<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
	<title>Josh More's Blog's Comments</title>
	
	<link>http://blog.starmind.org</link>
	<description>Comments on business, security, and IT. Feed of readers' content on &lt;a href="http://blog.starmind.org:&gt;Josh More's Blog&lt;/a&gt;</description>
	<lastBuildDate>Thu, 04 Feb 2010 04:02:37 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/starmind-blogcomments" /><feedburner:info uri="starmind-blogcomments" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><image><link>http://www.starmind.org/</link><url>http://www.starmind.org/star-icon.png</url><title>Josh More - The Starmind</title></image><feedburner:emailServiceId>starmind-blogcomments</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>Comment on Security Sprint – Firefox Profiles by Josh</title>
		<link>http://feedproxy.google.com/~r/starmind-blogcomments/~3/Lx4Fa1qgeHg/</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Thu, 04 Feb 2010 04:02:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.starmind.org/?p=624#comment-856</guid>
		<description>Hmm, LastPass &lt;a href="http://devilsadvocatesecurity.blogspot.com/2009/04/lastpass-answering-security-questions.html"&gt;does look promising&lt;/a&gt;.  I agree with what you say about 1Password.  It is a very good solution, but only in the OSX/iPhone space.  I just haven't researched anything else in any details, as the solution I have right now is working.

I expect that I'll be looking a lot come this time next year when it's time to pick out a shiny new phone.  :)</description>
		<content:encoded><![CDATA[<p>Hmm, LastPass <a href="http://devilsadvocatesecurity.blogspot.com/2009/04/lastpass-answering-security-questions.html">does look promising</a>.  I agree with what you say about 1Password.  It is a very good solution, but only in the OSX/iPhone space.  I just haven&#8217;t researched anything else in any details, as the solution I have right now is working.</p>
<p>I expect that I&#8217;ll be looking a lot come this time next year when it&#8217;s time to pick out a shiny new phone.  :)</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blogcomments?a=Lx4Fa1qgeHg:TsDQNNYULls:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blogcomments?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
	<feedburner:origLink>http://blog.starmind.org/2010/02/03/security-sprint-%e2%80%93-firefox-profiles/comment-page-1/#comment-856</feedburner:origLink></item>
	<item>
		<title>Comment on Security Sprint – Firefox Profiles by Kenneth Younger</title>
		<link>http://feedproxy.google.com/~r/starmind-blogcomments/~3/llWSBQC58k4/</link>
		<dc:creator>Kenneth Younger</dc:creator>
		<pubDate>Thu, 04 Feb 2010 00:28:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.starmind.org/?p=624#comment-854</guid>
		<description>I was just doing a little searching and ran across http://lastpass.com - very wide compatibility, including linux. This Ubuntu forum question and response by a team member of LastPass was encouraging as well: http://ubuntuforums.org/showthread.php?p=5896494

I was considering 1Password as well, but they have completely ignored an Android version for a long time, continually saying they'll get to it eventually - plus, they don't support any OS other than OSX.</description>
		<content:encoded><![CDATA[<p>I was just doing a little searching and ran across <a href="http://lastpass.com" rel="nofollow">http://lastpass.com</a> &#8211; very wide compatibility, including linux. This Ubuntu forum question and response by a team member of LastPass was encouraging as well: <a href="http://ubuntuforums.org/showthread.php?p=5896494" >http://ubuntuforums.org/showthread.php?p=5896494</a></p>
<p>I was considering 1Password as well, but they have completely ignored an Android version for a long time, continually saying they&#8217;ll get to it eventually &#8211; plus, they don&#8217;t support any OS other than OSX.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blogcomments?a=llWSBQC58k4:-H-kKUEj1zU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blogcomments?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
	<feedburner:origLink>http://blog.starmind.org/2010/02/03/security-sprint-%e2%80%93-firefox-profiles/comment-page-1/#comment-854</feedburner:origLink></item>
	<item>
		<title>Comment on Security Sprint – Firefox Profiles by Josh</title>
		<link>http://feedproxy.google.com/~r/starmind-blogcomments/~3/63y56wg2PcI/</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Wed, 03 Feb 2010 22:44:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.starmind.org/?p=624#comment-853</guid>
		<description>Personally, I prefer the password wallet systems.  I generate a secure password for each site and store it in a wallet.  Wallets should use secure encryption (like AES or Twofish).

Generally speaking, I distrust the "store it in the browser" option.  I know that it's more convenient and that modern browsers use decent encryption on their password stores... but in order to function, they must be able to read the store.  This means that it is theoretically possible for a flaw in the browser to expose the store to an attacker via web page.

That's not to say that my solution is perfect.  In particular, it is vulnerable to password sniffing by keylogger and accidental account lockouts due to mis-entered passwords.  However, when I compare those risks to those of native browser storage, the native browser solution seems riskier.  (This is just a feeling... I've not researched it... yet ;)

Basically, my philosophy is similar to the Unix philosophy.  Most systems do one thing well.   Browsers, be they IE, Firefox, Opera or Chrome are really good at browsing.  They're getting better at security, but it's still not their core focus.  There is a lot of security in simplicity, so a simple password wallet with good market history (and that is being actively maintained) is probably better then security in a browser.

