<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Computer Science @ CofC</title>
	<atom:link href="http://www.cs.cofc.edu/blog/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cs.cofc.edu/blog</link>
	<description>Commentary from Students &#38; Faculty</description>
	<lastBuildDate>Fri, 03 Feb 2012 21:16:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on Summer Undergraduate Research Program Opportunity by PC</title>
		<link>http://www.cs.cofc.edu/blog/2012/01/summer-undergraduate-research-program-opportunity/comment-page-1/#comment-408</link>
		<dc:creator>PC</dc:creator>
		<pubDate>Fri, 03 Feb 2012 21:16:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.cs.cofc.edu/blog/?p=199#comment-408</guid>
		<description>Looks like fun - too bad I missed the deadline :(</description>
		<content:encoded><![CDATA[<p>Looks like fun &#8211; too bad I missed the deadline <img src='http://www.cs.cofc.edu/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to Keep the (traditionally) Educated Population Ignorant by computer repair ft lauderdale</title>
		<link>http://www.cs.cofc.edu/blog/2011/04/how-to-keep-the-traditionally-educated-population-ignorant/comment-page-1/#comment-323</link>
		<dc:creator>computer repair ft lauderdale</dc:creator>
		<pubDate>Wed, 22 Jun 2011 11:11:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.cs.cofc.edu/blog/?p=164#comment-323</guid>
		<description>excel formulas are something a lot of people fail to educate themselves with unfortunately, but its also where i...&quot;excel&quot;...haha.</description>
		<content:encoded><![CDATA[<p>excel formulas are something a lot of people fail to educate themselves with unfortunately, but its also where i&#8230;&#8221;excel&#8221;&#8230;haha.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Password Aging at the College of Charleston by Gary Smith</title>
		<link>http://www.cs.cofc.edu/blog/2010/08/password-aging-at-the-college-of-charleston/comment-page-1/#comment-289</link>
		<dc:creator>Gary Smith</dc:creator>
		<pubDate>Sun, 27 Mar 2011 12:46:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.cs.cofc.edu/blog/?p=143#comment-289</guid>
		<description>I am pretty paranoid bacause i ve been exposed to some &lt;a href=&quot;http://keyloggerreview.net&quot; rel=&quot;nofollow&quot;&gt;keyloggers&lt;/a&gt;
and i know how easy it is for someone to get your passwords and steal valuable data.

I now use different passwords for each important task i need to do, and i generate the passwords based on an algorithm that i can remember, based on the website.

This produces unique strong passwords that can&#039;t be easily exposed, and if i do get hacked, it will be only on one account.</description>
		<content:encoded><![CDATA[<p>I am pretty paranoid bacause i ve been exposed to some <a href="http://keyloggerreview.net" rel="nofollow">keyloggers</a><br />
and i know how easy it is for someone to get your passwords and steal valuable data.</p>
<p>I now use different passwords for each important task i need to do, and i generate the passwords based on an algorithm that i can remember, based on the website.</p>
<p>This produces unique strong passwords that can&#8217;t be easily exposed, and if i do get hacked, it will be only on one account.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on When the educated do not compute by Meili</title>
		<link>http://www.cs.cofc.edu/blog/2010/06/when-the-educated-do-not-compute/comment-page-1/#comment-285</link>
		<dc:creator>Meili</dc:creator>
		<pubDate>Mon, 07 Mar 2011 13:20:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.cs.cofc.edu/blog/?p=137#comment-285</guid>
		<description>&quot;We still expect high school students to take multiple years of mathematics but not even a day of computer science&quot;

That is true and its a pity that Computer Science is not taught early. Fora graduate who is not in the scientific, technological or mathematical fields, computer science is a lot more useful than calculus.

&lt;a href=&quot;http://stripeybank.blogspot.com/&quot; rel=&quot;nofollow&quot;&gt;Meili&#039;s Runescape Blog - The Runescape Wilderness&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>&#8220;We still expect high school students to take multiple years of mathematics but not even a day of computer science&#8221;</p>
<p>That is true and its a pity that Computer Science is not taught early. Fora graduate who is not in the scientific, technological or mathematical fields, computer science is a lot more useful than calculus.</p>
<p><a href="http://stripeybank.blogspot.com/" rel="nofollow">Meili&#8217;s Runescape Blog &#8211; The Runescape Wilderness</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Password Aging at the College of Charleston by Sean</title>
		<link>http://www.cs.cofc.edu/blog/2010/08/password-aging-at-the-college-of-charleston/comment-page-1/#comment-266</link>
		<dc:creator>Sean</dc:creator>
		<pubDate>Mon, 17 Jan 2011 07:22:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.cs.cofc.edu/blog/?p=143#comment-266</guid>
		<description>One thing that confuses me when it comes to passwords that need to be secure are banks using pictures or site keys. I don&#039;t see how that would help them with security.

