<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Perfect Paper Passwords</title>
	<atom:link href="http://www.itsecpackets.com/blog/2007/12/20/perfect-paper-passwords/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.itsecpackets.com/blog/2007/12/20/perfect-paper-passwords/</link>
	<description>A Progammer explores the IT Security field; offering packets of useful information he picks up along the way.</description>
	<lastBuildDate>Tue, 05 Jan 2010 01:34:42 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: ITSec Packets &#124; VIP Access on your IPhone/ITouch</title>
		<link>http://www.itsecpackets.com/blog/2007/12/20/perfect-paper-passwords/comment-page-1/#comment-326</link>
		<dc:creator>ITSec Packets &#124; VIP Access on your IPhone/ITouch</dc:creator>
		<pubDate>Sun, 30 Aug 2009 03:54:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.itsecpackets.com/blog/?p=21#comment-326</guid>
		<description>[...] Appolgies for not writting in a while. I hope to make it up to you with this post and future posts with, hopefully, much less than 5 months between. Found a great little app for iPhone/iTouch that gives us home users multi-factor authentication with a cryptographically strong OTP (one time password). Many of us have a similar device to log onto our corporate networks. I have an RSA token from work that spits a new six digit one time code. The OTP adds an additional layer of security when logging onto to a site on the net and makes brute force attacks impossible. We discussed OTP in the post about Steve&#8217;s PPP  authentication system. [...]</description>
		<content:encoded><![CDATA[<p>[...] Appolgies for not writting in a while. I hope to make it up to you with this post and future posts with, hopefully, much less than 5 months between. Found a great little app for iPhone/iTouch that gives us home users multi-factor authentication with a cryptographically strong OTP (one time password). Many of us have a similar device to log onto our corporate networks. I have an RSA token from work that spits a new six digit one time code. The OTP adds an additional layer of security when logging onto to a site on the net and makes brute force attacks impossible. We discussed OTP in the post about Steve&#8217;s PPP  authentication system. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hugs</title>
		<link>http://www.itsecpackets.com/blog/2007/12/20/perfect-paper-passwords/comment-page-1/#comment-239</link>
		<dc:creator>Hugs</dc:creator>
		<pubDate>Mon, 01 Sep 2008 20:23:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.itsecpackets.com/blog/?p=21#comment-239</guid>
		<description>@P it&#039;s only part of a two factor authentication

&quot;Note that using PPP passcodes for authentication without also requiring a separate secret password would not be secure due to the danger that the PPP passcard could be compromised. For two-factor authentication to enhance security, both assertions &quot;something only you know&quot; and &quot;something only you have&quot; must remain valid. &quot;</description>
		<content:encoded><![CDATA[<p>@P it&#8217;s only part of a two factor authentication</p>
<p>&#8220;Note that using PPP passcodes for authentication without also requiring a separate secret password would not be secure due to the danger that the PPP passcard could be compromised. For two-factor authentication to enhance security, both assertions &#8220;something only you know&#8221; and &#8220;something only you have&#8221; must remain valid. &#8220;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: P</title>
		<link>http://www.itsecpackets.com/blog/2007/12/20/perfect-paper-passwords/comment-page-1/#comment-45</link>
		<dc:creator>P</dc:creator>
		<pubDate>Fri, 04 Jul 2008 15:39:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.itsecpackets.com/blog/?p=21#comment-45</guid>
		<description>This is not a very good solution. What if you leave the card on the table for a few minutes and some scans or photocopies the card. They can steal your 2FA device for life !</description>
		<content:encoded><![CDATA[<p>This is not a very good solution. What if you leave the card on the table for a few minutes and some scans or photocopies the card. They can steal your 2FA device for life !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben Rothke</title>
		<link>http://www.itsecpackets.com/blog/2007/12/20/perfect-paper-passwords/comment-page-1/#comment-12</link>
		<dc:creator>Ben Rothke</dc:creator>
		<pubDate>Tue, 25 Dec 2007 20:09:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.itsecpackets.com/blog/?p=21#comment-12</guid>
		<description>Good find.&lt;br/&gt;&lt;br/&gt;But how robust is the product?&lt;br/&gt;GRC is a small company, but is it scalable to work in a 50,000 token environment?&lt;br/&gt;&lt;br/&gt;Ben</description>
		<content:encoded><![CDATA[<p>Good find.</p>
<p>But how robust is the product?<br />GRC is a small company, but is it scalable to work in a 50,000 token environment?</p>
<p>Ben</p>
]]></content:encoded>
	</item>
</channel>
</rss>
