<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Pembi's Random Ramblings</title>
	<atom:link href="http://blog.pembi.net/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.pembi.net</link>
	<description>WARNING: May contain nuts.</description>
	<lastBuildDate>Wed, 11 Jan 2012 07:04:47 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on A new toy &#8211; Nokia E90 Communicator by morgan silver</title>
		<link>http://blog.pembi.net/a-new-toy-nokia-e90-communicator/comment-page-1#comment-183</link>
		<dc:creator>morgan silver</dc:creator>
		<pubDate>Wed, 11 Jan 2012 07:04:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.pembi.net/blog/?p=46#comment-183</guid>
		<description>&lt;strong&gt;That&#039;s Right!...&lt;/strong&gt;

This is a really good blog. Good work!...</description>
		<content:encoded><![CDATA[<p><strong>That&#8217;s Right!&#8230;</strong></p>
<p>This is a really good blog. Good work!&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on eBooks? No thanks. by Ken</title>
		<link>http://blog.pembi.net/ebooks-no-thanks/comment-page-1#comment-48</link>
		<dc:creator>Ken</dc:creator>
		<pubDate>Fri, 19 Nov 2010 14:28:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pembi.net/?p=938#comment-48</guid>
		<description>Reviving this rant once again...

It is ABSOLUTELY ridiculous that Amazon charges MORE for the Kindle version of Stephen Fry&#039;s book than for the tree-killing HARDCOVER copy! http://www.amazon.co.uk/The-Fry-Chronicles/dp/B0042JTA56/ref=sr_1_9?ie=UTF8&amp;m=A3TVV12T0I6NSM&amp;s=digital-text&amp;qid=1290172185&amp;sr=1-9 Oh come ON, Amazon! You can do BETTER! 

Stephen - clobber them!</description>
		<content:encoded><![CDATA[<p>Reviving this rant once again&#8230;</p>
<p>It is ABSOLUTELY ridiculous that Amazon charges MORE for the Kindle version of Stephen Fry&#8217;s book than for the tree-killing HARDCOVER copy! <a href="http://www.amazon.co.uk/The-Fry-Chronicles/dp/B0042JTA56/ref=sr_1_9?ie=UTF8&#038;m=A3TVV12T0I6NSM&#038;s=digital-text&#038;qid=1290172185&#038;sr=1-9" rel="nofollow">http://www.amazon.co.uk/The-Fry-Chronicles/dp/B0042JTA56/ref=sr_1_9?ie=UTF8&#038;m=A3TVV12T0I6NSM&#038;s=digital-text&#038;qid=1290172185&#038;sr=1-9</a> Oh come ON, Amazon! You can do BETTER! </p>
<p>Stephen &#8211; clobber them!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on eBooks? No thanks. by Ken</title>
		<link>http://blog.pembi.net/ebooks-no-thanks/comment-page-1#comment-44</link>
		<dc:creator>Ken</dc:creator>
		<pubDate>Tue, 08 Jun 2010 18:03:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pembi.net/?p=938#comment-44</guid>
		<description>It seems I&#039;ve been a little unfair with Waterstone&#039;s. I sent them a message via their Facebook account, and got a very prompt reply, which they&#039;ve given me permission to re-publish here:

&quot;Hi Ken, as with traditional books, the RRP of each eBook title is dictated by the publisher of the eBook. Waterstone&#039;s is working with all publishers to agree what is the appropriate price for an eBook and in the meantime, we discount as many eBook titles as possible to try and offer the best possible value to our customers. A long way from perfect, we know, but hopefully there will be changes in the near future. Kate&quot;

