<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Review of Clipperz.com &#8211; password storage app</title>
	<atom:link href="http://www.centernetworks.com/review-of-clipperz-com-password-storage-app/feed" rel="self" type="application/rss+xml" />
	<link>http://www.centernetworks.com/review-of-clipperz-com-password-storage-app</link>
	<description>Web 2 and Social Media News and Reviews</description>
	<lastBuildDate>Sat, 21 Nov 2009 01:50:56 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Plinan</title>
		<link>http://www.centernetworks.com/review-of-clipperz-com-password-storage-app/comment-page-#comment-12641</link>
		<dc:creator>Plinan</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-12641</guid>
		<description>I usually just use the built-in password manager of firefox in combination of multiple passwords for different importance levels. Works pretty well for me so far. </description>
		<content:encoded><![CDATA[<p>I usually just use the built-in password manager of firefox in combination of multiple passwords for different importance levels. Works pretty well for me so far.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darren Stuart</title>
		<link>http://www.centernetworks.com/review-of-clipperz-com-password-storage-app/comment-page-#comment-12642</link>
		<dc:creator>Darren Stuart</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-12642</guid>
		<description>While I think its a good idea I think its a couple years to late.

openID solves this problem and I also tend to use things like backpack from 37 signals for this stuff also.

As Plinan says also Firefox does this fine and also so do the other major browsers out there.

</description>
		<content:encoded><![CDATA[<p>While I think its a good idea I think its a couple years to late.</p>
<p>openID solves this problem and I also tend to use things like backpack from 37 signals for this stuff also.</p>
<p>As Plinan says also Firefox does this fine and also so do the other major browsers out there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marco Barulli</title>
		<link>http://www.centernetworks.com/review-of-clipperz-com-password-storage-app/comment-page-#comment-12644</link>
		<dc:creator>Marco Barulli</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-12644</guid>
		<description>@ Allen

Hacking our servers will be quite useless since Clipperz let you submit confidential information into your browser, but your secrets are locally encrypted by the browser itself before being uploaded to Clipperz. You are not providing Clipperz any data, just a bunch of scrambled bits.

I just wanted to add that you don&#039;t really need to trust us, since _all_ Clipperz source code is available from our website along with checksums to verify its integrity. Further information about performing a security code review of Clipperz are available here:
http://www.clipperz.com/learn_more/reviewing_the_code

Furthermore we released under a BSD license the core crypto functions, the Clipperz Crypto Library is available here: http://code.google.com/p/clipperz.

So, don&#039;t trust us, but check for yourself! :-)


@Darren and Plinan

Browsers could really be a useful tool to store you password, but:
- just your passwords and the many other confidential data of our everyday lives
- if you need to access your web services from more than one terminal an ubiquitous online service works much better

Thanks for discussing Clipperz,
best regards,
Marco
</description>
		<content:encoded><![CDATA[<p>@ Allen</p>
<p>Hacking our servers will be quite useless since Clipperz let you submit confidential information into your browser, but your secrets are locally encrypted by the browser itself before being uploaded to Clipperz. You are not providing Clipperz any data, just a bunch of scrambled bits.</p>
<p>I just wanted to add that you don&#8217;t really need to trust us, since _all_ Clipperz source code is available from our website along with checksums to verify its integrity. Further information about performing a security code review of Clipperz are available here:<br />
<a href="http://www.clipperz.com/learn_more/reviewing_the_code" rel="nofollow">http://www.clipperz.com/learn_more/reviewing_the_code</a></p>
<p>Furthermore we released under a BSD license the core crypto functions, the Clipperz Crypto Library is available here: <a href="http://code.google.com/p/clipperz" rel="nofollow">http://code.google.com/p/clipperz</a>.</p>
<p>So, don&#8217;t trust us, but check for yourself! :-)</p>
<p>@Darren and Plinan</p>
<p>Browsers could really be a useful tool to store you password, but:<br />
- just your passwords and the many other confidential data of our everyday lives<br />
- if you need to access your web services from more than one terminal an ubiquitous online service works much better</p>
<p>Thanks for discussing Clipperz,<br />
best regards,<br />
Marco</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick Yeates</title>
		<link>http://www.centernetworks.com/review-of-clipperz-com-password-storage-app/comment-page-#comment-12694</link>
		<dc:creator>Nick Yeates</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-12694</guid>
		<description>@Marco

What about the comment of what happens when you are at a public terminal?

I may be at the library or a public work machine and need a password/login. Obviously a keylogger could be used in that case, but that is nearly unavoidable. What about someone coming after the fact or someone hacking into that public machine and getting some kind of locally cached version of your unencrypted info?</description>
		<content:encoded><![CDATA[<p>@Marco</p>
<p>What about the comment of what happens when you are at a public terminal?</p>
<p>I may be at the library or a public work machine and need a password/login. Obviously a keylogger could be used in that case, but that is nearly unavoidable. What about someone coming after the fact or someone hacking into that public machine and getting some kind of locally cached version of your unencrypted info?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tara Kelly (PassPack)</title>
		<link>http://www.centernetworks.com/review-of-clipperz-com-password-storage-app/comment-page-#comment-12701</link>
		<dc:creator>Tara Kelly (PassPack)</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-12701</guid>
		<description>Both Firefox and Explorer have security holes in their password storage. Here&#039;s a &lt;a href=&quot;http://www.securityfocus.com/infocus/1883&quot;&gt;link&lt;/a&gt; (it&#039;s old, but just run a search on google for more news).

Try using a Password Manager - it&#039;s just better. There&#039;s Clipperz. &lt;a href=&quot;https://www.passpack.com&quot;&gt;There&#039;s also PassPack&lt;/a&gt; (that&#039;s mine). Or if you prefer something not internet based, there&#039;s a plethora of sowftware to choose from.

