<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Save your passwords with Mozilla&#8217;s Weave</title>
	<atom:link href="http://www.gnucitizen.org/blog/save-your-passwords-with-mozillas-weave/feed/" rel="self" type="application/rss+xml" />
	<link>/blog/save-your-passwords-with-mozillas-weave/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Thu, 21 Aug 2008 20:21:20 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Atul Varma</title>
		<link>/blog/save-your-passwords-with-mozillas-weave/#comment-122892</link>
		<dc:creator>Atul Varma</dc:creator>
		<pubDate>Tue, 08 Jul 2008 22:53:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=889#comment-122892</guid>
		<description>Robert is correct; everything on the server is encrypted with your passphrase, so that even Mozilla's server admins don't know what you're storing, and this is in addition to yet another password that protects access to the encrypted data.

You can learn more about the technology behind it here:

  http://www.toolness.com/wp/?p=41</description>
		<content:encoded><![CDATA[<p>Robert is correct; everything on the server is encrypted with your passphrase, so that even Mozilla&#8217;s server admins don&#8217;t know what you&#8217;re storing, and this is in addition to yet another password that protects access to the encrypted data.</p>
<p>You can learn more about the technology behind it here:</p>
<p>  <a href="http://www.toolness.com/wp/?p=41" rel="nofollow">http://www.toolness.com/wp/?p=41</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert Helmer</title>
		<link>/blog/save-your-passwords-with-mozillas-weave/#comment-122884</link>
		<dc:creator>Robert Helmer</dc:creator>
		<pubDate>Tue, 08 Jul 2008 08:14:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=889#comment-122884</guid>
		<description>Er, doesn't Weave store everything encrypted on the server? 

Not to say that the user's machine could not be compromised and the key discovered, but if that happens then local data is compromised too.

This does open up the possibility for mass compromise if there is some kind of weakness in the encryption algorithm, key strength, etc. though I suppose.</description>
		<content:encoded><![CDATA[<p>Er, doesn&#8217;t Weave store everything encrypted on the server? </p>
<p>Not to say that the user&#8217;s machine could not be compromised and the key discovered, but if that happens then local data is compromised too.</p>
<p>This does open up the possibility for mass compromise if there is some kind of weakness in the encryption algorithm, key strength, etc. though I suppose.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCitizen: Another Mozilla Attack Vector? &#124; Infosecurity.US</title>
		<link>/blog/save-your-passwords-with-mozillas-weave/#comment-122873</link>
		<dc:creator>GNUCitizen: Another Mozilla Attack Vector? &#124; Infosecurity.US</dc:creator>
		<pubDate>Mon, 07 Jul 2008 06:58:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=889#comment-122873</guid>
		<description>[...] comments on the new Mozilla Weave product, yet another cloud computing initiative, gone awry? Is it really a good idea to save your passwords, and other personally identifiable data in the Cloud? Especially given today&#8217;s rather sorry record of protecting that data&#8230;.you decide.  Sphere: Related Content [...]</description>
		<content:encoded><![CDATA[<p>[...] comments on the new Mozilla Weave product, yet another cloud computing initiative, gone awry? Is it really a good idea to save your passwords, and other personally identifiable data in the Cloud? Especially given today&#8217;s rather sorry record of protecting that data&#8230;.you decide.  Sphere: Related Content [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jipe</title>
		<link>/blog/save-your-passwords-with-mozillas-weave/#comment-122797</link>
		<dc:creator>Jipe</dc:creator>
		<pubDate>Wed, 02 Jul 2008 21:02:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=889#comment-122797</guid>
		<description>What a nice single point of compromission for dummy users... and others ;-D</description>
		<content:encoded><![CDATA[<p>What a nice single point of compromission for dummy users&#8230; and others ;-D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LordNykon</title>
		<link>/blog/save-your-passwords-with-mozillas-weave/#comment-122789</link>
		<dc:creator>LordNykon</dc:creator>
		<pubDate>Wed, 02 Jul 2008 09:55:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=889#comment-122789</guid>
		<description>you have no idea ;) this is not to underestimate.
i.e. students using VPN to connect to their university which is pretty common nowadays

etc etc</description>
		<content:encoded><![CDATA[<p>you have no idea ;) this is not to underestimate.<br />
i.e. students using VPN to connect to their university which is pretty common nowadays</p>
<p>etc etc</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ronald</title>
		<link>/blog/save-your-passwords-with-mozillas-weave/#comment-122778</link>
		<dc:creator>ronald</dc:creator>
		<pubDate>Tue, 01 Jul 2008 22:30:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=889#comment-122778</guid>
		<description>word!</description>
		<content:encoded><![CDATA[<p>word!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>/blog/save-your-passwords-with-mozillas-weave/#comment-122776</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Tue, 01 Jul 2008 20:43:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=889#comment-122776</guid>
		<description>Wouldn't surprise me if many do!</description>
		<content:encoded><![CDATA[<p>Wouldn&#8217;t surprise me if many do!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>/blog/save-your-passwords-with-mozillas-weave/#comment-122773</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 01 Jul 2008 18:44:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=889#comment-122773</guid>
		<description>I hope not. :) I was speaking figuratively...</description>
		<content:encoded><![CDATA[<p>I hope not. :) I was speaking figuratively&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>/blog/save-your-passwords-with-mozillas-weave/#comment-122770</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Tue, 01 Jul 2008 17:36:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=889#comment-122770</guid>
		<description>Pshaw, no one uses the same password for their social networking account as their VPN account ;-)</description>
		<content:encoded><![CDATA[<p>Pshaw, no one uses the same password for their social networking account as their VPN account ;-)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
