<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Plaintext Password Reminders</title>
	<atom:link href="http://www.lightbluetouchpaper.org/2012/09/20/plaintext-password-reminders/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lightbluetouchpaper.org/2012/09/20/plaintext-password-reminders/</link>
	<description>Security Research, Computer Laboratory, University of Cambridge</description>
	<lastBuildDate>Sun, 19 May 2013 19:34:11 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Detroit Mobile Locksmith</title>
		<link>http://www.lightbluetouchpaper.org/2012/09/20/plaintext-password-reminders/comment-page-1/#comment-432869</link>
		<dc:creator>Detroit Mobile Locksmith</dc:creator>
		<pubDate>Sun, 06 Jan 2013 05:32:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=4519#comment-432869</guid>
		<description>Just wish to say your article is as astonishing.
The clearness in your post is just excellent and i could assume 
you are an expert on this subject. Fine with your permission allow me to grab your 
feed to keep updated with forthcoming post. Thanks a million and please continue the enjoyable work.</description>
		<content:encoded><![CDATA[<p>Just wish to say your article is as astonishing.<br />
The clearness in your post is just excellent and i could assume<br />
you are an expert on this subject. Fine with your permission allow me to grab your<br />
feed to keep updated with forthcoming post. Thanks a million and please continue the enjoyable work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alvin Chang</title>
		<link>http://www.lightbluetouchpaper.org/2012/09/20/plaintext-password-reminders/comment-page-1/#comment-395809</link>
		<dc:creator>Alvin Chang</dc:creator>
		<pubDate>Wed, 05 Dec 2012 18:53:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=4519#comment-395809</guid>
		<description>Isn&#039;t it true that all majordomo mailing lists store your password and remind you in cleartext once a month?</description>
		<content:encoded><![CDATA[<p>Isn&#8217;t it true that all majordomo mailing lists store your password and remind you in cleartext once a month?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Cvrcek</title>
		<link>http://www.lightbluetouchpaper.org/2012/09/20/plaintext-password-reminders/comment-page-1/#comment-342107</link>
		<dc:creator>Dan Cvrcek</dc:creator>
		<pubDate>Thu, 27 Sep 2012 12:09:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=4519#comment-342107</guid>
		<description>There are some differences between electronic access and posting printed and signed forms. I think they can be grouped around two aspects:
a. existence of physical evidence that can be used in possible disputes; and
b. use of electronic access to automate unauthorised access to the system.

Particular issues would include:
1. sending printed documents is fairly difficult to automate;
2. if there is a dispute, signatures can be verified; and 
3. it is not possible to anonymously obtain private information from Companies House using Royal Mail but easy with a stolen password.</description>
		<content:encoded><![CDATA[<p>There are some differences between electronic access and posting printed and signed forms. I think they can be grouped around two aspects:<br />
a. existence of physical evidence that can be used in possible disputes; and<br />
b. use of electronic access to automate unauthorised access to the system.</p>
<p>Particular issues would include:<br />
1. sending printed documents is fairly difficult to automate;<br />
2. if there is a dispute, signatures can be verified; and<br />
3. it is not possible to anonymously obtain private information from Companies House using Royal Mail but easy with a stolen password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian</title>
		<link>http://www.lightbluetouchpaper.org/2012/09/20/plaintext-password-reminders/comment-page-1/#comment-342099</link>
		<dc:creator>Ian</dc:creator>
		<pubDate>Thu, 27 Sep 2012 11:56:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=4519#comment-342099</guid>
		<description>Given that everything that can be done on the company house website could be done by sending in paper forms with no real checks made, I don’t think the risk has increased.   However I wish they would use the government gateway, so I did not have to have yet another password.

I can’t recall if they prompted me to change the password at any point of the registration process.   It is a real pain of a website to remember the passwords for, as I have to log in once a year.</description>
		<content:encoded><![CDATA[<p>Given that everything that can be done on the company house website could be done by sending in paper forms with no real checks made, I don’t think the risk has increased.   However I wish they would use the government gateway, so I did not have to have yet another password.</p>
<p>I can’t recall if they prompted me to change the password at any point of the registration process.   It is a real pain of a website to remember the passwords for, as I have to log in once a year.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ethical</title>
		<link>http://www.lightbluetouchpaper.org/2012/09/20/plaintext-password-reminders/comment-page-1/#comment-341126</link>
		<dc:creator>Ethical</dc:creator>
		<pubDate>Tue, 25 Sep 2012 07:58:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=4519#comment-341126</guid>
		<description>Typical mentality I&#039;m afraid. I&#039;m sounding off.

