<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: A clever little trick to protect your passwords.</title>
	<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords/</link>
	<description>Comments on MetaFilter post A clever little trick to protect your passwords.</description>
	<pubDate>Thu, 23 Nov 2006 10:58:11 -0800</pubDate>
	<lastBuildDate>Thu, 23 Nov 2006 10:58:11 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>A clever little trick to protect your passwords.</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords</link>	
		<description>How to log in from an internet caf&amp;eacute; &lt;a href=&quot;http://www.astalavista.com/index.php?section=directory&amp;cmd=detail&amp;id=7492&quot;&gt;without worrying about keyloggers.&lt;/a&gt;   (.pdf)</description>
		<guid isPermaLink="false">post:www.metafilter.com,2006:site.56479</guid>
		<pubDate>Thu, 23 Nov 2006 10:57:11 -0800</pubDate>
		<dc:creator>weapons-grade pandemonium</dc:creator>		<category>KeyLogger</category>		<category>Password</category>		<category>Passswords</category>		<category>PasswordProtection</category>		<category>Hack</category>
	</item>	<item>
		<title>By: weapons-grade pandemonium</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503301</link>	
		<description>The link goes to Astalavista; To read the article, click on the .pdf abstract
In a nutshell--the keylogger registers everything typed; your browser only recognizes characters typed into the text entry fields.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503301</guid>
		<pubDate>Thu, 23 Nov 2006 10:58:11 -0800</pubDate>
		<dc:creator>weapons-grade pandemonium</dc:creator>
	</item>	<item>
		<title>By: casconed</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503305</link>	
		<description>i&apos;m still worried.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503305</guid>
		<pubDate>Thu, 23 Nov 2006 11:06:20 -0800</pubDate>
		<dc:creator>casconed</dc:creator>
	</item>	<item>
		<title>By: delmoi</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503307</link>	
		<description>&lt;a href=&quot;http://cups.cs.cmu.edu/soups/2006/posters/herley-poster_abstract.pdf&quot;&gt;here is the PDF&lt;/a&gt;, which you can read without clicking through a pop-up ridden &apos;haxor&apos; site. 

The technique:
&lt;code&gt;
Navigate to the login page desired;
Type in the userid;
for (each pwd character){
  Give focus to anywhere but the pwd field;
  Type some random characters;
  Give focus to the pwd field;
  Type the next character of the pwd
}
Submit;&lt;/code&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503307</guid>
		<pubDate>Thu, 23 Nov 2006 11:09:13 -0800</pubDate>
		<dc:creator>delmoi</dc:creator>
	</item>	<item>
		<title>By: aubilenon</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503308</link>	
		<description>That&apos;s clever.  But this isn&apos;t that tough.  You can also use charmap to type your password.  Or build it out of letters copied and pasted from metafilter.  Or any number of ways that would take equally sophisticated logging to beat.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503308</guid>
		<pubDate>Thu, 23 Nov 2006 11:09:48 -0800</pubDate>
		<dc:creator>aubilenon</dc:creator>
	</item>	<item>
		<title>By: CheeseburgerBrown</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503309</link>	
		<description>W49ow56, th454at&apos;s a really5 ne4at, simpleQ tri659ck!  Th840IEWZls, MeFi7!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503309</guid>
		<pubDate>Thu, 23 Nov 2006 11:12:22 -0800</pubDate>
		<dc:creator>CheeseburgerBrown</dc:creator>
	</item>	<item>
		<title>By: George_Spiggott</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503310</link>	
		<description>The trouble with this technique is that the keylogger still gets all your credentials, just with quasirandom characters mixed in.  

In the rare occasion I&apos;ve used one of those computers for something I had to log into, I&apos;ve been known to copy-and-paste my credentials into the field one character at a time from other text sources.  That&apos;s an improvement on this in that you never type any of the characters of your credentials, though it is a little slow.

