their strength...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/04/26/my-favorite-passwords-of-the-month.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1809218" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/tips/default.aspx">tips</category><category domain="http://msmvps.com/blogs/xato/archive/tags/techniques/default.aspx">techniques</category></item><item><title>Did the EFF Get it Wrong on CISPA?</title><link>http://msmvps.com/blogs/xato/archive/2012/04/08/did-the-eff-get-it-wrong-on-cispa.aspx</link><pubDate>Sun, 08 Apr 2012 09:19:08 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1808620</guid><dc:creator>Xato</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1808620</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/04/08/did-the-eff-get-it-wrong-on-cispa.aspx#comments</comments><description>My first reaction in seeing the recent headlines about CISPA (HR 3523), like many others, was simply being outraged at yet another attempt by the US government to open the doors for spying and censorship. In fact, we have seen so much of this lately and...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/04/08/did-the-eff-get-it-wrong-on-cispa.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1808620" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://msmvps.com/blogs/xato/archive/tags/sopa/default.aspx">sopa</category><category domain="http://msmvps.com/blogs/xato/archive/tags/cispa/default.aspx">cispa</category><category domain="http://msmvps.com/blogs/xato/archive/tags/eff/default.aspx">eff</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Law/default.aspx">Law</category><category domain="http://msmvps.com/blogs/xato/archive/tags/congress/default.aspx">congress</category><category domain="http://msmvps.com/blogs/xato/archive/tags/cybersecurity/default.aspx">cybersecurity</category></item><item><title>Yes, Use Bcrypt. And Scrypt.</title><link>http://msmvps.com/blogs/xato/archive/2012/03/19/yes-use-bcrypt-and-scrypt.aspx</link><pubDate>Mon, 19 Mar 2012 18:06:34 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1807842</guid><dc:creator>Xato</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1807842</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/03/19/yes-use-bcrypt-and-scrypt.aspx#comments</comments><description>I often come across articles that argue the strengths or weaknesses of one crypto algorithm or another. As these articles point out, cryptography is complicated and there are many factors that can affect any particular algorithm. The greatest threat for...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/03/19/yes-use-bcrypt-and-scrypt.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1807842" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Cryptography/default.aspx">Cryptography</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password/default.aspx">password</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Secure+Coding/default.aspx">Secure Coding</category><category domain="http://msmvps.com/blogs/xato/archive/tags/hash/default.aspx">hash</category><category domain="http://msmvps.com/blogs/xato/archive/tags/bcrypt/default.aspx">bcrypt</category><category domain="http://msmvps.com/blogs/xato/archive/tags/cryptanalysis/default.aspx">cryptanalysis</category><category domain="http://msmvps.com/blogs/xato/archive/tags/hashes/default.aspx">hashes</category><category domain="http://msmvps.com/blogs/xato/archive/tags/algorithms/default.aspx">algorithms</category></item><item><title>The RIAA &amp; MPAA Don’t Want you to Know They Suck</title><link>http://msmvps.com/blogs/xato/archive/2012/03/07/the-riaa-amp-mpaa-don-t-want-you-to-know-they-suck.aspx</link><pubDate>Wed, 07 Mar 2012 22:11:15 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1807843</guid><dc:creator>Xato</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1807843</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/03/07/the-riaa-amp-mpaa-don-t-want-you-to-know-they-suck.aspx#comments</comments><description>We know that a while back the entertainment industry apparently pressured Google into removing terms that are closely associated with piracy from appearing in Autocomplete. Of course, this strategy is completely absurd and it is hard to imagine that industry...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/03/07/the-riaa-amp-mpaa-don-t-want-you-to-know-they-suck.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1807843" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/RIAA/default.aspx">RIAA</category><category domain="http://msmvps.com/blogs/xato/archive/tags/laws/default.aspx">laws</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Piracy/default.aspx">Piracy</category><category domain="http://msmvps.com/blogs/xato/archive/tags/MPAA/default.aspx">MPAA</category><category domain="http://msmvps.com/blogs/xato/archive/tags/abuse/default.aspx">abuse</category><category domain="http://msmvps.com/blogs/xato/archive/tags/dmca/default.aspx">dmca</category><category domain="http://msmvps.com/blogs/xato/archive/tags/sopa/default.aspx">sopa</category><category domain="http://msmvps.com/blogs/xato/archive/tags/entertainment+industry/default.aspx">entertainment industry</category></item><item><title>Amazing Visualization of Password Numbers</title><link>http://msmvps.com/blogs/xato/archive/2012/02/29/amazing-visualization-of-password-numbers.aspx</link><pubDate>Wed, 29 Feb 2012 07:48:43 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1807844</guid><dc:creator>Xato</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1807844</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/02/29/amazing-visualization-of-password-numbers.aspx#comments</comments><description>One thing humans have an incredibly difficult time visualizing is huge numbers. For example, most of have a horrible time conceptualizing number like a trillion. When dealing with passwords, one way we have of measuring a password&amp;#8217;s strength is...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/02/29/amazing-visualization-of-password-numbers.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1807844" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/statistics/default.aspx">statistics</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Password+cracking/default.aspx">Password cracking</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password+length/default.aspx">password length</category><category domain="http://msmvps.com/blogs/xato/archive/tags/cracking/default.aspx">cracking</category><category domain="http://msmvps.com/blogs/xato/archive/tags/password+cracker/default.aspx">password cracker</category><category domain="http://msmvps.com/blogs/xato/archive/tags/gpu/default.aspx">gpu</category><category domain="http://msmvps.com/blogs/xato/archive/tags/Password+strength/default.aspx">Password strength</category><category domain="http://msmvps.com/blogs/xato/archive/tags/quadrillion/default.aspx">quadrillion</category><category domain="http://msmvps.com/blogs/xato/archive/tags/visualization/default.aspx">visualization</category></item><item><title>A Million Random Digits</title><link>http://msmvps.com/blogs/xato/archive/2012/02/23/a-million-random-digits.aspx</link><pubDate>Thu, 23 Feb 2012 06:04:48 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1807845</guid><dc:creator>Xato</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/xato/rsscomments.aspx?PostID=1807845</wfw:commentRss><comments>http://msmvps.com/blogs/xato/archive/2012/02/23/a-million-random-digits.aspx#comments</comments><description>There is much to be said about randomness and many recommend using truly random password generators. However, sometimes you just don&amp;#8217;t have internet access to visit a random password generator web site. The solution? this book contains six hundred...(&lt;a href="http://msmvps.com/blogs/xato/archive/2012/02/23/a-million-random-digits.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1807845" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/xato/archive/tags/Passwords/default.aspx">Passwords</category><category domain="http://msmvps.com/blogs/xato/archive/tags/security/default.aspx">security</category><category domain="http://msmvps.com/blogs/xato/archive/tags/numbers/default.aspx">numbers</category><category domain="http://msmvps.com/blogs/xato/archive/tags/random/default.aspx">random</category><category domain="http://msmvps.com/blogs/xato/archive/tags/randomness/default.aspx">randomness</category></item></channel></rss>