<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: American Express&#8217;s Security Problem: Awful password system</title>
	<atom:link href="http://danwin.com/thoughts/american-expresss-security-problem-awful-password-system/feed/" rel="self" type="application/rss+xml" />
	<link>http://danwin.com/thoughts/american-expresss-security-problem-awful-password-system/</link>
	<description>The &#039;g&#039; is mostly silent</description>
	<lastBuildDate>Fri, 03 Sep 2010 22:32:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: Steve Jones</title>
		<link>http://danwin.com/thoughts/american-expresss-security-problem-awful-password-system/comment-page-1/#comment-304</link>
		<dc:creator>Steve Jones</dc:creator>
		<pubDate>Tue, 23 Mar 2010 09:48:58 +0000</pubDate>
		<guid isPermaLink="false">http://danwin.com/?p=330#comment-304</guid>
		<description>I just complained to AMEX about their password policy, they stated they are &quot;unable&quot; to change it! Have the got an amateur coder or something? I am forced to either write my password down, or use an unsecure easy to remember one because they wont allow me to use a secure password that I DO remember.</description>
		<content:encoded><![CDATA[<p>I just complained to AMEX about their password policy, they stated they are &#8220;unable&#8221; to change it! Have the got an amateur coder or something? I am forced to either write my password down, or use an unsecure easy to remember one because they wont allow me to use a secure password that I DO remember.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Taylor</title>
		<link>http://danwin.com/thoughts/american-expresss-security-problem-awful-password-system/comment-page-1/#comment-189</link>
		<dc:creator>Andrew Taylor</dc:creator>
		<pubDate>Wed, 10 Feb 2010 13:59:04 +0000</pubDate>
		<guid isPermaLink="false">http://danwin.com/?p=330#comment-189</guid>
		<description>See their &quot;explanation&quot; at http://blogs.pcmag.com/securitywatch/2010/02/amex_password_policies_declare.php</description>
		<content:encoded><![CDATA[<p>See their &#8220;explanation&#8221; at <a href="http://blogs.pcmag.com/securitywatch/2010/02/amex_password_policies_declare.php" rel="nofollow">http://blogs.pcmag.com/securitywatch/2010/02/amex_password_policies_declare.php</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tweets that mention American Express’s Security Problem: Awful password system &#124; Danwin: Dan Nguyen, in short -- Topsy.com</title>
		<link>http://danwin.com/thoughts/american-expresss-security-problem-awful-password-system/comment-page-1/#comment-109</link>
		<dc:creator>Tweets that mention American Express’s Security Problem: Awful password system &#124; Danwin: Dan Nguyen, in short -- Topsy.com</dc:creator>
		<pubDate>Sun, 24 Jan 2010 22:49:25 +0000</pubDate>
		<guid isPermaLink="false">http://danwin.com/?p=330#comment-109</guid>
		<description>[...] This post was mentioned on Twitter by Chris Eng, Dan Nguyen and Marqueue, Rijo Thomas. Rijo Thomas said: NYTimes had a story today about a man who accidentally was able to log into a stranger&#039;s… http://goo.gl/fb/VKD2 [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Chris Eng, Dan Nguyen and Marqueue, Rijo Thomas. Rijo Thomas said: NYTimes had a story today about a man who accidentally was able to log into a stranger&#39;s… <a href="http://goo.gl/fb/VKD2" rel="nofollow">http://goo.gl/fb/VKD2</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: American Express&#39;s Security Problem: Awful password system &#8230; &#124; Drakz Free Online Service</title>
		<link>http://danwin.com/thoughts/american-expresss-security-problem-awful-password-system/comment-page-1/#comment-107</link>
		<dc:creator>American Express&#39;s Security Problem: Awful password system &#8230; &#124; Drakz Free Online Service</dc:creator>
		<pubDate>Sun, 24 Jan 2010 05:05:12 +0000</pubDate>
		<guid isPermaLink="false">http://danwin.com/?p=330#comment-107</guid>
		<description>[...] from: American Express&#039;s Security Problem: Awful password system &#8230;   Share and [...]</description>
		<content:encoded><![CDATA[<p>[...] from: American Express&#39;s Security Problem: Awful password system &#8230;   Share and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Human</title>
		<link>http://danwin.com/thoughts/american-expresss-security-problem-awful-password-system/comment-page-1/#comment-106</link>
		<dc:creator>Tom Human</dc:creator>
		<pubDate>Sun, 24 Jan 2010 04:12:59 +0000</pubDate>
		<guid isPermaLink="false">http://danwin.com/?p=330#comment-106</guid>
		<description>Why do you believe that a concatenation of dictionary words isn&#039;t secure?

If you have a 100,000 word dictionary, then there are 10 billion choices of two words, a quadrillion choices of three words.  What dictionary attack will get a password like that?

Plenty of places have stupid passwords.  A Major Brokerage Firm uses 6-8 characters, lower case, no punctuation, must contain a number, and that number can&#039;t be at the start or end of the password.  That rule is so restrictive it&#039;s almost impossible to come up with a password at all!</description>
		<content:encoded><![CDATA[<p>Why do you believe that a concatenation of dictionary words isn&#8217;t secure?</p>
<p>If you have a 100,000 word dictionary, then there are 10 billion choices of two words, a quadrillion choices of three words.  What dictionary attack will get a password like that?</p>
<p>Plenty of places have stupid passwords.  A Major Brokerage Firm uses 6-8 characters, lower case, no punctuation, must contain a number, and that number can&#8217;t be at the start or end of the password.  That rule is so restrictive it&#8217;s almost impossible to come up with a password at all!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: uberVU - social comments</title>
		<link>http://danwin.com/thoughts/american-expresss-security-problem-awful-password-system/comment-page-1/#comment-105</link>
		<dc:creator>uberVU - social comments</dc:creator>
		<pubDate>Sun, 24 Jan 2010 02:31:43 +0000</pubDate>
		<guid isPermaLink="false">http://danwin.com/?p=330#comment-105</guid>
		<description>&lt;strong&gt;Social comments and analytics for this post...&lt;/strong&gt;

This post was mentioned on Twitter by dancow: NYT re: accidental breach of AmEx account. No surprise, AmEx password limit is 8 case-insensitive alphanumerics http://bit.ly/8mvaUw...</description>
		<content:encoded><![CDATA[<p><strong>Social comments and analytics for this post&#8230;</strong></p>
<p>This post was mentioned on Twitter by dancow: NYT re: accidental breach of AmEx account. No surprise, AmEx password limit is 8 case-insensitive alphanumerics <a href="http://bit.ly/8mvaUw.." rel="nofollow">http://bit.ly/8mvaUw..</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Computer, Electronic, and Freeware</title>
		<link>http://danwin.com/thoughts/american-expresss-security-problem-awful-password-system/comment-page-1/#comment-103</link>
		<dc:creator>Computer, Electronic, and Freeware</dc:creator>
		<pubDate>Sun, 24 Jan 2010 00:20:26 +0000</pubDate>
		<guid isPermaLink="false">http://danwin.com/?p=330#comment-103</guid>
		<description>[...] American Express&#039;s Security Problem: Awful password system &#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] American Express&#39;s Security Problem: Awful password system &#8230; [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
