<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: NCSAM TIP #14: Password Management</title>
	<atom:link href="http://blogs.cisco.com/security/ncsam-tip14-password-management/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.cisco.com/security/ncsam-tip14-password-management/</link>
	<description></description>
	<lastBuildDate>Wed, 19 Jun 2013 16:52:29 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: Nitin Jain</title>
		<link>http://blogs.cisco.com/security/ncsam-tip14-password-management/#comment-348662</link>
		<dc:creator>Nitin Jain</dc:creator>
		<pubDate>Mon, 24 Oct 2011 22:22:34 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cisco.com/?p=47628#comment-348662</guid>
		<description><![CDATA[I am using last pass since a year and it is very good
For password management and keeping password stored in 
Exel sheet along with automatic password filling option.. Which is quite good]]></description>
		<content:encoded><![CDATA[<p>I am using last pass since a year and it is very good<br />
For password management and keeping password stored in<br />
Exel sheet along with automatic password filling option.. Which is quite good
<p class="comment-like"><img class="comment-like-btn" title="Vote" onclick="cl_like_this('http://blogs.cisco.com/wp-admin/admin-ajax.php',348662)" src="http://blogs.cisco.com/wp-content/plugins/comments-likes/images/like.png" />&nbsp;&nbsp;&nbsp;<span id="comment-like-cnt-348662">0</span> likes</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy Balinsky</title>
		<link>http://blogs.cisco.com/security/ncsam-tip14-password-management/#comment-334906</link>
		<dc:creator>Andy Balinsky</dc:creator>
		<pubDate>Fri, 21 Oct 2011 18:59:30 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cisco.com/?p=47628#comment-334906</guid>
		<description><![CDATA[Those virtual keyboards are certainly a good defense against keystroke loggers. For completely compromised machines, other things can be recorded, too, such as mouse clicks, screen captures, etc. So they are a step up, but never a 100% safety guarantee.
Cloud-based storage is purely a personal choice between convenience and security. There is always additional risk, no matter how mitigated, to trusting your passwords to a cloud service. These risks can be reduced if the cloud provider doesn&#039;t have the encryption key, and has strong security practices and technical controls. Of course, your local password store could also be lost in the event of theft or computer compromise. In either case, it then comes down to the strength of your master secrets, and the willingness of the adversary to apply computing resources against them. On a humorous note, this comic points out that the secrets themselves aren&#039;t always the weakest link: http://xkcd.com/538]]></description>
		<content:encoded><![CDATA[<p>Those virtual keyboards are certainly a good defense against keystroke loggers. For completely compromised machines, other things can be recorded, too, such as mouse clicks, screen captures, etc. So they are a step up, but never a 100% safety guarantee.<br />
Cloud-based storage is purely a personal choice between convenience and security. There is always additional risk, no matter how mitigated, to trusting your passwords to a cloud service. These risks can be reduced if the cloud provider doesn&#8217;t have the encryption key, and has strong security practices and technical controls. Of course, your local password store could also be lost in the event of theft or computer compromise. In either case, it then comes down to the strength of your master secrets, and the willingness of the adversary to apply computing resources against them. On a humorous note, this comic points out that the secrets themselves aren&#8217;t always the weakest link: <a href="http://xkcd.com/538" rel="nofollow">http://xkcd.com/538</a>
<p class="comment-like"><img class="comment-like-btn" title="Vote" onclick="cl_like_this('http://blogs.cisco.com/wp-admin/admin-ajax.php',334906)" src="http://blogs.cisco.com/wp-content/plugins/comments-likes/images/like.png" />&nbsp;&nbsp;&nbsp;<span id="comment-like-cnt-334906">0</span> likes</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Usman</title>
		<link>http://blogs.cisco.com/security/ncsam-tip14-password-management/#comment-330883</link>
		<dc:creator>Usman</dc:creator>
		<pubDate>Fri, 21 Oct 2011 04:29:04 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cisco.com/?p=47628#comment-330883</guid>
		<description><![CDATA[Well i am confronted with the same threat of password theft. I have been using different passwords for different accounts but for this reason I have to remember multiple passwords. Well personally i think the software programs that allow entry of the password on a virtual keyboard through mouse clicks are more reliable for protection against keystroke loggers but i think its not a wise idea to store passwords in a cloud based storage service.]]></description>
		<content:encoded><![CDATA[<p>Well i am confronted with the same threat of password theft. I have been using different passwords for different accounts but for this reason I have to remember multiple passwords. Well personally i think the software programs that allow entry of the password on a virtual keyboard through mouse clicks are more reliable for protection against keystroke loggers but i think its not a wise idea to store passwords in a cloud based storage service.
