<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-20434908.post1378296572609219831..comments</id><updated>2009-11-22T18:46:57.792+02:00</updated><title type='text'>Comments on Rational Relational: Assumption is The Mother of All Fuckups - Firefox ...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.shlomoid.com/feeds/1378296572609219831/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20434908/1378296572609219831/comments/default'/><link rel='alternate' type='text/html' href='http://blog.shlomoid.com/2008/02/assumption-is-mother-of-all-fuckups.html'/><author><name>Shlomo Priymak</name><uri>http://www.blogger.com/profile/08509735030020026930</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-20434908.post-2885170564816915332</id><published>2008-10-09T20:54:34.562+02:00</published><updated>2008-10-09T20:54:34.562+02:00</updated><title type='text'>OK, if a bad person had access to your computer, t...</title><content type='html'>OK, if a bad person had access to your computer, this would be a bad thing. Nothing new, right?&lt;BR/&gt;&lt;BR/&gt;I mean, that person could as well switch Java on and surf to a malicious website to get your PC infected (with a Trojan horse, for example), so that encryption doesn't help you anymore! &lt;BR/&gt;So why should Firefox give you the illusion your passwords were save, by encrypting them?&lt;BR/&gt;&lt;BR/&gt;When my browser tells me it "remembers" an information (like a password), then my intuition tells me, that information has to be stored somewhere and that it can be received easily. Like, your surfing history, cookies, and, by the way, ANY OTHER DATA ON YOUR HARD DRIVE can be easily read out and even manipulated in no time by anyone who has physical access to your running computer! This person could also directly infect your PC (with a Trojan horse, for example) and/or manipulate it in every possible way! To prevent this (I don't know if this is really totally possible at all) you'd have to take FAR MORE steps than simply configuring your browser right! Or, on the other hand, you could just log off from your windows session (press Windows key + L), or turn on a password protected screen saver or whatever, when you leave your running computer for a short time. This would NOT be absolutely secure, but already much more secure than encrypting your passwords!&lt;BR/&gt;&lt;BR/&gt;Encrypting your passwords could only act as a child-proof lock!&lt;BR/&gt;&lt;BR/&gt;The only real security purpose imaginable to me would be, if someone breaks into your home and accesses your computer you could prevent him/her from easily reading out your passwords, but ONLY if you realize that your PC has been accessed and immediately delete and reinstall your hole system, in order to destroy any Trojan horse!&lt;BR/&gt;But for that scenario it would make MUCH more sense to encrypt your whole hard drive (free programs for that purpose are available on the net), so again, consider password encryption to be a child-proof lock and only use it for that single purpose!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20434908/1378296572609219831/comments/default/2885170564816915332'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20434908/1378296572609219831/comments/default/2885170564816915332'/><link rel='alternate' type='text/html' href='http://blog.shlomoid.com/2008/02/assumption-is-mother-of-all-fuckups.html?showComment=1223578474562#c2885170564816915332' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.shlomoid.com/2008/02/assumption-is-mother-of-all-fuckups.html' ref='tag:blogger.com,1999:blog-20434908.post-1378296572609219831' source='http://www.blogger.com/feeds/20434908/posts/default/1378296572609219831' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-20434908.post-4853734753932874281</id><published>2008-02-23T16:47:42.579+02:00</published><updated>2008-02-23T16:47:42.579+02:00</updated><title type='text'>Yeah, I know you can do this, this is why I said "...</title><content type='html'>Yeah, I know you can do this, this is why I said "somewhat mitigated if you place a master-password over the configuration". :)&lt;BR/&gt;&lt;BR/&gt;For most users, the default configuration is the only configuration - and they assume it works a certain way, which it doesn't really.