<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Firefox Tip: Disable Password Manager</title>
	<atom:link href="http://robert.accettura.com/blog/2007/05/07/disable-password-manager/feed/" rel="self" type="application/rss+xml" />
	<link>http://robert.accettura.com/blog/2007/05/07/disable-password-manager/</link>
	<description>Robert Accettura's Personal Blog on Web Development and Tech</description>
	<pubDate>Fri, 21 Nov 2008 21:50:53 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: Tara (PassPack)</title>
		<link>http://robert.accettura.com/blog/2007/05/07/disable-password-manager/#comment-143133</link>
		<dc:creator>Tara (PassPack)</dc:creator>
		<pubDate>Thu, 31 May 2007 09:15:25 +0000</pubDate>
		<guid isPermaLink="false">http://robert.accettura.com/archives/2007/05/07/disable-password-manager/#comment-143133</guid>
		<description>@Justin
Thanks, "amply cracked" was probably too strong a choice of words. However, there was a ton of press surrounding the lack of security of Firefox's password manager - was that related to people not using the master password?

I think the idea to simplify and promote the use of the master password would be a step in the right direction, but what about flat out requiring it?

Perhaps that would help protect against tools like FirePassword which is advertised as "The Firefox Username &#38; Password List Decryptor"

I had a look at your blog - lots of exciting changes in the works, especially the porting from C   to JS. Very cool.

Cheers,
Tara</description>
		<content:encoded><![CDATA[<p>@Justin<br />
Thanks, &#8220;amply cracked&#8221; was probably too strong a choice of words. However, there was a ton of press surrounding the lack of security of Firefox&#8217;s password manager - was that related to people not using the master password?</p>
<p>I think the idea to simplify and promote the use of the master password would be a step in the right direction, but what about flat out requiring it?</p>
<p>Perhaps that would help protect against tools like FirePassword which is advertised as &#8220;The Firefox Username &amp; Password List Decryptor&#8221;</p>
<p>I had a look at your blog - lots of exciting changes in the works, especially the porting from C   to JS. Very cool.</p>
<p>Cheers,<br />
Tara</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Dolske</title>
		<link>http://robert.accettura.com/blog/2007/05/07/disable-password-manager/#comment-142587</link>
		<dc:creator>Justin Dolske</dc:creator>
		<pubDate>Fri, 25 May 2007 01:12:24 +0000</pubDate>
		<guid isPermaLink="false">http://robert.accettura.com/archives/2007/05/07/disable-password-manager/#comment-142587</guid>
		<description>Tara, that's not quite accurate...

The Firefox password manager uses 3DES to encrypt the passwords, and if you're using a master password you're secure. [Someone could steal your profile and try to brute force your master password, but if they can do that they can probably just install a keystroke sniffer or various other malware anyway.]

Firefox doesn't require you to set a master password by default, which does mean that anyone with access to your browser's configuration could access your passwords.</description>
		<content:encoded><![CDATA[<p>Tara, that&#8217;s not quite accurate&#8230;</p>
<p>The Firefox password manager uses 3DES to encrypt the passwords, and if you&#8217;re using a master password you&#8217;re secure. [Someone could steal your profile and try to brute force your master password, but if they can do that they can probably just install a keystroke sniffer or various other malware anyway.]</p>
<p>Firefox doesn&#8217;t require you to set a master password by default, which does mean that anyone with access to your browser&#8217;s configuration could access your passwords.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tara (PassPack)</title>
		<link>http://robert.accettura.com/blog/2007/05/07/disable-password-manager/#comment-142082</link>
		<dc:creator>Tara (PassPack)</dc:creator>
		<pubDate>Fri, 18 May 2007 10:15:38 +0000</pubDate>
		<guid isPermaLink="false">http://robert.accettura.com/archives/2007/05/07/disable-password-manager/#comment-142082</guid>
		<description>Sorry - I pasted in that link horribly. Here's another go:
http://passpack.wordpress.com/2007/03/09/recover-your-passwords-from-your-browser/</description>
		<content:encoded><![CDATA[<p>Sorry - I pasted in that link horribly. Here&#8217;s another go:<br />
<a href="http://passpack.wordpress.com/2007/03/09/recover-your-passwords-from-your-browser/" rel="nofollow">http://passpack.wordpress.com/.....r-browser/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tara (PassPack)</title>
		<link>http://robert.accettura.com/blog/2007/05/07/disable-password-manager/#comment-142081</link>
		<dc:creator>Tara (PassPack)</dc:creator>
		<pubDate>Fri, 18 May 2007 10:14:25 +0000</pubDate>
		<guid isPermaLink="false">http://robert.accettura.com/archives/2007/05/07/disable-password-manager/#comment-142081</guid>
		<description>It's a good idea to turn that off - the browser's built in password manager is very unsafe. They've all been amply cracked.

For those who do use their browser's password manager, you might consider turning it off. No worries, you can still recover your passwords from there: a href="http://passpack.wordpress.com/2007/03/09/recover-your-passwords-from-your-browser/"&#62; This article explains how

I run an online password manager, so that article contains a product plug. But regardless of whether or not you are interested in PassPack, it should be helpful anyway.

Cheers,
Tara Kelly</description>
		<content:encoded><![CDATA[<p>It&#8217;s a good idea to turn that off - the browser&#8217;s built in password manager is very unsafe. They&#8217;ve all been amply cracked.</p>
<p>For those who do use their browser&#8217;s password manager, you might consider turning it off. No worries, you can still recover your passwords from there: a href=&#8221;http://passpack.wordpress.com/2007/03/09/recover-your-passwords-from-your-browser/&#8221;&gt; This article explains how</p>
<p>I run an online password manager, so that article contains a product plug. But regardless of whether or not you are interested in PassPack, it should be helpful anyway.</p>
<p>Cheers,<br />
Tara Kelly</p>
]]></content:encoded>
	</item>
</channel>
</rss>