The important thing is that you choose - and use - a password manager.</description>
		<content:encoded><![CDATA[<p>Both Firefox and Explorer have security holes in their password storage. Here&#8217;s a <a href="http://www.securityfocus.com/infocus/1883">link</a> (it&#8217;s old, but just run a search on google for more news).</p>
<p>Try using a Password Manager &#8211; it&#8217;s just better. There&#8217;s Clipperz. <a href="https://www.passpack.com">There&#8217;s also PassPack</a> (that&#8217;s mine). Or if you prefer something not internet based, there&#8217;s a plethora of sowftware to choose from.</p>
<p>The important thing is that you choose &#8211; and use &#8211; a password manager.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tara Kelly (PassPack)</title>
		<link>http://www.centernetworks.com/review-of-clipperz-com-password-storage-app/comment-page-#comment-12702</link>
		<dc:creator>Tara Kelly (PassPack)</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-12702</guid>
		<description>OpenID is often cited as a replacement for the need for a password manager. Actually OpenID and Password Managers solve two different problems:

OpenID = authentication (no security implied)
Password Manager = secure storage (no authentication implied)

Granted, password manager often *also* do an auto-login that pushes them into the realm of authentication as well, but that&#039;s not the primary function.

Plus, not all passwords are for websites, and not all websites support OpenID. So there&#039;s still plenty of need for a password manager.

</description>
		<content:encoded><![CDATA[<p>OpenID is often cited as a replacement for the need for a password manager. Actually OpenID and Password Managers solve two different problems:</p>
<p>OpenID = authentication (no security implied)<br />
Password Manager = secure storage (no authentication implied)</p>
<p>Granted, password manager often *also* do an auto-login that pushes them into the realm of authentication as well, but that&#8217;s not the primary function.</p>
<p>Plus, not all passwords are for websites, and not all websites support OpenID. So there&#8217;s still plenty of need for a password manager.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tara Kelly (PassPack)</title>
		<link>http://www.centernetworks.com/review-of-clipperz-com-password-storage-app/comment-page-#comment-12703</link>
		<dc:creator>Tara Kelly (PassPack)</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-12703</guid>
		<description>OpenID is often cited as a replacement for the need for a password manager. Actually OpenID and Password Managers solve two different problems:

OpenID = authentication (no security implied)
Password Manager = secure storage (no authentication implied)

Granted, password manager often *also* do an auto-login that pushes them into the realm of authentication as well, but that&#039;s not the primary function.

Plus, not all passwords are for websites, and not all websites support OpenID. So there&#039;s still plenty of need for a password manager.

</description>
		<content:encoded><![CDATA[<p>OpenID is often cited as a replacement for the need for a password manager. Actually OpenID and Password Managers solve two different problems:</p>
<p>OpenID = authentication (no security implied)<br />
Password Manager = secure storage (no authentication implied)</p>
<p>Granted, password manager often *also* do an auto-login that pushes them into the realm of authentication as well, but that&#8217;s not the primary function.</p>
<p>Plus, not all passwords are for websites, and not all websites support OpenID. So there&#8217;s still plenty of need for a password manager.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tara Kelly (PassPack)</title>
		<link>http://www.centernetworks.com/review-of-clipperz-com-password-storage-app/comment-page-#comment-12704</link>
		<dc:creator>Tara Kelly (PassPack)</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-12704</guid>
		<description>&lt;a href=&quot;https://www.passpack.com&quot;&gt;Here at PassPack&lt;/a&gt; we support disposable logins, also known as One Time Passwords or OTP. I know Clipperz is working on this because they&#039;ve mentioned it in other posts, but they haven&#039;t rolled it out yet.

By combining disposable logins, with an auto-login feature, you can sucessfully circumvent keyloggers.

PassPack&#039;s autologin tool (&lt;a href=&quot;http://passpack.wordpress.com/2007/03/22/passpack-auto-login-no-plugin-needed/&quot;&gt;coming &lt;i&gt;very&lt;/i&gt; soon&lt;/a&gt;) uses an anonymous bookmarklet.

The procedure would be: sign into your account using the Disposable Login, add the bookmarklet to the browser&#039;s favorites and use it. You can remove it form the favorites before leaving the terminal, but even if you forget, it won&#039;t work for anyone else. It contains no passwords or account information, and is entirely useless unless there is a PassPack account open in that browser.

All the data in PassPack (and Clipperz - they&#039;re our competitor, and we know their code probably better than they do [wink]) is totally volitile. When the browser window is closed, or you sign out, it&#039;s gone. Completely gone.</description>
		<content:encoded><![CDATA[<p><a href="https://www.passpack.com">Here at PassPack</a> we support disposable logins, also known as One Time Passwords or OTP. I know Clipperz is working on this because they&#8217;ve mentioned it in other posts, but they haven&#8217;t rolled it out yet.</p>
<p>By combining disposable logins, with an auto-login feature, you can sucessfully circumvent keyloggers.</p>
<p>PassPack&#8217;s autologin tool (<a href="http://passpack.wordpress.com/2007/03/22/passpack-auto-login-no-plugin-needed/">coming <i>very</i> soon</a>) uses an anonymous bookmarklet.</p>
<p>The procedure would be: sign into your account using the Disposable Login, add the bookmarklet to the browser&#8217;s favorites and use it. You can remove it form the favorites before leaving the terminal, but even if you forget, it won&#8217;t work for anyone else. It contains no passwords or account information, and is entirely useless unless there is a PassPack account open in that browser.</p>
<p>All the data in PassPack (and Clipperz &#8211; they&#8217;re our competitor, and we know their code probably better than they do [wink]) is totally volitile. When the browser window is closed, or you sign out, it&#8217;s gone. Completely gone.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
