<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: 20f1aeb7819d7858684c898d1e98c1bb</title>
	<atom:link href="http://ocaoimh.ie/20f1aeb7819d7858684c898d1e98c1bb/feed/" rel="self" type="application/rss+xml" />
	<link>http://ocaoimh.ie/20f1aeb7819d7858684c898d1e98c1bb/</link>
	<description>Look what I found today!</description>
	<lastBuildDate>Fri, 12 Mar 2010 15:12:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Episode 33: WordPress 2.3.2 released, WordPress 2.4 missed and changes to the podcast &#124; PHP Podcasts</title>
		<link>http://ocaoimh.ie/20f1aeb7819d7858684c898d1e98c1bb/comment-page-1/#comment-516968</link>
		<dc:creator>Episode 33: WordPress 2.3.2 released, WordPress 2.4 missed and changes to the podcast &#124; PHP Podcasts</dc:creator>
		<pubDate>Tue, 12 Feb 2008 21:37:44 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/2007/12/19/20f1aeb7819d7858684c898d1e98c1bb/#comment-516968</guid>
		<description>[...] algorithm, there&#8217;s a plugin to secure your admin pages, Donncha O Caoimh details other ways to secure your blog, and Blog Security&#8217;s Whitepaper on securing your blog is [...]</description>
		<content:encoded><![CDATA[<p>[...] algorithm, there&#8217;s a plugin to secure your admin pages, Donncha O Caoimh details other ways to secure your blog, and Blog Security&#8217;s Whitepaper on securing your blog is [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David G. Johnson</title>
		<link>http://ocaoimh.ie/20f1aeb7819d7858684c898d1e98c1bb/comment-page-1/#comment-413325</link>
		<dc:creator>David G. Johnson</dc:creator>
		<pubDate>Fri, 28 Dec 2007 04:34:25 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/2007/12/19/20f1aeb7819d7858684c898d1e98c1bb/#comment-413325</guid>
		<description>Thanks for raising this topic in such a creative fashion.  All someone needs to do is download a brute force utility to see how easy it is to hack their weak passwords.  8 characters should be anyone&#039;s minimum, and those should not be dictionary entries -- in any language.  

And oh yes... thanks, John, for the &quot;Princess Bride&quot; reference.</description>
		<content:encoded><![CDATA[<p>Thanks for raising this topic in such a creative fashion.  All someone needs to do is download a brute force utility to see how easy it is to hack their weak passwords.  8 characters should be anyone&#8217;s minimum, and those should not be dictionary entries &#8212; in any language.  </p>
<p>And oh yes&#8230; thanks, John, for the &#8220;Princess Bride&#8221; reference.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pirahna</title>
		<link>http://ocaoimh.ie/20f1aeb7819d7858684c898d1e98c1bb/comment-page-1/#comment-411868</link>
		<dc:creator>Pirahna</dc:creator>
		<pubDate>Wed, 26 Dec 2007 20:38:12 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/2007/12/19/20f1aeb7819d7858684c898d1e98c1bb/#comment-411868</guid>
		<description>Well &quot;Anthony&quot; isn&#039;t exactly what i call a secure password.

Try something like &quot;ireallywouldliketoseeAnthonyagain&quot; ... that should do the trick.</description>
		<content:encoded><![CDATA[<p>Well &#8220;Anthony&#8221; isn&#8217;t exactly what i call a secure password.</p>
<p>Try something like &#8220;ireallywouldliketoseeAnthonyagain&#8221; &#8230; that should do the trick.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shanti Braford</title>
		<link>http://ocaoimh.ie/20f1aeb7819d7858684c898d1e98c1bb/comment-page-1/#comment-406445</link>
		<dc:creator>Shanti Braford</dc:creator>
		<pubDate>Sat, 22 Dec 2007 22:41:58 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/2007/12/19/20f1aeb7819d7858684c898d1e98c1bb/#comment-406445</guid>
		<description>It&#039;s good to see some work being done in WordPress around this area.