The other problem is that keyloggers are not the only form of spyware that a business in control of the machine can install. I&apos;ve written extensions for IE as well as wrappers for the IE control and I know how easy it is; it would barely be the work of an afternoon to create something that looked indistinguishable from off-the-rack IE but captured everything that was typed into it, by any means.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503310</guid>
		<pubDate>Thu, 23 Nov 2006 11:13:34 -0800</pubDate>
		<dc:creator>George_Spiggott</dc:creator>
	</item>	<item>
		<title>By: Jairus</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503316</link>	
		<description>Modern keyloggers log all clipboard actions.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503316</guid>
		<pubDate>Thu, 23 Nov 2006 11:25:50 -0800</pubDate>
		<dc:creator>Jairus</dc:creator>
	</item>	<item>
		<title>By: weapons-grade pandemonium</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503319</link>	
		<description>Has anyone come up with a dynamic password system, i.e., a password that changes each time, according to an algorithm which both the user and website recognize? It would be more difficult to hack an algorithm than a static password.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503319</guid>
		<pubDate>Thu, 23 Nov 2006 11:29:43 -0800</pubDate>
		<dc:creator>weapons-grade pandemonium</dc:creator>
	</item>	<item>
		<title>By: edd</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503320</link>	
		<description>I&apos;ve heard some keyloggers record the clipboard too, so copying and pasting one character at a time might still be insecure.

Personally I wouldn&apos;t trust a machine that might have a keylogger unless I could stick in a LiveCD and run from that.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503320</guid>
		<pubDate>Thu, 23 Nov 2006 11:31:31 -0800</pubDate>
		<dc:creator>edd</dc:creator>
	</item>	<item>
		<title>By: chunking express</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503322</link>	
		<description>&lt;a href=&quot;http://www.rsasecurity.com/node.asp?id=1311&quot;&gt;wgp, check out the RSA key fob.&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503322</guid>
		<pubDate>Thu, 23 Nov 2006 11:33:40 -0800</pubDate>
		<dc:creator>chunking express</dc:creator>
	</item>	<item>
		<title>By: delmoi</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503324</link>	
		<description>I&apos;ve always thought the thing to do would be to replace typed password fields with &apos;graphical character selectors&apos; like those found in video games.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503324</guid>
		<pubDate>Thu, 23 Nov 2006 11:36:07 -0800</pubDate>
		<dc:creator>delmoi</dc:creator>
	</item>	<item>
		<title>By: jon_kill</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503327</link>	
		<description>This won&apos;t work forever. They can just gather per-window keylogging instead. Every window (a handle is readily available) could be given its own output.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503327</guid>
		<pubDate>Thu, 23 Nov 2006 11:38:32 -0800</pubDate>
		<dc:creator>jon_kill</dc:creator>
	</item>	<item>
		<title>By: weapons-grade pandemonium</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503328</link>	
		<description>Cool RSA fob, chunking express.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503328</guid>
		<pubDate>Thu, 23 Nov 2006 11:41:45 -0800</pubDate>
		<dc:creator>weapons-grade pandemonium</dc:creator>
	</item>	<item>
		<title>By: dminor</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503337</link>	
		<description>I think &lt;a href=&quot;http://rutgersscholar.rutgers.edu/volume04/sobrbirg/sobrbirg.htm&quot;&gt;this rules&lt;/a&gt; as far as log in authentication schemes go..</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503337</guid>
		<pubDate>Thu, 23 Nov 2006 11:55:30 -0800</pubDate>
		<dc:creator>dminor</dc:creator>
	</item>	<item>
		<title>By: boo_radley</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503341</link>	
		<description>Maple story ( a free MMO side scroller game) had such a huge problem with keyloggers that they instituted a PIN that&apos;s set up when your game account is created. When you sign in, you type your password as normal, but the PIN gets entered on an onscreen keyboard that randomly maps numbers to various keys. It was just a short time after this innovation that the MS keylogger started taking screenshots as well. Ain&apos;t nothin&apos; safe.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503341</guid>
		<pubDate>Thu, 23 Nov 2006 12:05:29 -0800</pubDate>
		<dc:creator>boo_radley</dc:creator>
	</item>	<item>
		<title>By: drjimmy11</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503346</link>	
		<description>This is definitely a major issue to be concerned about. I see a lot of internet cafes opening in my neighborhood. They claim to be small businessmen wanting to set up roots in the community, but I know as soon as they get their hands on my gmail password, they&apos;ll pack it up in the night and run for Mexico!