Something that may help with security at your college is if you login from a different machine than normal it asks you a security question to make sure it&#039;s you. I know my credit card company does that, it is annoying, but I imagine it cuts down on the trouble.</description>
		<content:encoded><![CDATA[<p>One thing that confuses me when it comes to passwords that need to be secure are banks using pictures or site keys. I don&#8217;t see how that would help them with security.</p>
<p>Something that may help with security at your college is if you login from a different machine than normal it asks you a security question to make sure it&#8217;s you. I know my credit card company does that, it is annoying, but I imagine it cuts down on the trouble.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Password Aging at the College of Charleston by ace</title>
		<link>http://www.cs.cofc.edu/blog/2010/08/password-aging-at-the-college-of-charleston/comment-page-1/#comment-261</link>
		<dc:creator>ace</dc:creator>
		<pubDate>Wed, 01 Dec 2010 15:25:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.cs.cofc.edu/blog/?p=143#comment-261</guid>
		<description>Just create the strong password, remember it, don&#039;t lose it. and use virtual keyboard to prevent keylogger. It is safer eventhough very traditional.</description>
		<content:encoded><![CDATA[<p>Just create the strong password, remember it, don&#8217;t lose it. and use virtual keyboard to prevent keylogger. It is safer eventhough very traditional.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on When the educated do not compute by ace</title>
		<link>http://www.cs.cofc.edu/blog/2010/06/when-the-educated-do-not-compute/comment-page-1/#comment-260</link>
		<dc:creator>ace</dc:creator>
		<pubDate>Wed, 01 Dec 2010 15:18:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.cs.cofc.edu/blog/?p=137#comment-260</guid>
		<description>Nowadays computer is a need. Everything is covered by computer. It&#039;s time to set the mindset that technology support education to make it easier.</description>
		<content:encoded><![CDATA[<p>Nowadays computer is a need. Everything is covered by computer. It&#8217;s time to set the mindset that technology support education to make it easier.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Password Aging at the College of Charleston by Jim Bowring</title>
		<link>http://www.cs.cofc.edu/blog/2010/08/password-aging-at-the-college-of-charleston/comment-page-1/#comment-248</link>
		<dc:creator>Jim Bowring</dc:creator>
		<pubDate>Fri, 24 Sep 2010 13:06:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.cs.cofc.edu/blog/?p=143#comment-248</guid>
		<description>Issue 1:
The insertion of a meaningful-to-the-user string into an already strong password does not weaken it, in fact you can find recommendations to do so by security folks as for example: http://www.microsoft.com/protect/fraud/passwords/create.aspx .  If you don&#039;t like that, then you could insert the year as digits into your password using the Fibonacci series as indices, for example.  You could also normalize the year to 2000 etc.  Patterns get a bad rap here as patterns are at the heart of building passwords the user can remember without writing it down, which is one of the most common loss-of-security failures of password systems--plain text.  Thus, a pattern can be thought of as an algorithm or recipe that you can remember that generates your password.  Even a random password generator is an algorithm seeded by a specific value. So, at the limit, you could select a random-password generator and seed it with 2010, 2011 etc as needed to recreate your password if you forgot it.</description>
		<content:encoded><![CDATA[<p>Issue 1:<br />
The insertion of a meaningful-to-the-user string into an already strong password does not weaken it, in fact you can find recommendations to do so by security folks as for example: <a href="http://www.microsoft.com/protect/fraud/passwords/create.aspx" rel="nofollow">http://www.microsoft.com/protect/fraud/passwords/create.aspx</a> .  If you don&#8217;t like that, then you could insert the year as digits into your password using the Fibonacci series as indices, for example.  You could also normalize the year to 2000 etc.  Patterns get a bad rap here as patterns are at the heart of building passwords the user can remember without writing it down, which is one of the most common loss-of-security failures of password systems&#8211;plain text.  Thus, a pattern can be thought of as an algorithm or recipe that you can remember that generates your password.  Even a random password generator is an algorithm seeded by a specific value. So, at the limit, you could select a random-password generator and seed it with 2010, 2011 etc as needed to recreate your password if you forgot it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Password Aging at the College of Charleston by Clay McCauley</title>
		<link>http://www.cs.cofc.edu/blog/2010/08/password-aging-at-the-college-of-charleston/comment-page-1/#comment-247</link>
		<dc:creator>Clay McCauley</dc:creator>
		<pubDate>Thu, 23 Sep 2010 15:08:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.cs.cofc.edu/blog/?p=143#comment-247</guid>
		<description>You should never use regular patterns like incrementing a date, or dictionary words in your password.  These are the first things most brute-force attacks will try.  Remember, the programmers who write the attack software have thought of these things too.

If you are relying solely on a password to authenticate users, those passwords have to be changed at some interval to ensure they haven&#039;t been compromised. Choosing that interval carefully is important, but will be different depending on the community being served and the assets that need to be protected.

It&#039;s certainly true that once a keylogger has been installed, it would be able to pick up any new passwords entered while it&#039;s running.  It&#039;s not the best example, but the point was that in combination with a good anti-malware suite, that threat can be mitigated. (because the anti-malware software should detect and disable the keylogger and in many cases block it from being reintroduced)  The traditional keylogger isn&#039;t the only threat to your passwords.  Your web browser is a very useful, but highly vulnerable platform that is capable of running untrusted code from any number of sources without your knowledge or express consent.  (the recent Twitter XSS vulnerability is a good example)

Putting things in the cloud isn&#039;t a silver bullet either.  The cloud is a black box.  You don&#039;t control the security of what&#039;s running in the cloud and you have no way of verifying that the company providing the cloud services is actually secure.  Once your data is in the cloud, you just have to trust that it&#039;s being properly protected.