For developers in general, who may not be familiar w/ all the ins and outs of storing user password hashes, salts, etc:

http://onwebapps.com/the-hopefully-somewhat-definitive-article-on-how-to-store-user-password-hashes/</description>
		<content:encoded><![CDATA[<p>It&#8217;s good to see some work being done in WordPress around this area.</p>
<p>For developers in general, who may not be familiar w/ all the ins and outs of storing user password hashes, salts, etc:</p>
<p><a href="http://onwebapps.com/the-hopefully-somewhat-definitive-article-on-how-to-store-user-password-hashes/" rel="nofollow">http://onwebapps.com/the-hopefully-somewhat-definitive-article-on-how-to-store-user-password-hashes/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lee</title>
		<link>http://ocaoimh.ie/20f1aeb7819d7858684c898d1e98c1bb/comment-page-1/#comment-403976</link>
		<dc:creator>Lee</dc:creator>
		<pubDate>Thu, 20 Dec 2007 17:37:53 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/2007/12/19/20f1aeb7819d7858684c898d1e98c1bb/#comment-403976</guid>
		<description>Maybe a WP plug-in that utilises some of the popular reverse md5 lookup web sites/services:

http://md5.rednoize.com/?xml&amp;q=20f1aeb7819d7858684c898d1e98c1bb

http://gdataonline.com/qkhash.php?mode=xml&amp;hash=20f1aeb7819d7858684c898d1e98c1bb

The results would be used to show the user if their password is &quot;known by hackers&quot;.</description>
		<content:encoded><![CDATA[<p>Maybe a WP plug-in that utilises some of the popular reverse md5 lookup web sites/services:</p>
<p><a href="http://md5.rednoize.com/?xml&amp;q=20f1aeb7819d7858684c898d1e98c1bb" rel="nofollow">http://md5.rednoize.com/?xml&amp;q=20f1aeb7819d7858684c898d1e98c1bb</a></p>
<p><a href="http://gdataonline.com/qkhash.php?mode=xml&amp;hash=20f1aeb7819d7858684c898d1e98c1bb" rel="nofollow">http://gdataonline.com/qkhash.php?mode=xml&amp;hash=20f1aeb7819d7858684c898d1e98c1bb</a></p>
<p>The results would be used to show the user if their password is &#8220;known by hackers&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tadd</title>
		<link>http://ocaoimh.ie/20f1aeb7819d7858684c898d1e98c1bb/comment-page-1/#comment-403919</link>
		<dc:creator>Tadd</dc:creator>
		<pubDate>Thu, 20 Dec 2007 15:26:03 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/2007/12/19/20f1aeb7819d7858684c898d1e98c1bb/#comment-403919</guid>
		<description>I don&#039;t use word passwords. All of my passwords are 12 characters, randomly generated via a program. I then save them on a thumb drive that I have on my person. When I need to log in I have my secured drive. I&#039;m planning on getting one of those thumb drives that use your thumb print as a password to access the information ... heck yeah. If for nothing else than for a complete geek factor.

But, it is amazing to me how people still use the ol&#039; cliche passwords. First names, pet names, middle names, birthdays, god ... anyone with any shred of &#039;net wisdom will realize that you need at least one number in there to break up the easy guesses.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t use word passwords. All of my passwords are 12 characters, randomly generated via a program. I then save them on a thumb drive that I have on my person. When I need to log in I have my secured drive. I&#8217;m planning on getting one of those thumb drives that use your thumb print as a password to access the information &#8230; heck yeah. If for nothing else than for a complete geek factor.</p>
<p>But, it is amazing to me how people still use the ol&#8217; cliche passwords. First names, pet names, middle names, birthdays, god &#8230; anyone with any shred of &#8216;net wisdom will realize that you need at least one number in there to break up the easy guesses.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Donncha</title>
		<link>http://ocaoimh.ie/20f1aeb7819d7858684c898d1e98c1bb/comment-page-1/#comment-403730</link>
		<dc:creator>Donncha</dc:creator>
		<pubDate>Thu, 20 Dec 2007 10:29:08 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/2007/12/19/20f1aeb7819d7858684c898d1e98c1bb/#comment-403730</guid>
		<description>Lloyd - of course! I should have linked to the trac ticket.

