<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SuperBoB &#187; security</title>
	<atom:link href="http://www.superbob.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.superbob.com</link>
	<description>the pundit.</description>
	<lastBuildDate>Sat, 04 Jun 2011 01:02:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<item>
		<title>More OpenID and Yubikey</title>
		<link>http://www.superbob.com/2008/05/27/more-openid-and-yubikey/</link>
		<comments>http://www.superbob.com/2008/05/27/more-openid-and-yubikey/#comments</comments>
		<pubDate>Tue, 27 May 2008 16:15:08 +0000</pubDate>
		<dc:creator>bob</dc:creator>
				<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.superbob.com/?p=47</guid>
		<description><![CDATA[Stefan Brands has quite a list of issues with OpenID. I would think that the nature of Yubikey could solve some of the phishing issues. Since the password changes every time, capturing the password gives the bad guy one free login, but doesn&#8217;t hand off the keys to the kingdom. The privacy and web activity [...]]]></description>
			<content:encoded><![CDATA[<p>Stefan Brands has quite <a href="http://idcorner.org/2007/08/22/the-problems-with-openid/">a list</a> of issues with OpenID.  I would think that the nature of <a href="http://yubico.com/home/index/">Yubikey</a> could solve some of the phishing issues.  Since the password changes every time, capturing the password gives the bad guy one free login, but doesn&#8217;t hand off the keys to the kingdom.  The privacy and web activity tracking issues won&#8217;t be solved this way.  Running your own OpenID server on an SSL protected domain would help a lot, but not everybody can afford (financially or technically) to do that.  Stefan points out a lot more issues that have made me reconsider OpenID and whether it is the right idea.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.superbob.com/2008/05/27/more-openid-and-yubikey/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

