<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Sacrificing a Lot of Security for a Small Gain in Usability</title>
	<atom:link href="http://www.jamesgalvin.com/2007/08/25/sacrificing-a-lot-of-security-for-a-small-gain-in-usability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jamesgalvin.com/2007/08/25/sacrificing-a-lot-of-security-for-a-small-gain-in-usability/</link>
	<description>Even a stopped clock tells the right time twice a day.</description>
	<pubDate>Tue, 07 Oct 2008 10:05:20 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: &#8220;News Alert: Irish Broadband Routers Totally Secure&#8221; &#124; James Galvin</title>
		<link>http://www.jamesgalvin.com/2007/08/25/sacrificing-a-lot-of-security-for-a-small-gain-in-usability/#comment-30944</link>
		<dc:creator>&#8220;News Alert: Irish Broadband Routers Totally Secure&#8221; &#124; James Galvin</dc:creator>
		<pubDate>Tue, 09 Oct 2007 22:14:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.jamesgalvin.com/2007/08/25/sacrificing-a-lot-of-security-for-a-small-gain-in-usability/#comment-30944</guid>
		<description>[...] for &#8220;crack wpa&#8221;, even if the encryption method is somehow 100% unbreakable, just ask Paypal what happens when you allow the user to pick his own [...]</description>
		<content:encoded><![CDATA[<p>[...] for &#8220;crack wpa&#8221;, even if the encryption method is somehow 100% unbreakable, just ask Paypal what happens when you allow the user to pick his own [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dahamsta</title>
		<link>http://www.jamesgalvin.com/2007/08/25/sacrificing-a-lot-of-security-for-a-small-gain-in-usability/#comment-28151</link>
		<dc:creator>dahamsta</dc:creator>
		<pubDate>Sun, 26 Aug 2007 18:06:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.jamesgalvin.com/2007/08/25/sacrificing-a-lot-of-security-for-a-small-gain-in-usability/#comment-28151</guid>
		<description>Jesus don't say challenge/response James, you'll have the anti-spam C/R dickheads in here. :)</description>
		<content:encoded><![CDATA[<p>Jesus don&#8217;t say challenge/response James, you&#8217;ll have the anti-spam C/R dickheads in here. <img src='http://www.jamesgalvin.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://www.jamesgalvin.com/2007/08/25/sacrificing-a-lot-of-security-for-a-small-gain-in-usability/#comment-28148</link>
		<dc:creator>James</dc:creator>
		<pubDate>Sun, 26 Aug 2007 17:33:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.jamesgalvin.com/2007/08/25/sacrificing-a-lot-of-security-for-a-small-gain-in-usability/#comment-28148</guid>
		<description>Speaking of banks... that reminds me about their policy to check up on credit cards.  I got a TEXT MESSAGE once along the lines of

&lt;blockquote&gt;IMPORTANT!! Ring BOI Credit Card Services @ 01 xxxxxx ASAP!&lt;/blockquote&gt;

Turned out it was legit, but I certainly didn't ring the number they sent me (I rang the number on the back of my card).  That is a good point though, there should be a challenge/response allowing us to verify the bank's identity.</description>
		<content:encoded><![CDATA[<p>Speaking of banks&#8230; that reminds me about their policy to check up on credit cards.  I got a TEXT MESSAGE once along the lines of</p>
<blockquote><p>IMPORTANT!! Ring BOI Credit Card Services @ 01 xxxxxx ASAP!</p></blockquote>
<p>Turned out it was legit, but I certainly didn&#8217;t ring the number they sent me (I rang the number on the back of my card).  That is a good point though, there should be a challenge/response allowing us to verify the bank&#8217;s identity.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dahamsta</title>
		<link>http://www.jamesgalvin.com/2007/08/25/sacrificing-a-lot-of-security-for-a-small-gain-in-usability/#comment-28145</link>
		<dc:creator>dahamsta</dc:creator>
		<pubDate>Sun, 26 Aug 2007 15:04:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.jamesgalvin.com/2007/08/25/sacrificing-a-lot-of-security-for-a-small-gain-in-usability/#comment-28145</guid>
		<description>My favourite is when the bank rings me an prepares to ask a security question. I always interrupt them and say:

&lt;i&gt;"Sorry, you rang me (without caller id). I know who I am, I don't know who you are. I should be asking you security questions."&lt;/i&gt;

They usually go "huh", because they're automatons just doing what their told anyway. No imagination, no security.

On DNS, when ISPs and other orgs ask me to authenticate using a fax "for security reasons", I call them on it. It's for ass-covering, not security.

adam</description>
		<content:encoded><![CDATA[<p>My favourite is when the bank rings me an prepares to ask a security question. I always interrupt them and say:</p>
<p><i>&#8220;Sorry, you rang me (without caller id). I know who I am, I don&#8217;t know who you are. I should be asking you security questions.&#8221;</i></p>
<p>They usually go &#8220;huh&#8221;, because they&#8217;re automatons just doing what their told anyway. No imagination, no security.</p>
<p>On DNS, when ISPs and other orgs ask me to authenticate using a fax &#8220;for security reasons&#8221;, I call them on it. It&#8217;s for ass-covering, not security.</p>
<p>adam</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: University Update - North Carolina State - Sacrificing a Lot of Security for a Small Gain in Usability</title>
		<link>http://www.jamesgalvin.com/2007/08/25/sacrificing-a-lot-of-security-for-a-small-gain-in-usability/#comment-28112</link>
		<dc:creator>University Update - North Carolina State - Sacrificing a Lot of Security for a Small Gain in Usability</dc:creator>
		<pubDate>Sat, 25 Aug 2007 13:21:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.jamesgalvin.com/2007/08/25/sacrificing-a-lot-of-security-for-a-small-gain-in-usability/#comment-28112</guid>
		<description>[...] Forest University                           Sacrificing a Lot of Security for a Small Gain in Usability &#187;  This Summary is from an article posted at James Galvin on Saturday, August 25, 2007     Itâ€™s [...]</description>
		<content:encoded><![CDATA[<p>[...] Forest University                           Sacrificing a Lot of Security for a Small Gain in Usability &#187;  This Summary is from an article posted at James Galvin on Saturday, August 25, 2007     Itâ€™s [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