Thanks, Kate. And Waterstone&#039;s. I appreciate the time taken to reply. And good luck in your arm-wrestling with the publishers. Unless and until the powers-that-be have a serious pricing re-think, eBooks remain an interesting idea for slightly eccentric people. And that&#039;s a great pity.</description>
		<content:encoded><![CDATA[<p>It seems I&#8217;ve been a little unfair with Waterstone&#8217;s. I sent them a message via their Facebook account, and got a very prompt reply, which they&#8217;ve given me permission to re-publish here:</p>
<p>&#8220;Hi Ken, as with traditional books, the RRP of each eBook title is dictated by the publisher of the eBook. Waterstone&#8217;s is working with all publishers to agree what is the appropriate price for an eBook and in the meantime, we discount as many eBook titles as possible to try and offer the best possible value to our customers. A long way from perfect, we know, but hopefully there will be changes in the near future. Kate&#8221;</p>
<p>Thanks, Kate. And Waterstone&#8217;s. I appreciate the time taken to reply. And good luck in your arm-wrestling with the publishers. Unless and until the powers-that-be have a serious pricing re-think, eBooks remain an interesting idea for slightly eccentric people. And that&#8217;s a great pity.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PswGen FireFox Toolbar now available! by Tweets that mention PswGen FireFox Toolbar now available! &#124; Pembi's Random Ramblings -- Topsy.com</title>
		<link>http://blog.pembi.net/pswgen-firefox-toolbar-now-available/comment-page-1#comment-36</link>
		<dc:creator>Tweets that mention PswGen FireFox Toolbar now available! &#124; Pembi's Random Ramblings -- Topsy.com</dc:creator>
		<pubDate>Tue, 19 Jan 2010 00:20:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pembi.net/?p=738#comment-36</guid>
		<description>[...] This post was mentioned on Twitter by Ken Pemberton, Casepicker. Casepicker said: RT @kenpembi: New post on http://blog.pembi.net : PswGen FireFox Toolbar now available! at http://tinyurl.com/yd4xkqe [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Ken Pemberton, Casepicker. Casepicker said: RT @kenpembi: New post on <a href="http://blog.pembi.net" rel="nofollow">http://blog.pembi.net</a> : PswGen FireFox Toolbar now available! at <a href="http://tinyurl.com/yd4xkqe" rel="nofollow">http://tinyurl.com/yd4xkqe</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Perfect Passwords &#8211; with ease by Ken</title>
		<link>http://blog.pembi.net/essentials/essential-security/pembis-perfect-passwords/comment-page-1#comment-35</link>
		<dc:creator>Ken</dc:creator>
		<pubDate>Tue, 12 Jan 2010 16:35:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pembi.net/?page_id=628#comment-35</guid>
		<description>Let me know if you have any further thoughts once you&#039;ve used it a bit? All feedback welcome!</description>
		<content:encoded><![CDATA[<p>Let me know if you have any further thoughts once you&#8217;ve used it a bit? All feedback welcome!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Perfect Passwords &#8211; with ease by thingomy.livejournal.com/</title>
		<link>http://blog.pembi.net/essentials/essential-security/pembis-perfect-passwords/comment-page-1#comment-34</link>
		<dc:creator>thingomy.livejournal.com/</dc:creator>
		<pubDate>Sat, 09 Jan 2010 11:23:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pembi.net/?page_id=628#comment-34</guid>
		<description>(note that I haven&#039;t installed it -- I&#039;ve just looked at this page and the firefox addon page so far ...)

You may want to mention the web version and the other systems on the firefox page.

BTW, having studied theoretical computer science, the concepts discussed above seem very strong indeed. The only weakness that I can see is in the key (&quot;general-purpose password and secret-number&quot;)

If a cracker knows you are using this system, they could use that to run a dictionary or other brute force attack on the key entered this would be only slightly harder than doing it for a normal password. They could also set up a fraudulent site, and use your password there to run an off-line dictionary attack and discover your key. 

As long as ONE of the following is true you are safe however: you use a secure key with sufficient entropy; noone knows or suspects that you use this system; noone is determined enough to jump through the extra couple of hoops just to attack you and other users of this system.

