<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Creating a better site registration login</title>
	<atom:link href="http://www.adamduvander.com/simple/creating-a-better-site-registration-login/feed" rel="self" type="application/rss+xml" />
	<link>http://www.adamduvander.com/simple/creating-a-better-site-registration-login</link>
	<description>Adam DuVander’s thoughts on keeping things simple.</description>
	<lastBuildDate>Mon, 09 Jan 2012 07:03:40 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Simplicity Rules &#38;#187; Blog Archive &#38;#187; Security and Privacy versus Simplicity</title>
		<link>http://www.adamduvander.com/simple/creating-a-better-site-registration-login/comment-page-1#comment-132</link>
		<dc:creator>Simplicity Rules &#38;#187; Blog Archive &#38;#187; Security and Privacy versus Simplicity</dc:creator>
		<pubDate>Fri, 05 May 2006 18:14:11 +0000</pubDate>
		<guid isPermaLink="false">http://yamhill.adamduvander.com/news/creating-a-better-site-registration-login#comment-132</guid>
		<description>[...] Sometimes we have roadblocks, like security. I have so many site registrations that it can be a lot of work to guess my username and password. As a defense, I know many who have the same login for every site. What would security experts have to say about that? [...]</description>
		<content:encoded><![CDATA[<p>[...] Sometimes we have roadblocks, like security. I have so many site registrations that it can be a lot of work to guess my username and password. As a defense, I know many who have the same login for every site. What would security experts have to say about that? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://www.adamduvander.com/simple/creating-a-better-site-registration-login/comment-page-1#comment-131</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Sun, 08 Jan 2006 20:53:00 +0000</pubDate>
		<guid isPermaLink="false">http://yamhill.adamduvander.com/news/creating-a-better-site-registration-login#comment-131</guid>
		<description>I told you I&#039;m not a security expert! This makes some sense, but I&#039;m not so sure it&#039;s that big of a leg up, especially given trade-off of the trouble it can give a visitor trying to guess his own credentials.

But I guess this is why I&#039;m not in security. &lt;a HREF=&quot;http://adamduvander.com/news/2005/11/year-of-optional-registration.html&quot; rel=&quot;nofollow&quot;&gt;Heck, I don&#039;t even want people to register at all&lt;/A&gt;.</description>
		<content:encoded><![CDATA[<p>I told you I&#8217;m not a security expert! This makes some sense, but I&#8217;m not so sure it&#8217;s that big of a leg up, especially given trade-off of the trouble it can give a visitor trying to guess his own credentials.</p>
<p>But I guess this is why I&#8217;m not in security. <a HREF="http://adamduvander.com/news/2005/11/year-of-optional-registration.html" rel="nofollow">Heck, I don&#8217;t even want people to register at all</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Duffy</title>
		<link>http://www.adamduvander.com/simple/creating-a-better-site-registration-login/comment-page-1#comment-130</link>
		<dc:creator>Mike Duffy</dc:creator>
		<pubDate>Sat, 07 Jan 2006 05:44:00 +0000</pubDate>
		<guid isPermaLink="false">http://yamhill.adamduvander.com/news/creating-a-better-site-registration-login#comment-130</guid>
		<description>It&#039;s driven by security: if you don&#039;t know a valid username, all the passwords in the world (including a correct one) are worthless.  If someone is trying a brute force attack on a site, telling them whether they have a valid username is a big leg up, since then you can use a dictionary attack on the password side.</description>
		<content:encoded><![CDATA[<p>It&#8217;s driven by security: if you don&#8217;t know a valid username, all the passwords in the world (including a correct one) are worthless.  If someone is trying a brute force attack on a site, telling them whether they have a valid username is a big leg up, since then you can use a dictionary attack on the password side.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