I use &lt;a href="http://gnukeyring.sourceforge.net/"&gt;Gnu Keyring&lt;/a&gt; on my Palm and am considering &lt;a href="http://agilewebsolutions.com/products/1Password"&gt;1Password&lt;/a&gt; should I move to the iPhone.  I don't know what's available in the Blackberry and Android spaces, but I'm sure that they exist there too.</description>
		<content:encoded><![CDATA[<p>Personally, I prefer the password wallet systems.  I generate a secure password for each site and store it in a wallet.  Wallets should use secure encryption (like AES or Twofish).</p>
<p>Generally speaking, I distrust the &#8220;store it in the browser&#8221; option.  I know that it&#8217;s more convenient and that modern browsers use decent encryption on their password stores&#8230; but in order to function, they must be able to read the store.  This means that it is theoretically possible for a flaw in the browser to expose the store to an attacker via web page.</p>
<p>That&#8217;s not to say that my solution is perfect.  In particular, it is vulnerable to password sniffing by keylogger and accidental account lockouts due to mis-entered passwords.  However, when I compare those risks to those of native browser storage, the native browser solution seems riskier.  (This is just a feeling&#8230; I&#8217;ve not researched it&#8230; yet ;)</p>
<p>Basically, my philosophy is similar to the Unix philosophy.  Most systems do one thing well.   Browsers, be they IE, Firefox, Opera or Chrome are really good at browsing.  They&#8217;re getting better at security, but it&#8217;s still not their core focus.  There is a lot of security in simplicity, so a simple password wallet with good market history (and that is being actively maintained) is probably better then security in a browser.</p>
<p>I use <a href="http://gnukeyring.sourceforge.net/">Gnu Keyring</a> on my Palm and am considering <a href="http://agilewebsolutions.com/products/1Password">1Password</a> should I move to the iPhone.  I don&#8217;t know what&#8217;s available in the Blackberry and Android spaces, but I&#8217;m sure that they exist there too.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blogcomments?a=63y56wg2PcI:gxTVwxV78bM:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blogcomments?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
	<feedburner:origLink>http://blog.starmind.org/2010/02/03/security-sprint-%e2%80%93-firefox-profiles/comment-page-1/#comment-853</feedburner:origLink></item>
	<item>
		<title>Comment on Security Sprint – Firefox Profiles by Kenneth Younger</title>
		<link>http://feedproxy.google.com/~r/starmind-blogcomments/~3/1raUB0l_VTg/</link>
		<dc:creator>Kenneth Younger</dc:creator>
		<pubDate>Wed, 03 Feb 2010 16:07:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.starmind.org/?p=624#comment-848</guid>
		<description>Thanks for pointing me to the SQL Inject Me and XSS Me plugins, those will definitely help test the web apps.

I was curious, and was hoping you could elaborate as to how you manage your passwords securely.</description>
		<content:encoded><![CDATA[<p>Thanks for pointing me to the SQL Inject Me and XSS Me plugins, those will definitely help test the web apps.</p>
<p>I was curious, and was hoping you could elaborate as to how you manage your passwords securely.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blogcomments?a=1raUB0l_VTg:EiNq3ASN-6U:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blogcomments?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
	<feedburner:origLink>http://blog.starmind.org/2010/02/03/security-sprint-%e2%80%93-firefox-profiles/comment-page-1/#comment-848</feedburner:origLink></item>
	<item>
		<title>Comment on Mythic Monday – Immortality by Josh More – Starmind Blog » Security lessons from Nature – Immortal Jellyfish</title>
		<link>http://feedproxy.google.com/~r/starmind-blogcomments/~3/BLpK62NuKQg/</link>
		<dc:creator>Josh More – Starmind Blog » Security lessons from Nature – Immortal Jellyfish</dc:creator>
		<pubDate>Sun, 24 Jan 2010 02:52:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.starmind.org/?p=109#comment-782</guid>
		<description>[...] let's take a look at the other side of immortality (the down-side of which was explored here).  In particular, let's look at [...]</description>
		<content:encoded><![CDATA[<p>[...] let&#39;s take a look at the other side of immortality (the down-side of which was explored here).  In particular, let&#39;s look at [...]</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blogcomments?a=BLpK62NuKQg:83WSzNHmTCI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blogcomments?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
	<feedburner:origLink>http://blog.starmind.org/2009/02/09/mythic-monday-immortality/comment-page-1/#comment-782</feedburner:origLink></item>
	<item>
		<title>Comment on Mythic Natural History – Encapsulation by Josh More – Starmind Blog » Small Business Attack – Web Disclosure</title>
		<link>http://feedproxy.google.com/~r/starmind-blogcomments/~3/zd9u1xy6pPk/</link>
		<dc:creator>Josh More – Starmind Blog » Small Business Attack – Web Disclosure</dc:creator>
		<pubDate>Sun, 24 Jan 2010 02:37:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.starmind.org/?p=541#comment-781</guid>
		<description>[...] of the flaws on a legacy server at the Iowa State University Cyber Defense Competition resulted in granting me the ability to scan the entire web directory. Normally, you'd think "What's [...]</description>
		<content:encoded><![CDATA[<p>[...] of the flaws on a legacy server at the Iowa State University Cyber Defense Competition resulted in granting me the ability to scan the entire web directory. Normally, you&#39;d think &quot;What&#39;s [...]</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blogcomments?a=zd9u1xy6pPk:-t_oIULsj9g:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blogcomments?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
	<feedburner:origLink>http://blog.starmind.org/2009/10/16/mythic-natural-history-encapsulation/comment-page-1/#comment-781</feedburner:origLink></item>
	<item>
		<title>Comment on Site Review – Scribd by A4D</title>
		<link>http://feedproxy.google.com/~r/starmind-blogcomments/~3/Uku60Ove6MU/</link>
		<dc:creator>A4D</dc:creator>
		<pubDate>Tue, 01 Dec 2009 16:26:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.starmind.org/?p=140#comment-632</guid>
		<description>Interesting review as you cover it in a technical and thorough manner