Seriously, all these methods seem pretty good, but if you are that security-conscious, maybe just change your password after every login at a non-safe computer?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503346</guid>
		<pubDate>Thu, 23 Nov 2006 12:11:39 -0800</pubDate>
		<dc:creator>drjimmy11</dc:creator>
	</item>	<item>
		<title>By: signal</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503353</link>	
		<description>AskMe &lt;a href=&quot;http://ask.metafilter.com/mefi/27750&quot;&gt;question &lt;/a&gt;on this.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503353</guid>
		<pubDate>Thu, 23 Nov 2006 12:19:20 -0800</pubDate>
		<dc:creator>signal</dc:creator>
	</item>	<item>
		<title>By: aubilenon</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503354</link>	
		<description>boo_radley: oh, ING direct does the same thing with their PIN</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503354</guid>
		<pubDate>Thu, 23 Nov 2006 12:20:21 -0800</pubDate>
		<dc:creator>aubilenon</dc:creator>
	</item>	<item>
		<title>By: wumpus</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503367</link>	
		<description>what I do is just bring a heavy lead pipe with me to the internet cafe, and bash whatever computer i was just using into pieces before i leave</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503367</guid>
		<pubDate>Thu, 23 Nov 2006 12:51:10 -0800</pubDate>
		<dc:creator>wumpus</dc:creator>
	</item>	<item>
		<title>By: blag</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503406</link>	
		<description>A recent AskMe lead me to &lt;a href=&quot;http://boothbox.sourceforge.net/features.html&quot;&gt;Boothbox&lt;/a&gt;, a live CD containing nothing but Firefox - if more internet cafes switched over to this i) users would be a lot more secure and ii) the cafe admins would have much less work to do. Worried about keyloggers? Simply reboot between users.

Graphical logins (and kitten authorisation) also fascinate me.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503406</guid>
		<pubDate>Thu, 23 Nov 2006 14:07:57 -0800</pubDate>
		<dc:creator>blag</dc:creator>
	</item>	<item>
		<title>By: fings</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503421</link>	
		<description>Live CDs do nothing to protect against hardware keyloggers like &lt;a href=&quot;http://www.keyghost.com/&quot;&gt;keyghost&lt;/a&gt;.

And this technique of changing focus won&apos;t help much against keyloggers that log mouse-clicks.  The log will have something like: &quot;asdf&amp;lt;click&amp;gt;pa&amp;lt;click&amp;gt;fdsa&amp;lt;click&amp;gt;s&amp;lt;click&amp;gt;qewr&amp;lt;alt-tab&amp;gt;sw&amp;lt;click&amp;gt;b34&amp;lt;click&amp;gt;ord&quot;.  It might slow someone down a bit, making you less of a target, but if someone is after you specifically, it will only help a little.

If someone is worried about keyloggers that much, I would suggest either only using computers you own, or some sort of token system like RSA SecureID.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503421</guid>
		<pubDate>Thu, 23 Nov 2006 15:03:43 -0800</pubDate>
		<dc:creator>fings</dc:creator>
	</item>	<item>
		<title>By: event</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503437</link>	
		<description>Also: &lt;a href=&quot;http://en.wikipedia.org/wiki/S/Key&quot;&gt;S/Key&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503437</guid>
		<pubDate>Thu, 23 Nov 2006 15:38:02 -0800</pubDate>
		<dc:creator>event</dc:creator>
	</item>	<item>
		<title>By: tomplus2</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503450</link>	
		<description>&lt;i&gt;Has anyone come up with a dynamic password system, i.e., a password that changes each time, according to an algorithm which both the user and website recognize?&lt;/i&gt;