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20434908/1378296572609219831/comments/default/4853734753932874281'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20434908/1378296572609219831/comments/default/4853734753932874281'/><link rel='alternate' type='text/html' href='http://blog.shlomoid.com/2008/02/assumption-is-mother-of-all-fuckups.html?showComment=1203778062579#c4853734753932874281' title=''/><author><name>Shlomo Priymak</name><uri>http://www.blogger.com/profile/08509735030020026930</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14670563893292506590'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.shlomoid.com/2008/02/assumption-is-mother-of-all-fuckups.html' ref='tag:blogger.com,1999:blog-20434908.post-1378296572609219831' source='http://www.blogger.com/feeds/20434908/posts/default/1378296572609219831' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-20434908.post-2800138450574761973</id><published>2008-02-22T17:56:24.110+02:00</published><updated>2008-02-22T17:56:24.110+02:00</updated><title type='text'>In case you didn't know, then (since, like, foreve...</title><content type='html'>In case you didn't know, then (since, like, forever) you can set a master password on your Firefox profile and then all your sensitive details would be encrypted.&lt;BR/&gt;&lt;BR/&gt;Then, the first time a sensitive detail is needed (in a session), you're prompted for the password.&lt;BR/&gt;&lt;BR/&gt;In your Preferences, go to Security and then check Use Master Password.&lt;BR/&gt;&lt;BR/&gt;In fact, I can almost swear that the first time you're prompted to save a password and you accept that offer, you're also offered to set a master password.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20434908/1378296572609219831/comments/default/2800138450574761973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20434908/1378296572609219831/comments/default/2800138450574761973'/><link rel='alternate' type='text/html' href='http://blog.shlomoid.com/2008/02/assumption-is-mother-of-all-fuckups.html?showComment=1203695784110#c2800138450574761973' title=''/><author><name>Ilya</name><uri>http://www.blogger.com/profile/11368142121604941022</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.shlomoid.com/2008/02/assumption-is-mother-of-all-fuckups.html' ref='tag:blogger.com,1999:blog-20434908.post-1378296572609219831' source='http://www.blogger.com/feeds/20434908/posts/default/1378296572609219831' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-20434908.post-9011407944421012396</id><published>2008-02-18T19:51:52.856+02:00</published><updated>2008-02-18T19:51:52.856+02:00</updated><title type='text'>You're right, just hashing it one-way is wrong, bu...</title><content type='html'>You're right, just hashing it one-way is wrong, but it doesn't prevent the password managements system (whatever it is) to encrypt it in some form, which people assume is not easily accessible as it is here.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20434908/1378296572609219831/comments/default/9011407944421012396'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20434908/1378296572609219831/comments/default/9011407944421012396'/><link rel='alternate' type='text/html' href='http://blog.shlomoid.com/2008/02/assumption-is-mother-of-all-fuckups.html?showComment=1203357112856#c9011407944421012396' title=''/><author><name>Shlomo Priymak</name><uri>http://www.blogger.com/profile/08509735030020026930</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='14670563893292506590'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.shlomoid.com/2008/02/assumption-is-mother-of-all-fuckups.html' ref='tag:blogger.com,1999:blog-20434908.post-1378296572609219831' source='http://www.blogger.com/feeds/20434908/posts/default/1378296572609219831' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-20434908.post-4644079331610279422</id><published>2008-02-18T18:55:05.148+02:00</published><updated>2008-02-18T18:55:05.148+02:00</updated><title type='text'>This may be somewhat besides the point, but it's i...</title><content type='html'>This may be somewhat besides the point, but it's important to point out that passwords can't be saved in a encrypted or otherwise mangled fashion (i.e. hashed). This is because the passwords' plaintext must be available for use when preparing the request, be it HTTP, HTTPS or otherwise.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20434908/1378296572609219831/comments/default/4644079331610279422'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20434908/1378296572609219831/comments/default/4644079331610279422'/><link rel='alternate' type='text/html' href='http://blog.shlomoid.com/2008/02/assumption-is-mother-of-all-fuckups.html?showComment=1203353705148#c4644079331610279422' title=''/><author><name>Asaf</name><uri>http://www.blogger.com/profile/04982477020869207918</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.shlomoid.com/2008/02/assumption-is-mother-of-all-fuckups.html' ref='tag:blogger.com,1999:blog-20434908.post-1378296572609219831' source='http://www.blogger.com/feeds/20434908/posts/default/1378296572609219831' type='text/html'/></entry></feed>