<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>danielmiessler.com &#187; Community</title>
	<atom:link href="http://danielmiessler.com/categories/community/feed" rel="self" type="application/rss+xml" />
	<link>http://danielmiessler.com</link>
	<description>grep understanding</description>
	<lastBuildDate>Sat, 11 Feb 2012 21:09:03 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>New Project: PasswordStandards.com</title>
		<link>http://danielmiessler.com/blog/new-project-passwordstandardscom</link>
		<comments>http://danielmiessler.com/blog/new-project-passwordstandardscom#comments</comments>
		<pubDate>Mon, 12 Nov 2007 10:24:05 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Community]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://dmiessler.com/blogarchive/new-project-passwordstandardscom</guid>
		<description><![CDATA[I&#8217;ve just registered the domain of passwordstandards.com as part of a new project. The goal of the endeavor is to call attention to online services that don&#8217;t allow their users to select decently strong passwords. This is especially crucial for services that are financial in nature or maintain other types of sensitive information. Project Clarification [...]]]></description>
			<content:encoded><![CDATA[<p><center><img src="http://dmiessler.com/wp-content/uploaded_content/2007/11/lock.jpeg" alt="lock" /></center></p>

<p>I&#8217;ve just registered the domain of <strong>passwordstandards.com</strong> as part of a new project. The goal of the endeavor is to call attention to online services that don&#8217;t allow their users to select decently strong passwords. This is especially crucial for services that are financial in nature or maintain other types of sensitive information.</p>

<h2>Project Clarification</h2>

<p>First things first &#8212; the main focus of this site is to <strong>allow</strong> users to select <strong>strong</strong> passwords, not to disallow them from selecting weak ones. Prohibiting weak passwords is important as well but will not be the focus of the project.</p>

<h2>Basic Goals</h2>

<ul>
<li>Maintain a list of offenders and regularly &#8220;encourage&#8221; those on the list to improve</li>
<li>Have a few categories for the sites listed, e.g. financial, personal, etc.</li>
<li>For each site show the existing, weak standard that they support, e.g. no capitalization, or no special characters</li>
<li>Provide an interface for the community to submit sites for addition or deletion</li>
</ul>

<h2>The Mission Statement</h2>

<p>So let&#8217;s agree on a general project statement. Here&#8217;s what I&#8217;m thinking:</p>

<blockquote>Any online service that requires a login should allow security-conscious users to select strong passwords. If security is not a concern for your service then don&#8217;t require a password. If it is a concern then allow users to create a decent one.</blockquote>

<p>Please allow <em>at least</em> the following:</p>

<ol>
<li>Ten (10) total characters in length</li>
<li>Lowercase and uppercase letters</li>
<li>Numbers (0-9)</li>
<li>Basic special characters (to be agreed upon)</li>
</ol>

<p>Thoughts?</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/the-list-of-shame-websites-that-dont-allow-special-characters-in-their-passwords" rel="bookmark" class="crp_title">The List Of Shame: Websites That Don&#8217;t Allow Special Characters In Their Passwords</a></li><li><a href="http://danielmiessler.com/blog/security-implementing-a-secure-and-usable-internet-password-scheme" rel="bookmark" class="crp_title">Security: Implementing A Secure And Usable Internet Password Scheme</a></li><li><a href="http://danielmiessler.com/blog/lame-online-password-logic" rel="bookmark" class="crp_title">Lame Online Password Logic</a></li><li><a href="http://danielmiessler.com/blog/password-reset-mechanisms-the-online-security-threat-nobodys-talking-about" rel="bookmark" class="crp_title">Password Reset Mechanisms: The Online Security Threat Nobody&#8217;s Talking About</a></li><li><a href="http://danielmiessler.com/blog/from-password-reset-mechanisms-to-openid-a-brief-discussion-of-online-password-security" rel="bookmark" class="crp_title">From Password Reset Mechanisms to OpenID: A Brief Discussion of Online Password Security</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/new-project-passwordstandardscom/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>From Mailing Lists To RSS</title>
		<link>http://danielmiessler.com/blog/from-mailing-lists-to-rss</link>
		<comments>http://danielmiessler.com/blog/from-mailing-lists-to-rss#comments</comments>
		<pubDate>Thu, 22 Feb 2007 15:40:57 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Community]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Lists]]></category>
		<category><![CDATA[RSS]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/archives/1163</guid>
		<description><![CDATA[I&#8217;m not sure how this is going to work out yet, but I&#8217;m making the switch away from mailing list for a couple of my key security sources &#8212; most importantly, Full Disclosure and Bugtraq. A few I&#8217;ll still interact with through my mail client, i.e. those that I participate actively in more often, but [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m not sure how this is going to work out yet, but I&#8217;m making the switch away from mailing list for a couple of my key security sources &#8212; most importantly, Full Disclosure and Bugtraq.</p>