Etrade has a device that does this, right?  I have a friend who works for a bank and he has a new password generated each time he logs in.   He carries around a device that has a lcd display on it and the current password is displayed.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503450</guid>
		<pubDate>Thu, 23 Nov 2006 16:01:00 -0800</pubDate>
		<dc:creator>tomplus2</dc:creator>
	</item>	<item>
		<title>By: dreamsign</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503454</link>	
		<description>&lt;i&gt;And this technique of changing focus won&apos;t help much against keyloggers that log mouse-clicks. The log will have something like: &quot;asdf&lt;click&gt;pa&lt;click&gt;fdsa&lt;click&gt;s&lt;click&gt;qewr&lt;alt -tab&gt;sw&lt;click&gt;b34&lt;click&gt;ord&quot;.&lt;/click&gt;&lt;/click&gt;&lt;/alt&gt;&lt;/click&gt;&lt;/click&gt;&lt;/click&gt;&lt;/click&gt;&lt;/i&gt;

What if you copied a large string and right-click-deleted the nonsense text out from the letters you want?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503454</guid>
		<pubDate>Thu, 23 Nov 2006 16:07:40 -0800</pubDate>
		<dc:creator>dreamsign</dc:creator>
	</item>	<item>
		<title>By: eriko</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503456</link>	
		<description>&lt;i&gt;Personally I wouldn&apos;t trust a machine that might have a keylogger unless I could stick in a LiveCD and run from that.&lt;/i&gt;

You&apos;re assuming someone hasn&apos;t slipped a hardware keylogger onto the box.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503456</guid>
		<pubDate>Thu, 23 Nov 2006 16:08:15 -0800</pubDate>
		<dc:creator>eriko</dc:creator>
	</item>	<item>
		<title>By: -harlequin-</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503464</link>	
		<description>I use a tablet PC :-)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503464</guid>
		<pubDate>Thu, 23 Nov 2006 17:00:35 -0800</pubDate>
		<dc:creator>-harlequin-</dc:creator>
	</item>	<item>
		<title>By: Mitrovarr</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503492</link>	
		<description>Your passwords are never totally safe in an internet cafe.  Anyone could be shoulder surfing, possibly with a security camera.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503492</guid>
		<pubDate>Thu, 23 Nov 2006 18:00:36 -0800</pubDate>
		<dc:creator>Mitrovarr</dc:creator>
	</item>	<item>
		<title>By: sindark</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503545</link>	
		<description>If you access things important enough for the above to be a concern, don&apos;t use internet cafes.

Pretty simple.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503545</guid>
		<pubDate>Thu, 23 Nov 2006 20:46:56 -0800</pubDate>
		<dc:creator>sindark</dc:creator>
	</item>	<item>
		<title>By: hattifattener</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503578</link>	
		<description>The SecurID key fobs that chunking and (I assume) tomplus2 mention are pretty popular. They do have some weaknesses, but still, they seem to be the most common &quot;more secure than a simple password but can stil be carried in your pocket&quot; login system for people like sysadmins.

(RSADSI bought SecurID some years back; as far as I can tell they haven&apos;t updated the keyfob technology much from what it was before.)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503578</guid>
		<pubDate>Thu, 23 Nov 2006 22:01:07 -0800</pubDate>
		<dc:creator>hattifattener</dc:creator>
	</item>	<item>
		<title>By: edd</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503639</link>	
		<description>Fair point about the liveCDs, but you can then use tricks like keeping passwords in an encrypted bit of your CD, so they can get the password to your liveCD but not your actual accounts (as you can then copy and paste the passwords since it won&apos;t be able to see inside your clipboard if it just sits between the keyboard and PC).