Kae - I was about to try that on the WordPress.com wp_users but it would take ages to execute and probably slow the site down. Phew.</description>
		<content:encoded><![CDATA[<p>Lloyd &#8211; of course! I should have linked to the trac ticket.</p>
<p>Kae &#8211; I was about to try that on the WordPress.com wp_users but it would take ages to execute and probably slow the site down. Phew.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Monika's Gedanken</title>
		<link>http://ocaoimh.ie/20f1aeb7819d7858684c898d1e98c1bb/comment-page-1/#comment-403420</link>
		<dc:creator>Monika's Gedanken</dc:creator>
		<pubDate>Thu, 20 Dec 2007 02:02:10 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/2007/12/19/20f1aeb7819d7858684c898d1e98c1bb/#comment-403420</guid>
		<description>&lt;strong&gt;mein Blog wurde&#160;gehackt&lt;/strong&gt;

der Albtraum jedes Bloggers. 
Morgens surfst Du zum Blog und findest fremde Klingeltöne darin oder es geht gar nichts mehr.
Zu 99,99% kam der &#8220;ungewünschte Besucher&#8221; ganz normal über den Adminaccount, weil das Passwort derart einfach war...</description>
		<content:encoded><![CDATA[<p><strong>mein Blog wurde&nbsp;gehackt</strong></p>
<p>der Albtraum jedes Bloggers.<br />
Morgens surfst Du zum Blog und findest fremde Klingeltöne darin oder es geht gar nichts mehr.<br />
Zu 99,99% kam der &#8220;ungewünschte Besucher&#8221; ganz normal über den Adminaccount, weil das Passwort derart einfach war&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Pozadzides</title>
		<link>http://ocaoimh.ie/20f1aeb7819d7858684c898d1e98c1bb/comment-page-1/#comment-403387</link>
		<dc:creator>John Pozadzides</dc:creator>
		<pubDate>Thu, 20 Dec 2007 01:03:07 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/2007/12/19/20f1aeb7819d7858684c898d1e98c1bb/#comment-403387</guid>
		<description>Guys, just a little reminder seeing how I&#039;m constantly writing about this topic.  Please don&#039;t use weak passwords!  And here is a &lt;a href=&quot;http://onemansblog.com/2007/11/25/john-p-on-connecticut-public-radio/&quot;&gt;radio interview&lt;/a&gt; I did on the subject.  

I just can&#039;t understand how in this day and age people still fall for this.  It&#039;s one of the classic blunders behind, &#039;Don&#039;t get involved in a land war in Asia&#039;, and &#039;Never go up against a Sicilian when DEATH is on the line!&#039;  Muahahahaha.

John</description>
		<content:encoded><![CDATA[<p>Guys, just a little reminder seeing how I&#8217;m constantly writing about this topic.  Please don&#8217;t use weak passwords!  And here is a <a href="http://onemansblog.com/2007/11/25/john-p-on-connecticut-public-radio/">radio interview</a> I did on the subject.  </p>
<p>I just can&#8217;t understand how in this day and age people still fall for this.  It&#8217;s one of the classic blunders behind, &#8216;Don&#8217;t get involved in a land war in Asia&#8217;, and &#8216;Never go up against a Sicilian when DEATH is on the line!&#8217;  Muahahahaha.</p>
<p>John</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lloyd Budd</title>
		<link>http://ocaoimh.ie/20f1aeb7819d7858684c898d1e98c1bb/comment-page-1/#comment-403374</link>
		<dc:creator>Lloyd Budd</dc:creator>
		<pubDate>Thu, 20 Dec 2007 00:41:46 +0000</pubDate>
		<guid isPermaLink="false">http://ocaoimh.ie/2007/12/19/20f1aeb7819d7858684c898d1e98c1bb/#comment-403374</guid>
		<description>Not just Ryan! There is a whole team of people contributing to make WordPress&#039; hashing and cookies more robust to attack, including the person, Steven J. Murdoch, who was attacked and did such an amazing job of isolating the vector.</description>
		<content:encoded><![CDATA[<p>Not just Ryan! There is a whole team of people contributing to make WordPress&#8217; hashing and cookies more robust to attack, including the person, Steven J. Murdoch, who was attacked and did such an amazing job of isolating the vector.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