Definitely an interesting solution to what is a really tricky problem.</description>
		<content:encoded><![CDATA[<p>(note that I haven&#8217;t installed it &#8212; I&#8217;ve just looked at this page and the firefox addon page so far &#8230;)</p>
<p>You may want to mention the web version and the other systems on the firefox page.</p>
<p>BTW, having studied theoretical computer science, the concepts discussed above seem very strong indeed. The only weakness that I can see is in the key (&#8220;general-purpose password and secret-number&#8221;)</p>
<p>If a cracker knows you are using this system, they could use that to run a dictionary or other brute force attack on the key entered this would be only slightly harder than doing it for a normal password. They could also set up a fraudulent site, and use your password there to run an off-line dictionary attack and discover your key. </p>
<p>As long as ONE of the following is true you are safe however: you use a secure key with sufficient entropy; noone knows or suspects that you use this system; noone is determined enough to jump through the extra couple of hoops just to attack you and other users of this system.</p>
<p>Definitely an interesting solution to what is a really tricky problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PswGen for FireFox &#8211; testers wanted! by Ken</title>
		<link>http://blog.pembi.net/pswgen-for-firefox-testers-wanted/comment-page-1#comment-33</link>
		<dc:creator>Ken</dc:creator>
		<pubDate>Sat, 12 Sep 2009 08:46:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pembi.net/?p=718#comment-33</guid>
		<description>Thanks for the feedback, Ankur. I&#039;ll have a think about the popup options instead of a toolbar, that never occurred to me before. Perhaps an &quot;invisible&quot; mode, where (once you&#039;ve filled in the static fields) the toolbar disappears and (as you suggested) there is then just a small Copy-Password button on the main toolbar. Interesting! I&#039;ll have a look into that next time I have an hour to spare.

I don&#039;t quite follow your Exceptions issue, though. PswGen doesn&#039;t remember any passwords or auto-fill them for you, it only helps generate them.

Also please note that this post is pretty historical by now, PswGen has its own project page (links in the main post) which is a lot more current.

Thanks for your comments, they are appreciated.</description>
		<content:encoded><![CDATA[<p>Thanks for the feedback, Ankur. I&#8217;ll have a think about the popup options instead of a toolbar, that never occurred to me before. Perhaps an &#8220;invisible&#8221; mode, where (once you&#8217;ve filled in the static fields) the toolbar disappears and (as you suggested) there is then just a small Copy-Password button on the main toolbar. Interesting! I&#8217;ll have a look into that next time I have an hour to spare.</p>
<p>I don&#8217;t quite follow your Exceptions issue, though. PswGen doesn&#8217;t remember any passwords or auto-fill them for you, it only helps generate them.</p>
<p>Also please note that this post is pretty historical by now, PswGen has its own project page (links in the main post) which is a lot more current.</p>
<p>Thanks for your comments, they are appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PswGen for FireFox &#8211; testers wanted! by ankur.khurana1</title>
		<link>http://blog.pembi.net/pswgen-for-firefox-testers-wanted/comment-page-1#comment-32</link>
		<dc:creator>ankur.khurana1</dc:creator>
		<pubDate>Sat, 12 Sep 2009 06:36:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pembi.net/?p=718#comment-32</guid>
		<description>hmm m now trying it bro.. for sumthing i would like to say it would be better if a popup would appear instead the usual toolbar (coz i don&#039;t like toolbars) nd also add an option of Exceptions so that we might give a password to an email id nd might not end up having all our accounts locked.. i mean one email would be used to reset the password of other account then the 2nd one for the 3rd one nd like that.
also a small button should be added on the normal toolbar which would copy the password of that site onto the clipboard.well i hav not used it till now nd wil get back soon with updates.hope to hear from u soon.</description>
		<content:encoded><![CDATA[<p>hmm m now trying it bro.. for sumthing i would like to say it would be better if a popup would appear instead the usual toolbar (coz i don&#8217;t like toolbars) nd also add an option of Exceptions so that we might give a password to an email id nd might not end up having all our accounts locked.. i mean one email would be used to reset the password of other account then the 2nd one for the 3rd one nd like that.<br />
also a small button should be added on the normal toolbar which would copy the password of that site onto the clipboard.well i hav not used it till now nd wil get back soon with updates.hope to hear from u soon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PswGen Toolbar Updated by admin</title>
		<link>http://blog.pembi.net/pswgen-toolbar-updated/comment-page-1#comment-31</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Mon, 03 Aug 2009 07:50:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pembi.net/?p=741#comment-31</guid>
		<description>Yeah I&#039;m not entirely comfortable with the situation of amazon.com and amazon.co.uk having the same password, and I&#039;m not convinced I made the right decision there. But as you say, it&#039;s harmless, and does keep things tidy.

