<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Playing with Fire</title>
	<atom:link href="http://eternallyoptimistic.com/2008/02/14/playing-with-fire/feed/" rel="self" type="application/rss+xml" />
	<link>http://eternallyoptimistic.com/2008/02/14/playing-with-fire/</link>
	<description></description>
	<lastBuildDate>Wed, 10 Aug 2011 17:44:16 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: PageOnce Beta: Two Lattes Left On My Starbucks Card &#171; PhilSpace</title>
		<link>http://eternallyoptimistic.com/2008/02/14/playing-with-fire/comment-page-1/#comment-332</link>
		<dc:creator>PageOnce Beta: Two Lattes Left On My Starbucks Card &#171; PhilSpace</dc:creator>
		<pubDate>Thu, 17 Apr 2008 15:20:01 +0000</pubDate>
		<guid isPermaLink="false">http://eternaloptimist.wordpress.com/?p=242#comment-332</guid>
		<description>[...] has some negative impressions, and I agree with some of the reservations Pamela has over the aggregation trend as a whole. Privacy and data portability will continue to conflict, and you do need to be careful [...]</description>
		<content:encoded><![CDATA[<p>[...] has some negative impressions, and I agree with some of the reservations Pamela has over the aggregation trend as a whole. Privacy and data portability will continue to conflict, and you do need to be careful [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Grant Alan Friedline</title>
		<link>http://eternallyoptimistic.com/2008/02/14/playing-with-fire/comment-page-1/#comment-335</link>
		<dc:creator>Grant Alan Friedline</dc:creator>
		<pubDate>Wed, 26 Mar 2008 20:28:32 +0000</pubDate>
		<guid isPermaLink="false">http://eternaloptimist.wordpress.com/?p=242#comment-335</guid>
		<description>Hello Pam.  I am new to your blog.  With articles like this, I am quickly becoming a fan.  When I think about Pageonce, I ask myself &quot;Grant, would you trust any accounts to Pageonce?&quot;.  I am able to answer yes, though certainly not all accounts.  Is it the same for you?  That is interesting in itself.  I have to think about that.</description>
		<content:encoded><![CDATA[<p>Hello Pam.  I am new to your blog.  With articles like this, I am quickly becoming a fan.  When I think about Pageonce, I ask myself &#8220;Grant, would you trust any accounts to Pageonce?&#8221;.  I am able to answer yes, though certainly not all accounts.  Is it the same for you?  That is interesting in itself.  I have to think about that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SlashID Blog &#187; Blog Archive &#187; Business Model of Identity Management</title>
		<link>http://eternallyoptimistic.com/2008/02/14/playing-with-fire/comment-page-1/#comment-334</link>
		<dc:creator>SlashID Blog &#187; Blog Archive &#187; Business Model of Identity Management</dc:creator>
		<pubDate>Mon, 25 Feb 2008 03:54:04 +0000</pubDate>
		<guid isPermaLink="false">http://eternaloptimist.wordpress.com/?p=242#comment-334</guid>
		<description>[...] your contacts or show all your accounts on one screen, thank you very much. Some people already cry foul, and hopefully their voice is being heard. (Some would claim that OAuth solves this problem - but [...]</description>
		<content:encoded><![CDATA[<p>[...] your contacts or show all your accounts on one screen, thank you very much. Some people already cry foul, and hopefully their voice is being heard. (Some would claim that OAuth solves this problem &#8211; but [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alan H</title>
		<link>http://eternallyoptimistic.com/2008/02/14/playing-with-fire/comment-page-1/#comment-336</link>
		<dc:creator>Alan H</dc:creator>
		<pubDate>Sun, 24 Feb 2008 21:48:23 +0000</pubDate>
		<guid isPermaLink="false">http://eternaloptimist.wordpress.com/?p=242#comment-336</guid>
		<description>I couldn&#039;t agree more -- I&#039;ve been meaning to write up some semi-literate article about this myself. In my opinion, one of the main problems with this is that the user community has been poorly educated about credential management and conditioned to ignore or not consider the security problems posed by this. Admittedly, you need a fairly solid understanding of electronic security concepts before the &quot;attack&quot; itself is evident.

The less sophisticated web users are not even going to recognize that divulging their Google , Hotmail, Yahoo! or even bank credentials to a third party is a bad idea because it isn&#039;t always obvious that it is a third party. You pretty much have to know that there is no solution to this problem to understand that there is a problem at hand.

Simply put, we&#039;ve dumbed things down so much in the media and education system that folks simply don&#039;t understand how this works and therefore cannot see the issues or risks. They are told to trust the pop-up dialogs that warn about this and that, but they are not really understanding the underlying security mechanism, so they are not in a position to see when they are broken or (worse) being exploited.</description>
		<content:encoded><![CDATA[<p>I couldn&#8217;t agree more &#8212; I&#8217;ve been meaning to write up some semi-literate article about this myself. In my opinion, one of the main problems with this is that the user community has been poorly educated about credential management and conditioned to ignore or not consider the security problems posed by this. Admittedly, you need a fairly solid understanding of electronic security concepts before the &#8220;attack&#8221; itself is evident.</p>
<p>The less sophisticated web users are not even going to recognize that divulging their Google , Hotmail, Yahoo! or even bank credentials to a third party is a bad idea because it isn&#8217;t always obvious that it is a third party. You pretty much have to know that there is no solution to this problem to understand that there is a problem at hand.</p>
<p>Simply put, we&#8217;ve dumbed things down so much in the media and education system that folks simply don&#8217;t understand how this works and therefore cannot see the issues or risks. They are told to trust the pop-up dialogs that warn about this and that, but they are not really understanding the underlying security mechanism, so they are not in a position to see when they are broken or (worse) being exploited.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Links &#187; OAuth</title>
		<link>http://eternallyoptimistic.com/2008/02/14/playing-with-fire/comment-page-1/#comment-333</link>
		<dc:creator>Links &#187; OAuth</dc:creator>
		<pubDate>Sat, 23 Feb 2008 12:38:06 +0000</pubDate>
		<guid isPermaLink="false">http://eternaloptimist.wordpress.com/?p=242#comment-333</guid>
		<description>[...] is freaked out by sites that gather all your logins. So am I. But this is exactly why a group of us got together to create OAuth. OAuth allows you to [...]</description>
		<content:encoded><![CDATA[<p>[...] is freaked out by sites that gather all your logins. So am I. But this is exactly why a group of us got together to create OAuth. OAuth allows you to [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

