<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Talking with Marco Barulli about zero-knowledge online password management</title>
	<atom:link href="http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/</link>
	<description>Strategies for Internet citizens</description>
	<lastBuildDate>Fri, 17 Feb 2012 16:47:16 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: PacoBell</title>
		<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-131711</link>
		<dc:creator><![CDATA[PacoBell]]></dc:creator>
		<pubDate>Thu, 28 Jan 2010 20:01:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-131711</guid>
		<description><![CDATA[The only drawback to this approach is that it doesn&#039;t work for affiliate networks with differing domains (i.e. ZDnet).]]></description>
		<content:encoded><![CDATA[<p>The only drawback to this approach is that it doesn&#8217;t work for affiliate networks with differing domains (i.e. ZDnet).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clipperz and Zero-Knowledge Online Password Management - Wasif Hafeez</title>
		<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-131633</link>
		<dc:creator><![CDATA[Clipperz and Zero-Knowledge Online Password Management - Wasif Hafeez]]></dc:creator>
		<pubDate>Mon, 25 Jan 2010 11:32:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-131633</guid>
		<description><![CDATA[[...] latest in Jon Udell&#8217;s excellent podcast series is an interview with clipperz.com&#8217;s Marco Barulli about the tool and its use of zero-knowledge online password management (aka the host-proof hosting [...]]]></description>
		<content:encoded><![CDATA[<p>[...] latest in Jon Udell&#8217;s excellent podcast series is an interview with clipperz.com&#8217;s Marco Barulli about the tool and its use of zero-knowledge online password management (aka the host-proof hosting [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Crocker</title>
		<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130814</link>
		<dc:creator><![CDATA[Mark Crocker]]></dc:creator>
		<pubDate>Mon, 30 Nov 2009 19:18:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130814</guid>
		<description><![CDATA[A much slicker and easier to use JavaScript bookmarklet that will generate a hashed password is SuperGenPass (http://supergenpass.com/).  

SuperGenPass doesn&#039;t just hash the site address, but combines it with your personal password, so each site can have a unique password and you only have to remember a single password.  It&#039;s also portable, so as long as you have the bookmarklet on all of your browsers, it works everywhere without having to store any information other than the core password that you need to remember.]]></description>
		<content:encoded><![CDATA[<p>A much slicker and easier to use JavaScript bookmarklet that will generate a hashed password is SuperGenPass (<a href="http://supergenpass.com/" rel="nofollow">http://supergenpass.com/</a>).  </p>
<p>SuperGenPass doesn&#8217;t just hash the site address, but combines it with your personal password, so each site can have a unique password and you only have to remember a single password.  It&#8217;s also portable, so as long as you have the bookmarklet on all of your browsers, it works everywhere without having to store any information other than the core password that you need to remember.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chaim Krause</title>
		<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130683</link>
		<dc:creator><![CDATA[Chaim Krause]]></dc:creator>
		<pubDate>Fri, 06 Nov 2009 19:03:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130683</guid>
		<description><![CDATA[LOL. I just told Passpack to go talk to Passpack.