You don&#039;t have to enter the static data at the start of a session. The toolbar just quietly sits there waiting for you, feel free to ignore it! This will become clear when you start using it.

I agree with your &quot;good enough&quot; sentiment, and will consider adding to a future version.</description>
		<content:encoded><![CDATA[<p>Yeah I&#8217;m not entirely comfortable with the situation of amazon.com and amazon.co.uk having the same password, and I&#8217;m not convinced I made the right decision there. But as you say, it&#8217;s harmless, and does keep things tidy.</p>
<p>You don&#8217;t have to enter the static data at the start of a session. The toolbar just quietly sits there waiting for you, feel free to ignore it! This will become clear when you start using it.</p>
<p>I agree with your &#8220;good enough&#8221; sentiment, and will consider adding to a future version.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PswGen Toolbar Updated by city-zen.myopenid.com/</title>
		<link>http://blog.pembi.net/pswgen-toolbar-updated/comment-page-1#comment-30</link>
		<dc:creator>city-zen.myopenid.com/</dc:creator>
		<pubDate>Mon, 03 Aug 2009 03:05:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pembi.net/?p=741#comment-30</guid>
		<description>That&#039;s a sensible approach (trimming down to just the domain name without TLD), but it could lead to a slight decrease in security because the password generated for www.amazon.com will be the same as the one for www.amazon.co.uk
Probably pretty harmless, I honestly can&#039;t think of a situation where that could a problem, but it&#039;d be an exception to the feature of having different passwords for different websites.

I wasn&#039;t suggesting that the static data should persist across sessions. What I meant was that it should be entered the first time in a session where a password is required, not at the very start of the session. I think it&#039;d be an improvement in usability that wouldn&#039;t compromise security.

Finally, I think that maybe two of the three static fields (name, secret word, secret number) should be optional, and users should be warned about the security implications of using just one. I believe that it&#039;s better to have &quot;good enough&quot; security that people use 90% of the time, than having excellent security that people use 20% of the time.

Thanks for you reply and keep up the good work.</description>
		<content:encoded><![CDATA[<p>That&#8217;s a sensible approach (trimming down to just the domain name without TLD), but it could lead to a slight decrease in security because the password generated for <a href="http://www.amazon.com" rel="nofollow">http://www.amazon.com</a> will be the same as the one for <a href="http://www.amazon.co.uk" rel="nofollow">http://www.amazon.co.uk</a><br />
Probably pretty harmless, I honestly can&#8217;t think of a situation where that could a problem, but it&#8217;d be an exception to the feature of having different passwords for different websites.</p>
<p>I wasn&#8217;t suggesting that the static data should persist across sessions. What I meant was that it should be entered the first time in a session where a password is required, not at the very start of the session. I think it&#8217;d be an improvement in usability that wouldn&#8217;t compromise security.</p>
<p>Finally, I think that maybe two of the three static fields (name, secret word, secret number) should be optional, and users should be warned about the security implications of using just one. I believe that it&#8217;s better to have &#8220;good enough&#8221; security that people use 90% of the time, than having excellent security that people use 20% of the time.</p>
<p>Thanks for you reply and keep up the good work.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