ISO 27001, PCI, CESG etc Certified, is tick box exercise in some companies, masking the underlying frailties in management thinking and communication. There is a lot of snobbery in some circles around technical knowledge, and involving the right (or correct) abilities in projects to ensure plain-text or simple problems like this never get on-line. Or risks are accepted and &quot;that will never happen to us&quot; etc excuses. I know none of the facts of course, pure speculation, but it smells of the typical arrogance and ignorance of said mentality.

For example, a simple traceroute from the executives/civil servant/service provider key partner laptop, would open their eyes (with appropriate explanation) to where information in the clear travels, anyone of the IP address is storing, forwarding information (and whatever else is in between), or our plain text password in this case.

For the amount of &quot;enhanced&quot; security to prevent identity theft on the Companies House Website, this is ironic. Having said that these types of issues are sure to increase with the cut-back mentality that prevails....

I waffle one. Disgruntled, but honest.</description>
		<content:encoded><![CDATA[<p>Typical mentality I&#8217;m afraid. I&#8217;m sounding off.</p>
<p>ISO 27001, PCI, CESG etc Certified, is tick box exercise in some companies, masking the underlying frailties in management thinking and communication. There is a lot of snobbery in some circles around technical knowledge, and involving the right (or correct) abilities in projects to ensure plain-text or simple problems like this never get on-line. Or risks are accepted and &#8220;that will never happen to us&#8221; etc excuses. I know none of the facts of course, pure speculation, but it smells of the typical arrogance and ignorance of said mentality.</p>
<p>For example, a simple traceroute from the executives/civil servant/service provider key partner laptop, would open their eyes (with appropriate explanation) to where information in the clear travels, anyone of the IP address is storing, forwarding information (and whatever else is in between), or our plain text password in this case.</p>
<p>For the amount of &#8220;enhanced&#8221; security to prevent identity theft on the Companies House Website, this is ironic. Having said that these types of issues are sure to increase with the cut-back mentality that prevails&#8230;.</p>
<p>I waffle one. Disgruntled, but honest.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: P</title>
		<link>http://www.lightbluetouchpaper.org/2012/09/20/plaintext-password-reminders/comment-page-1/#comment-339502</link>
		<dc:creator>P</dc:creator>
		<pubDate>Fri, 21 Sep 2012 09:15:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=4519#comment-339502</guid>
		<description>See also Denis Health Insurance: they will mail you your password if you say you forgot it and they display it in the &quot;my details&quot; page while you are logged in.  

https://secureuk.denisglobal.com/Template.php?uvKey=Forget&amp;uvMode=&amp;uvCall=NOMENU</description>
		<content:encoded><![CDATA[<p>See also Denis Health Insurance: they will mail you your password if you say you forgot it and they display it in the &#8220;my details&#8221; page while you are logged in.  </p>
<p><a href="https://secureuk.denisglobal.com/Template.php?uvKey=Forget&amp;uvMode=&amp;uvCall=NOMENU" rel="nofollow">https://secureuk.denisglobal.com/Template.php?uvKey=Forget&amp;uvMode=&amp;uvCall=NOMENU</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Dugger</title>
		<link>http://www.lightbluetouchpaper.org/2012/09/20/plaintext-password-reminders/comment-page-1/#comment-339287</link>
		<dc:creator>Justin Dugger</dc:creator>
		<pubDate>Thu, 20 Sep 2012 15:55:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=4519#comment-339287</guid>
		<description>I&#039;m not sure if you&#039;ve mentioned this site before on this blog, but there&#039;s a site, &lt;a href=&quot;http://plaintextoffenders.com/&quot; rel=&quot;nofollow&quot;&gt;http://plaintextoffenders.com/&lt;/a&gt;, that attempts to catalog sites known to implement plaintext reminders. Name and shame, I suppose.</description>
		<content:encoded><![CDATA[<p>I&#8217;m not sure if you&#8217;ve mentioned this site before on this blog, but there&#8217;s a site, <a href="http://plaintextoffenders.com/" rel="nofollow">http://plaintextoffenders.com/</a>, that attempts to catalog sites known to implement plaintext reminders. Name and shame, I suppose.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