Hey Jon! You need to meet &lt;a href=&quot;http://jonudell.net/bio.html&quot; rel=&quot;nofollow&quot;&gt;this guy&lt;/a&gt;.]]></description>
		<content:encoded><![CDATA[<p>LOL. I just told Passpack to go talk to Passpack.</p>
<p>Hey Jon! You need to meet <a href="http://jonudell.net/bio.html" rel="nofollow">this guy</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chaim Krause</title>
		<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130681</link>
		<dc:creator><![CDATA[Chaim Krause]]></dc:creator>
		<pubDate>Fri, 06 Nov 2009 17:07:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130681</guid>
		<description><![CDATA[Please contact Passpack.com. I am just a customer, but I think they would be open to promoting a standard. I will point them here. Maybe also contact the developers of RoboForm. They would have a vested interest as well as promoting a standard.]]></description>
		<content:encoded><![CDATA[<p>Please contact Passpack.com. I am just a customer, but I think they would be open to promoting a standard. I will point them here. Maybe also contact the developers of RoboForm. They would have a vested interest as well as promoting a standard.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Francesco Sullo</title>
		<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130680</link>
		<dc:creator><![CDATA[Francesco Sullo]]></dc:creator>
		<pubDate>Fri, 06 Nov 2009 15:54:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130680</guid>
		<description><![CDATA[I proposed to Marco to work together on a password microformat definition in early 2007. He and Giulio Cesare didn&#039;t like the proposal, so it remained an idea. I recently reprised it and I am working on a RDF approach. If someone is interested, let me know.]]></description>
		<content:encoded><![CDATA[<p>I proposed to Marco to work together on a password microformat definition in early 2007. He and Giulio Cesare didn&#8217;t like the proposal, so it remained an idea. I recently reprised it and I am working on a RDF approach. If someone is interested, let me know.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marco Baruli</title>
		<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130679</link>
		<dc:creator><![CDATA[Marco Baruli]]></dc:creator>
		<pubDate>Fri, 06 Nov 2009 14:41:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130679</guid>
		<description><![CDATA[@foo

Hi, you can definitely install and run Clipperz on your own web server. You just need to download Clipperz Community Edition (AGPL license) and a PHP/MySQL box.

Thanks!]]></description>
		<content:encoded><![CDATA[<p>@foo</p>
<p>Hi, you can definitely install and run Clipperz on your own web server. You just need to download Clipperz Community Edition (AGPL license) and a PHP/MySQL box.</p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: foo</title>
		<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130674</link>
		<dc:creator><![CDATA[foo]]></dc:creator>
		<pubDate>Fri, 06 Nov 2009 05:48:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130674</guid>
		<description><![CDATA[*douh* silly me. I first should read the clipperz website]]></description>
		<content:encoded><![CDATA[<p>*douh* silly me. I first should read the clipperz website</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: foo</title>
		<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130673</link>
		<dc:creator><![CDATA[foo]]></dc:creator>
		<pubDate>Fri, 06 Nov 2009 05:34:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130673</guid>
		<description><![CDATA[Seriously: Why on earth should I put my sensitive passwords (and here even all in &quot;one bunch&quot;) into a web application that is not under my own control?

Don&#039;t get me wrong: The idea of a distributed password manager is great! But this thing has to be open source so that the users can put them on their own webservers.

One comment about the feature &quot;Anonymity&quot;:
Yea, sure. Of course the operator of &quot;clipperz&quot; does not need any personal information when users want to register: He gets them &quot;delivered free&quot;, as soon as the user puts the first passwords into &quot;clipperz&quot;.

As Bruce Schneier once said in one of his Crypto-Gram&#039;s:

&quot;In the cryptography world, we consider open source necessary for good security; we have for decades. Public security is always more secure than proprietary security&quot;