I was just looking at the site from a Social Media point of view and placed Scribd site review in Google and your site came up

Thanks for the review

not sure I would use it now

A4D</description>
		<content:encoded><![CDATA[<p>Interesting review as you cover it in a technical and thorough manner</p>
<p>I was just looking at the site from a Social Media point of view and placed Scribd site review in Google and your site came up</p>
<p>Thanks for the review</p>
<p>not sure I would use it now</p>
<p>A4D</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blogcomments?a=Uku60Ove6MU:Ta069ynHnTo:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blogcomments?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
	<feedburner:origLink>http://blog.starmind.org/2009/02/13/site-review-scribd/comment-page-1/#comment-632</feedburner:origLink></item>
	<item>
		<title>Comment on Mythic Monday – Medusa and Immutability by Josh</title>
		<link>http://feedproxy.google.com/~r/starmind-blogcomments/~3/pDsQtH3Ipd8/</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Sat, 14 Nov 2009 06:13:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.starmind.org/?p=280#comment-610</guid>
		<description>&lt;a href="#comment-606"&gt;@moso bamboo lover &lt;/a&gt; 

You should just be able to add http://feeds.feedburner.com/starmind-blog .  This can either be directly, or you can click on the orange RSS icon in the address bar in Firefox.  If you hover over the orange RSS logo at the top right of the page, it should display some common newsreaders.  If none of those are what you use, just clicking on the orange RSS icon itself should work just fine.</description>
		<content:encoded><![CDATA[<p><a href="#comment-606">@moso bamboo lover </a> </p>
<p>You should just be able to add <a href="http://feeds.feedburner.com/starmind-blog" >http://feeds.feedburner.com/starmind-blog</a> .  This can either be directly, or you can click on the orange RSS icon in the address bar in Firefox.  If you hover over the orange RSS logo at the top right of the page, it should display some common newsreaders.  If none of those are what you use, just clicking on the orange RSS icon itself should work just fine.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blogcomments?a=pDsQtH3Ipd8:6bPTD4rLhHI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blogcomments?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
	<feedburner:origLink>http://blog.starmind.org/2009/03/23/mythic-monday-medusa-and-immutability/comment-page-1/#comment-610</feedburner:origLink></item>
	<item>
		<title>Comment on Mythic Monday – Medusa and Immutability by moso bamboo lover</title>
		<link>http://feedproxy.google.com/~r/starmind-blogcomments/~3/yNsUYdQGoAM/</link>
		<dc:creator>moso bamboo lover</dc:creator>
		<pubDate>Thu, 12 Nov 2009 22:23:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.starmind.org/?p=280#comment-606</guid>
		<description></description>
		<content:encoded><![CDATA[<p>Hi, I can�t understand how to add your site in my rss reader, help please :)</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blogcomments?a=yNsUYdQGoAM:-VHjvtB2w8Q:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blogcomments?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
	<feedburner:origLink>http://blog.starmind.org/2009/03/23/mythic-monday-medusa-and-immutability/comment-page-1/#comment-606</feedburner:origLink></item>
	<item>
		<title>Comment on Mythic Monday – Aesop: The Dog, The Rooster and the Fox by Martin DeMello</title>
		<link>http://feedproxy.google.com/~r/starmind-blogcomments/~3/-rwBUa2o04I/</link>
		<dc:creator>Martin DeMello</dc:creator>
		<pubDate>Tue, 27 Oct 2009 13:51:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.starmind.org/?p=552#comment-583</guid>
		<description>'spear phishing' is a great term :) hadn't encountered it before.</description>
		<content:encoded><![CDATA[<p>&#8217;spear phishing&#8217; is a great term :) hadn&#8217;t encountered it before.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/starmind-blogcomments?a=-rwBUa2o04I:5rhliuObP-M:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/starmind-blogcomments?d=yIl2AUoC8zA" border="0"></img></a>
</div>]]></content:encoded>
	<feedburner:origLink>http://blog.starmind.org/2009/10/26/mythic-monday-aesop-the-dog-the-rooster-and-the-fox/comment-page-1/#comment-583</feedburner:origLink></item>
</channel>
</rss>
