<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Password Searching as a service</title>
	<atom:link href="http://www.timnash.co.uk/10/2009/password-searching-as-a-service/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.timnash.co.uk/10/2009/password-searching-as-a-service/</link>
	<description>The Stuff Consultant</description>
	<lastBuildDate>Tue, 07 May 2013 14:50:53 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Tim Nash</title>
		<link>http://www.timnash.co.uk/10/2009/password-searching-as-a-service/comment-page-1/#comment-3121</link>
		<dc:creator>Tim Nash</dc:creator>
		<pubDate>Wed, 07 Oct 2009 09:44:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.timnash.co.uk/?p=405#comment-3121</guid>
		<description><![CDATA[but would you trust a service that just returned the data you provided?
I think for it to work and to shock people into doing something it needs to return the password or something the user didn&#039;t give you. Though you would still need to read the list so would still be having the same problem.

Unless you simply return positive everytime and never read the list of course ;)

The issue is less with what data is returned but more by reading the data in the first place.]]></description>
		<content:encoded><![CDATA[<p>but would you trust a service that just returned the data you provided?<br />
I think for it to work and to shock people into doing something it needs to return the password or something the user didn&#8217;t give you. Though you would still need to read the list so would still be having the same problem.</p>
<p>Unless you simply return positive everytime and never read the list of course <img src='http://www.timnash.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>The issue is less with what data is returned but more by reading the data in the first place.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joff</title>
		<link>http://www.timnash.co.uk/10/2009/password-searching-as-a-service/comment-page-1/#comment-3120</link>
		<dc:creator>Joff</dc:creator>
		<pubDate>Wed, 07 Oct 2009 09:39:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.timnash.co.uk/?p=405#comment-3120</guid>
		<description><![CDATA[Do you need to search the passwords at all?  If there&#039;s a list of emails and passwords, then just return whether the email is in the list.

I can&#039;t see that being on the wrong side of the law.]]></description>
		<content:encoded><![CDATA[<p>Do you need to search the passwords at all?  If there&#8217;s a list of emails and passwords, then just return whether the email is in the list.</p>
<p>I can&#8217;t see that being on the wrong side of the law.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Nash</title>
		<link>http://www.timnash.co.uk/10/2009/password-searching-as-a-service/comment-page-1/#comment-3119</link>
		<dc:creator>Tim Nash</dc:creator>
		<pubDate>Wed, 07 Oct 2009 09:30:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.timnash.co.uk/?p=405#comment-3119</guid>
		<description><![CDATA[Problem is the service would knowing be opening and reading &quot;stolen&quot; passwords and there would be no way to not open and read other peoples passwords while processing the html file. So while you might have the permission of one person you don&#039;t of the rest.]]></description>
		<content:encoded><![CDATA[<p>Problem is the service would knowing be opening and reading &#8220;stolen&#8221; passwords and there would be no way to not open and read other peoples passwords while processing the html file. So while you might have the permission of one person you don&#8217;t of the rest.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Glen Allsopp</title>
		<link>http://www.timnash.co.uk/10/2009/password-searching-as-a-service/comment-page-1/#comment-3115</link>
		<dc:creator>Glen Allsopp</dc:creator>
		<pubDate>Tue, 06 Oct 2009 19:42:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.timnash.co.uk/?p=405#comment-3115</guid>
		<description><![CDATA[I personally think it would be a cool idea Tim, although depending on who long it takes to make, people may have recitified the situation by the time the tool comes out?

I&#039;m pretty sure it would be legal, just put a handy T&amp;C in there to be safe :)

- Glen]]></description>
		<content:encoded><![CDATA[<p>I personally think it would be a cool idea Tim, although depending on who long it takes to make, people may have recitified the situation by the time the tool comes out?</p>
<p>I&#8217;m pretty sure it would be legal, just put a handy T&amp;C in there to be safe <img src='http://www.timnash.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>- Glen</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Nash</title>
		<link>http://www.timnash.co.uk/10/2009/password-searching-as-a-service/comment-page-1/#comment-3114</link>
		<dc:creator>Tim Nash</dc:creator>
		<pubDate>Tue, 06 Oct 2009 18:28:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.timnash.co.uk/?p=405#comment-3114</guid>
		<description><![CDATA[Actually doing the rounds on the web and on many websites right now are tens of thousands of passwords got in the latest phishing attempt,
http://news.bbc.co.uk/1/hi/technology/8292928.stm
It took about 2 minutes and only a smidgeon of logical thinking to find a dozen or so sites with the passwords and being indexed in part by Google.

the issue which I should have put up, is that to &quot;find the users specific password&quot; the app would need to open and read the page containing the passwords and extract data.

Since the data is &quot;stolen&quot; you would have in effect be a accessory to the theft, even linking to it is a grey area you may remember TVLinks sites problem.]]></description>
		<content:encoded><![CDATA[<p>Actually doing the rounds on the web and on many websites right now are tens of thousands of passwords got in the latest phishing attempt,<br />
<a href="http://news.bbc.co.uk/1/hi/technology/8292928.stm" rel="nofollow">http://news.bbc.co.uk/1/hi/technology/8292928.stm</a><br />
It took about 2 minutes and only a smidgeon of logical thinking to find a dozen or so sites with the passwords and being indexed in part by Google.</p>
<p>the issue which I should have put up, is that to &#8220;find the users specific password&#8221; the app would need to open and read the page containing the passwords and extract data.</p>
<p>Since the data is &#8220;stolen&#8221; you would have in effect be a accessory to the theft, even linking to it is a grey area you may remember TVLinks sites problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe Hall</title>
		<link>http://www.timnash.co.uk/10/2009/password-searching-as-a-service/comment-page-1/#comment-3113</link>
		<dc:creator>Joe Hall</dc:creator>
		<pubDate>Tue, 06 Oct 2009 18:21:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.timnash.co.uk/?p=405#comment-3113</guid>
		<description><![CDATA[I don&#039;t think it would be illegal because it would be an opt in service with registration. But, more importantly, I don&#039;t think it would work. Most folks that pass around hacked email/passwords don&#039;t do it publicly. They mostly stay on their IRC channels or closed news groups. I think the big area where you might have some luck would be a few of the forums, but like I said not many divulge their data on there, just talk about it.]]></description>
		<content:encoded><![CDATA[<p>I don&#8217;t think it would be illegal because it would be an opt in service with registration. But, more importantly, I don&#8217;t think it would work. Most folks that pass around hacked email/passwords don&#8217;t do it publicly. They mostly stay on their IRC channels or closed news groups. I think the big area where you might have some luck would be a few of the forums, but like I said not many divulge their data on there, just talk about it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
