<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: From Password Reset Mechanisms to OpenID: A Brief Discussion of Online Password Security</title>
	<atom:link href="http://danielmiessler.com/blog/from-password-reset-mechanisms-to-openid-a-brief-discussion-of-online-password-security/feed" rel="self" type="application/rss+xml" />
	<link>http://danielmiessler.com/blog/from-password-reset-mechanisms-to-openid-a-brief-discussion-of-online-password-security</link>
	<description>grep understanding</description>
	<lastBuildDate>Fri, 25 May 2012 02:15:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Blog :: by Wade Woolwine &#187; Blog Archive &#187; News and Commentary :: by WadeW and You (08/28/2009)</title>
		<link>http://danielmiessler.com/blog/from-password-reset-mechanisms-to-openid-a-brief-discussion-of-online-password-security/comment-page-1#comment-243123</link>
		<dc:creator>Blog :: by Wade Woolwine &#187; Blog Archive &#187; News and Commentary :: by WadeW and You (08/28/2009)</dc:creator>
		<pubDate>Fri, 28 Aug 2009 13:12:02 +0000</pubDate>
		<guid isPermaLink="false">http://danielmiessler.com/blog/from-openid-to-email-resets-a-discussion-of-online-password-security#comment-243123</guid>
		<description>&lt;p&gt;[...] http://danielmiessler.com/blog/from-password-reset-mechanisms-to-openid-a-brief-discussion-of-online... / http://danielmiessler.com/blog/password-reset-mechanisms-the-online-security-threat-nobodys-talking-about I&#8217;m really glad this topic is getting some press. I wrote about ASQs a few months ago and have since been noticing some changes in the options available for password reset functionality. Google allows you to select between secondary email reset, SMS, and ASQ. Additionally, there&#8217;s a 24hrs waiting period after the email notification is sent out to the secondary email address before you can leverage the other 2 methods. Very nice. MyOpenID (my OpenID provider) offers password, certificate based authentication, and telephone based authentication &#8211; pretty awesome options! Alas, the recover password functionality simply sends an email with a 11 character variable that you click to recover your account. Not too happy about that. There you have it, Google has given some serious thought to security in password recovery, MyOpenID, not so much. [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://danielmiessler.com/blog/from-password-reset-mechanisms-to-openid-a-brief-discussion-of-online" rel="nofollow">http://danielmiessler.com/blog/from-password-reset-mechanisms-to-openid-a-brief-discussion-of-online</a>&#8230; / <a href="http://danielmiessler.com/blog/password-reset-mechanisms-the-online-security-threat-nobodys-talking-about" rel="nofollow">http://danielmiessler.com/blog/password-reset-mechanisms-the-online-security-threat-nobodys-talking-about</a> I&#8217;m really glad this topic is getting some press. I wrote about ASQs a few months ago and have since been noticing some changes in the options available for password reset functionality. Google allows you to select between secondary email reset, SMS, and ASQ. Additionally, there&#8217;s a 24hrs waiting period after the email notification is sent out to the secondary email address before you can leverage the other 2 methods. Very nice. MyOpenID (my OpenID provider) offers password, certificate based authentication, and telephone based authentication &#8211; pretty awesome options! Alas, the recover password functionality simply sends an email with a 11 character variable that you click to recover your account. Not too happy about that. There you have it, Google has given some serious thought to security in password recovery, MyOpenID, not so much. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

