<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Are Passwords Greener?</title>
	<atom:link href="http://www.bloginfosec.com/2009/03/09/are-passwords-greener/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bloginfosec.com/2009/03/09/are-passwords-greener/</link>
	<description>An Information Security Magazine in a Blog Format</description>
	<lastBuildDate>Mon, 30 Jan 2012 11:01:25 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Richard</title>
		<link>http://www.bloginfosec.com/2009/03/09/are-passwords-greener/comment-page-1/#comment-20178</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Mon, 09 Mar 2009 13:09:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.bloginfosec.com/?p=828#comment-20178</guid>
		<description>I would suggest two things in response to your comments on OTP.

Firstly, the bingo style cards that you speak of are actually less secure than even passwords, as they operate within a much smaller set of  finite values. Not to mention that a simple phishing attack would reveal the entire card for future use by any fraudster.

Secondly, newer, greener technologies such as OTP&#039;s generated by software applications on mobile phones and invisible user authentication based on things like device profiling, geo-location, authentication velocity etc. are becoming more popular.

I do agree that greener alternatives need to be considered however I do not believe that bingo cards are the answer.</description>
		<content:encoded><![CDATA[<p>I would suggest two things in response to your comments on OTP.</p>
<p>Firstly, the bingo style cards that you speak of are actually less secure than even passwords, as they operate within a much smaller set of  finite values. Not to mention that a simple phishing attack would reveal the entire card for future use by any fraudster.</p>
<p>Secondly, newer, greener technologies such as OTP&#8217;s generated by software applications on mobile phones and invisible user authentication based on things like device profiling, geo-location, authentication velocity etc. are becoming more popular.</p>
<p>I do agree that greener alternatives need to be considered however I do not believe that bingo cards are the answer.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

