<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Identity X-file 0&#215;01</title>
	<atom:link href="http://eternallyoptimistic.com/2007/03/25/identity-x-file-0x01/feed/" rel="self" type="application/rss+xml" />
	<link>http://eternallyoptimistic.com/2007/03/25/identity-x-file-0x01/</link>
	<description></description>
	<lastBuildDate>Wed, 10 Aug 2011 17:44:16 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Kim Cameron&#8217;s Identity Weblog &#187; 6 year old installs keylogger</title>
		<link>http://eternallyoptimistic.com/2007/03/25/identity-x-file-0x01/comment-page-1/#comment-225</link>
		<dc:creator>Kim Cameron&#8217;s Identity Weblog &#187; 6 year old installs keylogger</dc:creator>
		<pubDate>Fri, 06 Apr 2007 06:25:11 +0000</pubDate>
		<guid isPermaLink="false">http://eternaloptimist.wordpress.com/2007/03/25/identity-x-file-0x01/#comment-225</guid>
		<description>[...] Here is a strange one via Pamela Dingle&#8217;s eternal optimist: [...]</description>
		<content:encoded><![CDATA[<p>[...] Here is a strange one via Pamela Dingle&#8217;s eternal optimist: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Blakley</title>
		<link>http://eternallyoptimistic.com/2007/03/25/identity-x-file-0x01/comment-page-1/#comment-226</link>
		<dc:creator>Bob Blakley</dc:creator>
		<pubDate>Wed, 28 Mar 2007 04:53:06 +0000</pubDate>
		<guid isPermaLink="false">http://eternaloptimist.wordpress.com/2007/03/25/identity-x-file-0x01/#comment-226</guid>
		<description>You&#039;re correct; CardSpace doesn&#039;t fix this problem.  It&#039;s fundamentally an analog hole problem.

The omnipotent, omniscient, and omnipresent adversary is a tough one (&quot;For there is nothing covered that shall not be revealed, and hid, that shall not be known&quot; - Matt. 10:26); the bad guy sitting next to you as you work is a good simulation of that adversary.</description>
		<content:encoded><![CDATA[<p>You&#8217;re correct; CardSpace doesn&#8217;t fix this problem.  It&#8217;s fundamentally an analog hole problem.</p>
<p>The omnipotent, omniscient, and omnipresent adversary is a tough one (&#8220;For there is nothing covered that shall not be revealed, and hid, that shall not be known&#8221; &#8211; Matt. 10:26); the bad guy sitting next to you as you work is a good simulation of that adversary.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pamela</title>
		<link>http://eternallyoptimistic.com/2007/03/25/identity-x-file-0x01/comment-page-1/#comment-224</link>
		<dc:creator>Pamela</dc:creator>
		<pubDate>Mon, 26 Mar 2007 16:20:14 +0000</pubDate>
		<guid isPermaLink="false">http://eternaloptimist.wordpress.com/2007/03/25/identity-x-file-0x01/#comment-224</guid>
		<description>Heh, I&#039;m all for arguing, whether it&#039;s a subcase or not, I don&#039;t see the harm in it...

Information is information.  IdP passwords and damaging emails, it&#039;s all just a bitstream that has to be parsed.  I would ask what the difference is between an email loaded directly into a keyboard logger and an email that an attacker reads and downloads as a result of stealing the user&#039;s email password?</description>
		<content:encoded><![CDATA[<p>Heh, I&#8217;m all for arguing, whether it&#8217;s a subcase or not, I don&#8217;t see the harm in it&#8230;</p>
<p>Information is information.  IdP passwords and damaging emails, it&#8217;s all just a bitstream that has to be parsed.  I would ask what the difference is between an email loaded directly into a keyboard logger and an email that an attacker reads and downloads as a result of stealing the user&#8217;s email password?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric Norman</title>
		<link>http://eternallyoptimistic.com/2007/03/25/identity-x-file-0x01/comment-page-1/#comment-227</link>
		<dc:creator>Eric Norman</dc:creator>
		<pubDate>Mon, 26 Mar 2007 00:01:27 +0000</pubDate>
		<guid isPermaLink="false">http://eternaloptimist.wordpress.com/2007/03/25/identity-x-file-0x01/#comment-227</guid>
		<description>While the comment regarding stealing someone&#039;s IdP credentials is technically correct, it&#039;s not the whole story and I would not want to see folks argue a lot about how to solve that &quot;authentication&quot; step.

Isn&#039;t the real security problem with keystroke loggers that the miscreant can obtain information that was typed in after that initial step?  E.g. they can obtain what was typed into that confidential email message or something similar.</description>
		<content:encoded><![CDATA[<p>While the comment regarding stealing someone&#8217;s IdP credentials is technically correct, it&#8217;s not the whole story and I would not want to see folks argue a lot about how to solve that &#8220;authentication&#8221; step.</p>
<p>Isn&#8217;t the real security problem with keystroke loggers that the miscreant can obtain information that was typed in after that initial step?  E.g. they can obtain what was typed into that confidential email message or something similar.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

