<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: It&#8217;s Time to Get Serious About Security</title>
	<link>http://ilikeellipses.com/2008/05/29/its-time-to-get-serious-about-security/</link>
	<description>the blog for developers who care about more than just code...</description>
	<pubDate>Wed, 07 Jan 2009 01:38:40 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3</generator>
		<item>
		<title>By: mike hall</title>
		<link>http://ilikeellipses.com/2008/05/29/its-time-to-get-serious-about-security/#comment-1824</link>
		<dc:creator>mike hall</dc:creator>
		<pubDate>Thu, 29 May 2008 16:57:51 +0000</pubDate>
		<guid>http://ilikeellipses.com/2008/05/29/its-time-to-get-serious-about-security/#comment-1824</guid>
		<description>Don't get me wrong. You still need to be able to access the email account for this to work, since the emails with the username and reset password link are sent to that address, but how secure are most people's password anyways?</description>
		<content:encoded><![CDATA[<p>Don&#8217;t get me wrong. You still need to be able to access the email account for this to work, since the emails with the username and reset password link are sent to that address, but how secure are most people&#8217;s password anyways?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Gardiner</title>
		<link>http://ilikeellipses.com/2008/05/29/its-time-to-get-serious-about-security/#comment-1822</link>
		<dc:creator>Richard Gardiner</dc:creator>
		<pubDate>Thu, 29 May 2008 15:37:47 +0000</pubDate>
		<guid>http://ilikeellipses.com/2008/05/29/its-time-to-get-serious-about-security/#comment-1822</guid>
		<description>This is really insecure.  Your email address is in effect public (everybody you send an email to sees it, then they forward your email to someone else, who sends to someone else, ...).  Given the large customer base that the phone companies have, you could probably get into peoples accounts just by randomly trying email addresses you know - even without the user making the error you came across.  Even worse, what happens if you have a disgruntled ex-boyfriend/girlfriend - they probably already know your email address and phone company.</description>
		<content:encoded><![CDATA[<p>This is really insecure.  Your email address is in effect public (everybody you send an email to sees it, then they forward your email to someone else, who sends to someone else, &#8230;).  Given the large customer base that the phone companies have, you could probably get into peoples accounts just by randomly trying email addresses you know - even without the user making the error you came across.  Even worse, what happens if you have a disgruntled ex-boyfriend/girlfriend - they probably already know your email address and phone company.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arjan`s World &#187; LINKBLOG for May 29, 2008</title>
		<link>http://ilikeellipses.com/2008/05/29/its-time-to-get-serious-about-security/#comment-1821</link>
		<dc:creator>Arjan`s World &#187; LINKBLOG for May 29, 2008</dc:creator>
		<pubDate>Thu, 29 May 2008 15:28:31 +0000</pubDate>
		<guid>http://ilikeellipses.com/2008/05/29/its-time-to-get-serious-about-security/#comment-1821</guid>
		<description>[...] It’s Time to Get Serious About Security - Mike Hall Having a non-secure website is bad enough, but ignoring customers who take the time to spell this out for you &#8230; how would you feel if you&#8217;re the guy/gal that spelled their email address wrong with this possible consequence [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] It’s Time to Get Serious About Security - Mike Hall Having a non-secure website is bad enough, but ignoring customers who take the time to spell this out for you &#8230; how would you feel if you&#8217;re the guy/gal that spelled their email address wrong with this possible consequence [&#8230;]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