<p class="comment-like"><img class="comment-like-btn" title="Vote" onclick="cl_like_this('http://blogs.cisco.com/wp-admin/admin-ajax.php',330883)" src="http://blogs.cisco.com/wp-content/plugins/comments-likes/images/like.png" />&nbsp;&nbsp;&nbsp;<span id="comment-like-cnt-330883">0</span> likes</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://blogs.cisco.com/security/ncsam-tip14-password-management/#comment-329036</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Thu, 20 Oct 2011 21:09:22 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cisco.com/?p=47628#comment-329036</guid>
		<description><![CDATA[well, i recommend http://keepass.sf.net
client based, open source and strong encryptions, with mono (2.x) or wine (1.x) even running on linux. i use it since ~4-5 years.]]></description>
		<content:encoded><![CDATA[<p>well, i recommend <a href="http://keepass.sf.net" rel="nofollow">http://keepass.sf.net</a><br />
client based, open source and strong encryptions, with mono (2.x) or wine (1.x) even running on linux. i use it since ~4-5 years.
<p class="comment-like"><img class="comment-like-btn" title="Vote" onclick="cl_like_this('http://blogs.cisco.com/wp-admin/admin-ajax.php',329036)" src="http://blogs.cisco.com/wp-content/plugins/comments-likes/images/like.png" />&nbsp;&nbsp;&nbsp;<span id="comment-like-cnt-329036">0</span> likes</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy Balinsky</title>
		<link>http://blogs.cisco.com/security/ncsam-tip14-password-management/#comment-328612</link>
		<dc:creator>Andy Balinsky</dc:creator>
		<pubDate>Thu, 20 Oct 2011 19:14:45 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cisco.com/?p=47628#comment-328612</guid>
		<description><![CDATA[Thanks for the endorsement. There are a number of password managers out there. I avoided promoting any particular one publicly, but the one I use works great on MacOS, iOS, Windows, and all synchronized automatically, so rarely have to type a password.]]></description>
		<content:encoded><![CDATA[<p>Thanks for the endorsement. There are a number of password managers out there. I avoided promoting any particular one publicly, but the one I use works great on MacOS, iOS, Windows, and all synchronized automatically, so rarely have to type a password.
<p class="comment-like"><img class="comment-like-btn" title="Vote" onclick="cl_like_this('http://blogs.cisco.com/wp-admin/admin-ajax.php',328612)" src="http://blogs.cisco.com/wp-content/plugins/comments-likes/images/like.png" />&nbsp;&nbsp;&nbsp;<span id="comment-like-cnt-328612">0</span> likes</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Colin Westwater</title>
		<link>http://blogs.cisco.com/security/ncsam-tip14-password-management/#comment-328302</link>
		<dc:creator>Colin Westwater</dc:creator>
		<pubDate>Thu, 20 Oct 2011 17:39:57 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cisco.com/?p=47628#comment-328302</guid>
		<description><![CDATA[LastPass is excellent.  Paired with Chrome and Dolphin Browser HD on my HTC Desire it has simplified my password management and made my logins more secure]]></description>
		<content:encoded><![CDATA[<p>LastPass is excellent.  Paired with Chrome and Dolphin Browser HD on my HTC Desire it has simplified my password management and made my logins more secure
<p class="comment-like"><img class="comment-like-btn" title="Vote" onclick="cl_like_this('http://blogs.cisco.com/wp-admin/admin-ajax.php',328302)" src="http://blogs.cisco.com/wp-content/plugins/comments-likes/images/like.png" />&nbsp;&nbsp;&nbsp;<span id="comment-like-cnt-328302">0</span> likes</p>
]]></content:encoded>
	</item>
</channel>
</rss>