<p>A few I&#8217;ll still interact with through my mail client, i.e. those that I participate actively in more often, but for the majority of them I&#8217;m going to be moving to RSS. Here&#8217;s a short list of feeds you might want to look at: <a href="http://seclists.org/rss/bugtraq.rss"></a></p>

<ul>
    <li><a href="http://seclists.org/rss/bugtraq.rss">Bugtraq</a></li>
    <li><a href="http://seclists.org/rss/fulldisclosure.rss">Full Disclosure</a></li>
    <li><a href="http://seclists.org/rss/nmap-hackers.rss">Nmap Hackers</a></li>
</ul>

<p>And here&#8217;s <a href="http://seclists.org/">a comprehensive list from seclist.org</a>.</p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/nmap-now-does-web-spidering" rel="bookmark" class="crp_title">Nmap Now Does Web Spidering</a></li><li><a href="http://danielmiessler.com/blog/pentesting-use-firefox-quicksearches-to-lookup-bugtraq-ids-from-the-address-bar" rel="bookmark" class="crp_title">Pentesting: Use Firefox Quicksearches To Lookup Bugtraq IDs From The Address Bar</a></li><li><a href="http://danielmiessler.com/blog/stored-xss-on-amazon" rel="bookmark" class="crp_title">Stored XSS on Amazon</a></li><li><a href="http://danielmiessler.com/blog/why-i-hate-mailing-lists" rel="bookmark" class="crp_title">Why I Hate Mailing Lists</a></li><li><a href="http://danielmiessler.com/blog/new-features-in-nmap-400" rel="bookmark" class="crp_title">New Features in Nmap 4.00</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/from-mailing-lists-to-rss/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>OpenSSH Donation Pledge Drive</title>
		<link>http://danielmiessler.com/blog/openssh-donation-pledge-drive</link>
		<comments>http://danielmiessler.com/blog/openssh-donation-pledge-drive#comments</comments>
		<pubDate>Wed, 12 Apr 2006 19:38:46 +0000</pubDate>
		<dc:creator>Daniel Miessler</dc:creator>
				<category><![CDATA[Community]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://dmiessler.com/archives/740</guid>
		<description><![CDATA[I&#8217;ve already blogged about helping this project in the recent past, but my buddies at ATU have come together with a more organized effort. So once again I ask you, my fellow geeks, if you enjoy what OpenSSH offers and have a few bucks to spare, please go ahead and give what you can. This [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve already <a href="http://dmiessler.com/archives/725">blogged about helping this project</a> in the recent past, but my buddies at <a href="http://www.dslreports.com/forum/unixdsl">ATU</a> have come together with a more organized effort. So once again I ask you, my fellow geeks, if you enjoy what <a href="http://openssh.org">OpenSSH</a> offers and have a few bucks to spare, please go ahead and give what you can. This is one of the core projects in the security community and they need our help.</p>

<p><a href="http://www.dslreports.com/forum/remark,15881389">Link: OpenSSH Donation Pledge Drive</a></p>
<div id="crp_related"><h3>Related Content</h3><ul><li><a href="http://danielmiessler.com/blog/openssh-80" rel="bookmark" class="crp_title">OpenSSH 4.0</a></li><li><a href="http://danielmiessler.com/blog/openbsd-needs-you" rel="bookmark" class="crp_title">OpenBSD Needs You</a></li><li><a href="http://danielmiessler.com/blog/debate-about-the-word-hacker" rel="bookmark" class="crp_title">Debate About The Word Hacker</a></li><li><a href="http://danielmiessler.com/blog/devrandom-%c2%bb-openssh-new-feature-%e2%80%9cnetcat-mode%e2%80%9d" rel="bookmark" class="crp_title">/dev/random » OpenSSH New Feature: “Netcat mode”</a></li><li><a href="http://danielmiessler.com/blog/unix-geek-humor-3" rel="bookmark" class="crp_title">Unix Geek Humor</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://danielmiessler.com/blog/openssh-donation-pledge-drive/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