And this was already 10 years ago: http://www.schneier.com/crypto-gram-9909.html]]></description>
		<content:encoded><![CDATA[<p>Seriously: Why on earth should I put my sensitive passwords (and here even all in &#8220;one bunch&#8221;) into a web application that is not under my own control?</p>
<p>Don&#8217;t get me wrong: The idea of a distributed password manager is great! But this thing has to be open source so that the users can put them on their own webservers.</p>
<p>One comment about the feature &#8220;Anonymity&#8221;:<br />
Yea, sure. Of course the operator of &#8220;clipperz&#8221; does not need any personal information when users want to register: He gets them &#8220;delivered free&#8221;, as soon as the user puts the first passwords into &#8220;clipperz&#8221;.</p>
<p>As Bruce Schneier once said in one of his Crypto-Gram&#8217;s:</p>
<p>&#8220;In the cryptography world, we consider open source necessary for good security; we have for decades. Public security is always more secure than proprietary security&#8221;</p>
<p>And this was already 10 years ago: <a href="http://www.schneier.com/crypto-gram-9909.html" rel="nofollow">http://www.schneier.com/crypto-gram-9909.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clipperz and Zero-Knowledge Online Password Management &#124; Buddy's Blog</title>
		<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130670</link>
		<dc:creator><![CDATA[Clipperz and Zero-Knowledge Online Password Management &#124; Buddy's Blog]]></dc:creator>
		<pubDate>Thu, 05 Nov 2009 23:59:58 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130670</guid>
		<description><![CDATA[[...] latest in Jon Udell&#8217;s excellent podcast series is an interview with clipperz.com&#8217;s Maro Barulli about the tool and its use of zero-knowledge online password management (aka the host-proof hosting [...]]]></description>
		<content:encoded><![CDATA[<p>[...] latest in Jon Udell&#8217;s excellent podcast series is an interview with clipperz.com&#8217;s Maro Barulli about the tool and its use of zero-knowledge online password management (aka the host-proof hosting [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ajaxian &#187; Clipperz and Zero-Knowledge Online Password Management</title>
		<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130669</link>
		<dc:creator><![CDATA[Ajaxian &#187; Clipperz and Zero-Knowledge Online Password Management]]></dc:creator>
		<pubDate>Thu, 05 Nov 2009 23:17:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130669</guid>
		<description><![CDATA[[...] latest in Jon Udell&#8217;s excellent podcast series is an interview with clipperz.com&#8217;s Maro Barulli about the tool and its use of zero-knowledge online password management (aka the host-proof hosting [...]]]></description>
		<content:encoded><![CDATA[<p>[...] latest in Jon Udell&#8217;s excellent podcast series is an interview with clipperz.com&#8217;s Maro Barulli about the tool and its use of zero-knowledge online password management (aka the host-proof hosting [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: EBR</title>
		<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130647</link>
		<dc:creator><![CDATA[EBR]]></dc:creator>
		<pubDate>Thu, 05 Nov 2009 04:06:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130647</guid>
		<description><![CDATA[i&#039;m going to give a few a try. right now i&#039;m using sxipper for firefox but need a real app for protection and auto generation of passwords.]]></description>
		<content:encoded><![CDATA[<p>i&#8217;m going to give a few a try. right now i&#8217;m using sxipper for firefox but need a real app for protection and auto generation of passwords.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sim</title>
		<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130641</link>
		<dc:creator><![CDATA[Sim]]></dc:creator>
		<pubDate>Thu, 05 Nov 2009 02:49:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130641</guid>
		<description><![CDATA[LastPass also has a One Time password options along with Virtual Keyboards for kiosks and borrowed machines. However it looks like the One Time Passwords are generated for you.]]></description>
		<content:encoded><![CDATA[<p>LastPass also has a One Time password options along with Virtual Keyboards for kiosks and borrowed machines. However it looks like the One Time Passwords are generated for you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Udell</title>
		<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130635</link>
		<dc:creator><![CDATA[Jon Udell]]></dc:creator>
		<pubDate>Wed, 04 Nov 2009 18:27:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130635</guid>
		<description><![CDATA[&lt;i&gt;LastPass&lt;/i&gt;

It sounds like you use it to synch across a set of machines, and that the only missing piece is the kiosk or borrowed machine scenario?]]></description>
		<content:encoded><![CDATA[<p><i>LastPass</i></p>
<p>It sounds like you use it to synch across a set of machines, and that the only missing piece is the kiosk or borrowed machine scenario?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Udell</title>
		<link>http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130634</link>
		<dc:creator><![CDATA[Jon Udell]]></dc:creator>
		<pubDate>Wed, 04 Nov 2009 18:21:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2009/11/02/talking-with-marco-barulli-about-zero-knowledge-online-password-management/#comment-130634</guid>
		<description><![CDATA[&lt;i&gt;how this compares to Sxipper&lt;/i&gt;

Sxipper&#039;s still a Firefox plug-in only, right? Clipperz is a browser-independent JavaScript app.]]></description>
		<content:encoded><![CDATA[<p><i>how this compares to Sxipper</i></p>
<p>Sxipper&#8217;s still a Firefox plug-in only, right? Clipperz is a browser-independent JavaScript app.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

