<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Desjardins &#8220;Enhances&#8221; Security: Don&#8217;t Use Long Passwords</title>
	<atom:link href="http://www.favvas.com/2008/01/21/desjardins-enhances-security-dont-use-long-passwords/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.favvas.com/2008/01/21/desjardins-enhances-security-dont-use-long-passwords/</link>
	<description>fintech, social media and entrepreneurship</description>
	<lastBuildDate>Sun, 05 Feb 2012 05:15:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Callum</title>
		<link>http://www.favvas.com/2008/01/21/desjardins-enhances-security-dont-use-long-passwords/comment-page-1/#comment-4419</link>
		<dc:creator>Callum</dc:creator>
		<pubDate>Tue, 22 Jan 2008 11:28:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.favvas.com/2008/01/21/desjardins-enhances-security-dont-use-long-passwords/#comment-4419</guid>
		<description>Hahaha. Gotta love it when banks (err, credit unions) get it wrong.

The whole &quot;personalised login page&quot; is a bit of a security myth in my view. The smart attacker will simply proxy the live login page, so you&#039;ll see whatever you&#039;d normally see. Then once you&#039;ve logged in, they kill your session and take it over. It&#039;s not particularly hard to do, and it bypasses almost all forms of security.

Much better, in my opinion, is challenge / response type questions. So tell us one of 5 pieces of information we hold on you. Or please enter the 3rd, 6th and 1st characters of your password.

&lt;a href=&quot;http://www.smile.co.uk/&quot; rel=&quot;nofollow&quot;&gt;My bank&lt;/a&gt; uses both of these approaches. So short of proxying my live session, it would be nearly impossible to steal my login info. You&#039;d need to watch me log in at least 5 times, and probably more like 10.</description>
		<content:encoded><![CDATA[<p>Hahaha. Gotta love it when banks (err, credit unions) get it wrong.</p>
<p>The whole &#8220;personalised login page&#8221; is a bit of a security myth in my view. The smart attacker will simply proxy the live login page, so you&#8217;ll see whatever you&#8217;d normally see. Then once you&#8217;ve logged in, they kill your session and take it over. It&#8217;s not particularly hard to do, and it bypasses almost all forms of security.</p>
<p>Much better, in my opinion, is challenge / response type questions. So tell us one of 5 pieces of information we hold on you. Or please enter the 3rd, 6th and 1st characters of your password.</p>
<p><a href="http://www.smile.co.uk/" rel="nofollow">My bank</a> uses both of these approaches. So short of proxying my live session, it would be nearly impossible to steal my login info. You&#8217;d need to watch me log in at least 5 times, and probably more like 10.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

