<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Screens around the web: password restrictions</title>
	<atom:link href="http://floatingsun.net/2007/12/02/screens-around-the-web-password-restrictions/feed/" rel="self" type="application/rss+xml" />
	<link>http://floatingsun.net/2007/12/02/screens-around-the-web-password-restrictions/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=screens-around-the-web-password-restrictions</link>
	<description></description>
	<lastBuildDate>Sun, 20 May 2012 06:51:44 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Erik</title>
		<link>http://floatingsun.net/2007/12/02/screens-around-the-web-password-restrictions/#comment-40966</link>
		<dc:creator>Erik</dc:creator>
		<pubDate>Thu, 17 Apr 2008 07:37:23 +0000</pubDate>
		<guid isPermaLink="false">http://floatingsun.net/2007/12/02/screens-around-the-web-password-restrictions#comment-40966</guid>
		<description>I agree completely.  American Express&#039;s restrictions in particular seem to be designed for ease of brute-forcing.  There are a total of 2,684,372,063,360 possible passwords one can use with those restrictions, and I&#039;m sure a dictionary attack program could crack the majority of their customers&#039; passwords in a few minutes each.  Makes me want to cancel my account...</description>
		<content:encoded><![CDATA[<p>I agree completely.  American Express&#8217;s restrictions in particular seem to be designed for ease of brute-forcing.  There are a total of 2,684,372,063,360 possible passwords one can use with those restrictions, and I&#8217;m sure a dictionary attack program could crack the majority of their customers&#8217; passwords in a few minutes each.  Makes me want to cancel my account&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris X Edwards</title>
		<link>http://floatingsun.net/2007/12/02/screens-around-the-web-password-restrictions/#comment-30069</link>
		<dc:creator>Chris X Edwards</dc:creator>
		<pubDate>Thu, 14 Feb 2008 23:25:11 +0000</pubDate>
		<guid isPermaLink="false">http://floatingsun.net/2007/12/02/screens-around-the-web-password-restrictions#comment-30069</guid>
		<description>Reminds me of these 2WIRE routers (i.e. EESID shows up as ###2WIRE all over town) that are set with a default password of exactly 10 numeric bytes. You can do the math... or, this is fun if perhaps somewhat spurious:
http://www.hackosis.com/projects/bfcalc/bfcalc.php</description>
		<content:encoded><![CDATA[<p>Reminds me of these 2WIRE routers (i.e. EESID shows up as ###2WIRE all over town) that are set with a default password of exactly 10 numeric bytes. You can do the math&#8230; or, this is fun if perhaps somewhat spurious:<br />
<a href="http://www.hackosis.com/projects/bfcalc/bfcalc.php" rel="nofollow">http://www.hackosis.com/projects/bfcalc/bfcalc.php</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Diwaker Gupta</title>
		<link>http://floatingsun.net/2007/12/02/screens-around-the-web-password-restrictions/#comment-23192</link>
		<dc:creator>Diwaker Gupta</dc:creator>
		<pubDate>Fri, 14 Dec 2007 05:11:11 +0000</pubDate>
		<guid isPermaLink="false">http://floatingsun.net/2007/12/02/screens-around-the-web-password-restrictions#comment-23192</guid>
		<description>*@odi*: So? Their software should be smart enough to escape problematic characters. In any case, no one who is serious about security would ever use HTTP Basic authentication -- it is just what it says, BASIC. All of the web sites I mentioned go over HTTPS, and authentication is handled at the application layer.</description>
		<content:encoded><![CDATA[<p>*@odi*: So? Their software should be smart enough to escape problematic characters. In any case, no one who is serious about security would ever use HTTP Basic authentication &#8212; it is just what it says, BASIC. All of the web sites I mentioned go over HTTPS, and authentication is handled at the application layer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Diwaker Gupta</title>
		<link>http://floatingsun.net/2007/12/02/screens-around-the-web-password-restrictions/#comment-23191</link>
		<dc:creator>Diwaker Gupta</dc:creator>
		<pubDate>Fri, 14 Dec 2007 05:09:32 +0000</pubDate>
		<guid isPermaLink="false">http://floatingsun.net/2007/12/02/screens-around-the-web-password-restrictions#comment-23191</guid>
		<description>*@ian*: hmm, thats a good point. But still, I don&#039;t think it quite justifies the abysmal rules. Meanwhile, have you see myvidoop.com? Quite an interesting approach to the whole password management problem.</description>
		<content:encoded><![CDATA[<p>*@ian*: hmm, thats a good point. But still, I don&#8217;t think it quite justifies the abysmal rules. Meanwhile, have you see myvidoop.com? Quite an interesting approach to the whole password management problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian Holsman</title>
		<link>http://floatingsun.net/2007/12/02/screens-around-the-web-password-restrictions/#comment-21964</link>
		<dc:creator>Ian Holsman</dc:creator>
		<pubDate>Wed, 05 Dec 2007 23:17:16 +0000</pubDate>
		<guid isPermaLink="false">http://floatingsun.net/2007/12/02/screens-around-the-web-password-restrictions#comment-21964</guid>
		<description>I&#039;m guessing some systems have a restriction like the above so that you can use the same password on a phone with a IVR?

but yeah.. it&#039;s kinda silly</description>
		<content:encoded><![CDATA[<p>I&#8217;m guessing some systems have a restriction like the above so that you can use the same password on a phone with a IVR?</p>
<p>but yeah.. it&#8217;s kinda silly</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Odi</title>
		<link>http://floatingsun.net/2007/12/02/screens-around-the-web-password-restrictions/#comment-21703</link>
		<dc:creator>Odi</dc:creator>
		<pubDate>Mon, 03 Dec 2007 09:02:34 +0000</pubDate>
		<guid isPermaLink="false">http://floatingsun.net/2007/12/02/screens-around-the-web-password-restrictions#comment-21703</guid>
		<description>The HTTP Basic authentication scheme reserves the colon character to separate username from password. Thus a colon must not be used in the username or password. (If you know the implementation of the Basic scheme parser [indexOf(&#039;:&#039;) or lastIndexOf(&#039;:&#039;) ?], you MAY allow it in either username or password...)</description>
		<content:encoded><![CDATA[<p>The HTTP Basic authentication scheme reserves the colon character to separate username from password. Thus a colon must not be used in the username or password. (If you know the implementation of the Basic scheme parser [indexOf(':') or lastIndexOf(':') ?], you MAY allow it in either username or password&#8230;)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