But Mitrovarr and sindark are right.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503639</guid>
		<pubDate>Fri, 24 Nov 2006 01:06:07 -0800</pubDate>
		<dc:creator>edd</dc:creator>
	</item>	<item>
		<title>By: jam_pony</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1503653</link>	
		<description>&lt;i&gt;Seriously, all these methods seem pretty good, but if you are that security-conscious, maybe just change your password after every login at a non-safe computer?&lt;/i&gt; - drjimmy11
If you get to it before the bad guys do.

The only way to have relative security at cafes is to use the ones where they don&apos;t supply the computers, you bring your own (per -harlequin- above) and just use their internet connection. This also has hazards, including visual spying and network sniffing, but the set of possible attacks is so reduced that with care you have a good chance of avoiding all of them.

I&apos;d like to point out too, this whole scenario of using someone else&apos;s computer is a variation of, and in essence identical to, the case of so-called &quot;Trusted Computing&quot;. Once you allow some other party to have ultimate control over hardware or software at lower levels of the system, you cannot have any strong assurance that the system is not betraying you.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1503653</guid>
		<pubDate>Fri, 24 Nov 2006 01:58:44 -0800</pubDate>
		<dc:creator>jam_pony</dc:creator>
	</item>	<item>
		<title>By: blmurch</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1504364</link>	
		<description>My husband and I have been traveling in South America for the past 4 months and have used many different internet cafes to access the internet.  We did bring our laptops, but not all internet cafes will let you plug into their ethernet, as that messes with their accounting software.  Wifi is not as ubiquitous around here as it is in the states, so if you are telling me not to use an internet cafe, then you&apos;re just saying, don&apos;t use the internet.  Well, that&apos;s not an option.  Also, computers down here are *really freaking* expensive, and so for people who are not rich (most people down here), their only access to computers and the internet is using the internet cafes.  I think that most cafes wipe and reinstall all their computers each night, but I wouldn&apos;t count on it.  But, back to the point, this isn&apos;t just a theoretical problem for a lot of people.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1504364</guid>
		<pubDate>Sat, 25 Nov 2006 06:08:41 -0800</pubDate>
		<dc:creator>blmurch</dc:creator>
	</item>	<item>
		<title>By: etoile</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1504803</link>	
		<description>The SecurID keyfobs have been around for a long time; I had one about six years ago.  They&apos;re neat, but you have to have the appropriate authentication manager - they&apos;re not yet available for logging into your webmail, etc.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1504803</guid>
		<pubDate>Sat, 25 Nov 2006 20:50:38 -0800</pubDate>
		<dc:creator>etoile</dc:creator>
	</item>	<item>
		<title>By: CrayDrygu</title>
		<link>http://www.metafilter.com/56479/A-clever-little-trick-to-protect-your-passwords#1505406</link>	
		<description>Since it&apos;s been missed...

&lt;a href=&quot;http://en.wikipedia.org/wiki/S/KEY&quot;&gt;S/KEY&lt;/a&gt; is a &lt;a href=&quot;http://en.wikipedia.org/wiki/One-time_password&quot;&gt;one-time password&lt;/a&gt; system that doesn&apos;t require an expensive keyfob, can be freely implemented on all Linux/Unix/BSD systems (and anything else supporting &lt;a href=&quot;http://en.wikipedia.org/wiki/Simple_Authentication_and_Security_Layer&quot;&gt;SASL&lt;/a&gt;), and was designed specifically for use on untrusted systems/networks.  Even if your password is captured, it doesn&apos;t matter, because your password will be different the next time you log in, and it&apos;s impossible to derive your next password even from a full history of your past ones.

The problem?  It needs to be implemented server-side, and it rarely (if ever) is.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.56479-1505406</guid>
		<pubDate>Sun, 26 Nov 2006 21:26:07 -0800</pubDate>
		<dc:creator>CrayDrygu</dc:creator>
	</item>
	</channel>
</rss>
