<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Keeping your passwords in one place</title>
	<atom:link href="http://www.intelliot.com/blog/archives/2007/08/31/keeping-your-passwords-in-one-place/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.intelliot.com/blog/archives/2007/08/31/keeping-your-passwords-in-one-place/</link>
	<description>Thoughts, opinions and fascinating discoveries by Elliot, a student at USC</description>
	<pubDate>Sun, 06 Jul 2008 00:39:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Trevor Johns</title>
		<link>http://www.intelliot.com/blog/archives/2007/08/31/keeping-your-passwords-in-one-place/#comment-314488</link>
		<dc:creator>Trevor Johns</dc:creator>
		<pubDate>Wed, 19 Sep 2007 07:51:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.intelliot.com/blog/archives/2007/08/31/keeping-your-passwords-in-one-place/#comment-314488</guid>
		<description>First off, there's more at stake from having credentials stolen then just fraudulent purchases. A malicious user could publish libelous material in your name, access confidential documents, or use your source control privileges to introduce a backdoor into a software project. The damage from any of these things would be immeasurable, and all the federal regulations in the world won't help.

That being said, just about everybody online already "keeps all of their eggs in one basket", they just don't realize it. Because most services online allow users to retrieve or reset their password via email, once somebody's email account has been compromised, every other account online that is linked to that address should also be considered compromised.

To give credit where it's due, this was pointed out to me in a tech talk by Simon Wilson, who was using a similar argument to illustrate out why OpenID isn't any more dangerous than current sign-on systems. If you're curious, here's the video:

http://video.google.com/videoplay?docid=2288395847791059857</description>
		<content:encoded><![CDATA[<p>First off, there&#8217;s more at stake from having credentials stolen then just fraudulent purchases. A malicious user could publish libelous material in your name, access confidential documents, or use your source control privileges to introduce a backdoor into a software project. The damage from any of these things would be immeasurable, and all the federal regulations in the world won&#8217;t help.</p>
<p>That being said, just about everybody online already &#8220;keeps all of their eggs in one basket&#8221;, they just don&#8217;t realize it. Because most services online allow users to retrieve or reset their password via email, once somebody&#8217;s email account has been compromised, every other account online that is linked to that address should also be considered compromised.</p>
<p>To give credit where it&#8217;s due, this was pointed out to me in a tech talk by Simon Wilson, who was using a similar argument to illustrate out why OpenID isn&#8217;t any more dangerous than current sign-on systems. If you&#8217;re curious, here&#8217;s the video:</p>
<p><a href="http://video.google.com/videoplay?docid=2288395847791059857" rel="nofollow">http://video.google.com/videoplay?docid=2288395847791059857</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AntonEgo</title>
		<link>http://www.intelliot.com/blog/archives/2007/08/31/keeping-your-passwords-in-one-place/#comment-307572</link>
		<dc:creator>AntonEgo</dc:creator>
		<pubDate>Tue, 04 Sep 2007 16:15:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.intelliot.com/blog/archives/2007/08/31/keeping-your-passwords-in-one-place/#comment-307572</guid>
		<description>Your thinking is out of the box but basically sound. Reg E is a set of rules issued by the Federal Reserve governing electronic transactions that include online banking, ATM withdrawals and debit card payments. The bottom line is that consumers who act quickly are protected and will only be liable up to $50. Consumers must notify their bank of the fraud within 2 business days. Wait 3 days and the liability goes up to $500. And if a consumer waits more than 60 days the liability is unlimited -- but only for transactions after the 60 days has expired. Reg E rules are designed to encourage consumers to feel safe about electronic transactions. Even if a consumer has acted negligently and succumbed to a phishing attack and given away personal identification information that led to the fraud they will be protected.

So yeah -- use a service like Yodlee to stay on top of all your accounts, anytime, anywhere. Apart from the benefits of knowing where you spend your money each month, you'll know instantly if someone else is adding to your bills! And good luck to anyone trying to hack into Yodlee - check out their security section on their site.

As for the best Yodlee version to use - 2 words: Mint.com

Cheers.</description>
		<content:encoded><![CDATA[<p>Your thinking is out of the box but basically sound. Reg E is a set of rules issued by the Federal Reserve governing electronic transactions that include online banking, ATM withdrawals and debit card payments. The bottom line is that consumers who act quickly are protected and will only be liable up to $50. Consumers must notify their bank of the fraud within 2 business days. Wait 3 days and the liability goes up to $500. And if a consumer waits more than 60 days the liability is unlimited &#8212; but only for transactions after the 60 days has expired. Reg E rules are designed to encourage consumers to feel safe about electronic transactions. Even if a consumer has acted negligently and succumbed to a phishing attack and given away personal identification information that led to the fraud they will be protected.</p>
<p>So yeah &#8212; use a service like Yodlee to stay on top of all your accounts, anytime, anywhere. Apart from the benefits of knowing where you spend your money each month, you&#8217;ll know instantly if someone else is adding to your bills! And good luck to anyone trying to hack into Yodlee - check out their security section on their site.</p>
<p>As for the best Yodlee version to use - 2 words: Mint.com</p>
<p>Cheers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sam</title>
		<link>http://www.intelliot.com/blog/archives/2007/08/31/keeping-your-passwords-in-one-place/#comment-306754</link>
		<dc:creator>Sam</dc:creator>
		<pubDate>Mon, 03 Sep 2007 03:59:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.intelliot.com/blog/archives/2007/08/31/keeping-your-passwords-in-one-place/#comment-306754</guid>
		<description>Any suggestions on the best Yodlee version to use? I'm finding it difficult to register or even to know if I can register at all at the various websites that offer the service. I managed to register on Comerica, but the interface is plain and boring. The others are a mystery as to whether or not they are free or if I can register online.</description>
		<content:encoded><![CDATA[<p>Any suggestions on the best Yodlee version to use? I&#8217;m finding it difficult to register or even to know if I can register at all at the various websites that offer the service. I managed to register on Comerica, but the interface is plain and boring. The others are a mystery as to whether or not they are free or if I can register online.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
