<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Yubikey and OpenID</title>
	<atom:link href="http://www.superbob.com/2008/05/24/yubikey-and-openid/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.superbob.com/2008/05/24/yubikey-and-openid/</link>
	<description>the pundit.</description>
	<lastBuildDate>Mon, 19 Jul 2010 05:38:11 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: bob</title>
		<link>http://www.superbob.com/2008/05/24/yubikey-and-openid/comment-page-1/#comment-128</link>
		<dc:creator>bob</dc:creator>
		<pubDate>Wed, 28 May 2008 02:11:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.superbob.com/?p=46#comment-128</guid>
		<description>That&#039;s a good point.  I was thinking more for use on my personal computers, but it would certainly be useful to have this on public machines.  The way the key is constructed, it looks like you need a USB port.  I have been considering, if the specifications are open enough, whether or not this could be simulated in software.  I don&#039;t know if this goes against the spirit of what they are trying to do.  How are OTP vulnerable to MITM attacks?  I thought that was the whole point because replaying the password wouldn&#039;t help.  The server would be looking for a new password the next time you had to log in.</description>
		<content:encoded><![CDATA[<p>That&#8217;s a good point.  I was thinking more for use on my personal computers, but it would certainly be useful to have this on public machines.  The way the key is constructed, it looks like you need a USB port.  I have been considering, if the specifications are open enough, whether or not this could be simulated in software.  I don&#8217;t know if this goes against the spirit of what they are trying to do.  How are OTP vulnerable to MITM attacks?  I thought that was the whole point because replaying the password wouldn&#8217;t help.  The server would be looking for a new password the next time you had to log in.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: virkam</title>
		<link>http://www.superbob.com/2008/05/24/yubikey-and-openid/comment-page-1/#comment-127</link>
		<dc:creator>virkam</dc:creator>
		<pubDate>Mon, 26 May 2008 01:35:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.superbob.com/?p=46#comment-127</guid>
		<description>hi, 

vert interesting product. only one question is - public PCs where u will not have usb prot available? then how does the product work. Or it is limited to machines having usb port. 

secondly, OTP are bypassed by attacks like MITM and MTIB. So does this product also have some hidden protect from these forms of attacks. 

it is good they are letting the product be open for other vendors to integrate or develop using their products. 

cheers</description>
		<content:encoded><![CDATA[<p>hi, </p>
<p>vert interesting product. only one question is &#8211; public PCs where u will not have usb prot available? then how does the product work. Or it is limited to machines having usb port. </p>
<p>secondly, OTP are bypassed by attacks like MITM and MTIB. So does this product also have some hidden protect from these forms of attacks. </p>
<p>it is good they are letting the product be open for other vendors to integrate or develop using their products. </p>
<p>cheers</p>
]]></content:encoded>
	</item>
</channel>
</rss>