Imaging tools are a great benefit and time-saver, but regular re-imaging as a solution to malware is equivalent to treating the symptoms while ignoring the underlying problem.  If your system is compromised, re-imaging the system is just going to reset it to a still vulnerable, but uninfected state.  Proper application of a good, working and up-to-date anti-malware suite and keeping your OS/application software up-to-date will block the known vulnerabilities before they can be exploited.

Still, the main point of all this was user authentication.  My main point is that passwords alone may no longer be sufficient to protect anything of value.  Standard length passwords are too easy to crack and strong passwords are often too difficult to remember.  Changing them frequently mitigates some problems with compromised passwords, but also exacerbates the issue above.</description>
		<content:encoded><![CDATA[<p>You should never use regular patterns like incrementing a date, or dictionary words in your password.  These are the first things most brute-force attacks will try.  Remember, the programmers who write the attack software have thought of these things too.</p>
<p>If you are relying solely on a password to authenticate users, those passwords have to be changed at some interval to ensure they haven&#8217;t been compromised. Choosing that interval carefully is important, but will be different depending on the community being served and the assets that need to be protected.</p>
<p>It&#8217;s certainly true that once a keylogger has been installed, it would be able to pick up any new passwords entered while it&#8217;s running.  It&#8217;s not the best example, but the point was that in combination with a good anti-malware suite, that threat can be mitigated. (because the anti-malware software should detect and disable the keylogger and in many cases block it from being reintroduced)  The traditional keylogger isn&#8217;t the only threat to your passwords.  Your web browser is a very useful, but highly vulnerable platform that is capable of running untrusted code from any number of sources without your knowledge or express consent.  (the recent Twitter XSS vulnerability is a good example)</p>
<p>Putting things in the cloud isn&#8217;t a silver bullet either.  The cloud is a black box.  You don&#8217;t control the security of what&#8217;s running in the cloud and you have no way of verifying that the company providing the cloud services is actually secure.  Once your data is in the cloud, you just have to trust that it&#8217;s being properly protected.</p>
<p>Imaging tools are a great benefit and time-saver, but regular re-imaging as a solution to malware is equivalent to treating the symptoms while ignoring the underlying problem.  If your system is compromised, re-imaging the system is just going to reset it to a still vulnerable, but uninfected state.  Proper application of a good, working and up-to-date anti-malware suite and keeping your OS/application software up-to-date will block the known vulnerabilities before they can be exploited.</p>
<p>Still, the main point of all this was user authentication.  My main point is that passwords alone may no longer be sufficient to protect anything of value.  Standard length passwords are too easy to crack and strong passwords are often too difficult to remember.  Changing them frequently mitigates some problems with compromised passwords, but also exacerbates the issue above.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Password Aging at the College of Charleston by Jim Bowring</title>
		<link>http://www.cs.cofc.edu/blog/2010/08/password-aging-at-the-college-of-charleston/comment-page-1/#comment-244</link>
		<dc:creator>Jim Bowring</dc:creator>
		<pubDate>Sat, 18 Sep 2010 18:04:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.cs.cofc.edu/blog/?p=143#comment-244</guid>
		<description>Most IT organizations that i have interacted with give the user a window of a few days to a month to change their password, which seems like a good policy because it allows the user to manage the switch.  I am in favor of an annual change, which is a primary business frequency for renewals of all kinds.  

To handle keeping track of your password, you can, for example, embed the four digit year or a HEX version of it in your strong password without loss of strength and change only that part each year and still pass the new password test IT throws down.

I find the key-logger argument a poor one, as once a key-logger is installed on your machine, you are basically toast: the key-logger can also detect your new password.  If a key-logger is installed it is likely other spy-ware is installed as well.  

One big benefit of the cloud is that each client machine becomes &quot;thinner&quot;, it can be more easily be re-imaged as a routine maintenance task, thus removing stale, alien, dangerous and polluted entities.</description>
		<content:encoded><![CDATA[<p>Most IT organizations that i have interacted with give the user a window of a few days to a month to change their password, which seems like a good policy because it allows the user to manage the switch.  I am in favor of an annual change, which is a primary business frequency for renewals of all kinds.  </p>
<p>To handle keeping track of your password, you can, for example, embed the four digit year or a HEX version of it in your strong password without loss of strength and change only that part each year and still pass the new password test IT throws down.</p>
<p>I find the key-logger argument a poor one, as once a key-logger is installed on your machine, you are basically toast: the key-logger can also detect your new password.  If a key-logger is installed it is likely other spy-ware is installed as well.  </p>
<p>One big benefit of the cloud is that each client machine becomes &#8220;thinner&#8221;, it can be more easily be re-imaged as a routine maintenance task, thus removing stale, alien, dangerous and polluted entities.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

