<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Sense and Sensitivity</title>
	<atom:link href="http://www.robustmcmanlypants.org/blog/2009/06/17/sense-and-sensitivity/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.robustmcmanlypants.org/blog/2009/06/17/sense-and-sensitivity/</link>
	<description>Camo Pants with a Lavender Fringe</description>
	<lastBuildDate>Tue, 24 Jan 2012 19:14:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Michael</title>
		<link>http://www.robustmcmanlypants.org/blog/2009/06/17/sense-and-sensitivity/comment-page-1/#comment-13829</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Wed, 24 Jun 2009 04:22:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.robustmcmanlypants.org/blog/?p=932#comment-13829</guid>
		<description>Honestly?  It reads to me as someone saying something just to have something to say.  In the age of automated password resets, password masking is not what&#039;s at the root of all those massive coronaries in the future of support staff the world over.  Neither are reset buttons.  

I think the point that password masking leads people to choose weak passwords &lt;em&gt;might&lt;/em&gt; hold water except that I can&#039;t think of a single account I&#039;ve set up this decade that &lt;em&gt;doesn&#039;t&lt;/em&gt; have some sort of minimum complexity requirement.

My personal philosophy on this is pretty non-standard, though.  I think people should come up with one really strong password that they have no trouble remembering and then use it for as long as they want because their chief goal should be to avoid being the lowest hanging fruit in any given bunch and accept that if they, personally, are targeted then their password not timing out isn&#039;t going to be what saves them.</description>
		<content:encoded><![CDATA[<p>Honestly?  It reads to me as someone saying something just to have something to say.  In the age of automated password resets, password masking is not what&#8217;s at the root of all those massive coronaries in the future of support staff the world over.  Neither are reset buttons.  </p>
<p>I think the point that password masking leads people to choose weak passwords <em>might</em> hold water except that I can&#8217;t think of a single account I&#8217;ve set up this decade that <em>doesn&#8217;t</em> have some sort of minimum complexity requirement.</p>
<p>My personal philosophy on this is pretty non-standard, though.  I think people should come up with one really strong password that they have no trouble remembering and then use it for as long as they want because their chief goal should be to avoid being the lowest hanging fruit in any given bunch and accept that if they, personally, are targeted then their password not timing out isn&#8217;t going to be what saves them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dob</title>
		<link>http://www.robustmcmanlypants.org/blog/2009/06/17/sense-and-sensitivity/comment-page-1/#comment-13827</link>
		<dc:creator>dob</dc:creator>
		<pubDate>Tue, 23 Jun 2009 22:08:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.robustmcmanlypants.org/blog/?p=932#comment-13827</guid>
		<description>Just curious, what do you think of Jakob Nielsen&#039;s latest contention:

http://www.useit.com/alertbox/passwords.html</description>
		<content:encoded><![CDATA[<p>Just curious, what do you think of Jakob Nielsen&#8217;s latest contention:</p>
<p><a href="http://www.useit.com/alertbox/passwords.html" rel="nofollow">http://www.useit.com/alertbox/passwords.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://www.robustmcmanlypants.org/blog/2009/06/17/sense-and-sensitivity/comment-page-1/#comment-13819</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Mon, 22 Jun 2009 18:40:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.robustmcmanlypants.org/blog/?p=932#comment-13819</guid>
		<description>I get that.  In general, I scan the use of &quot;sensitive,&quot; in the context of information security, to mean &quot;oh shit what if this got stolen and someone found out?&quot;  I don&#039;t think fear makes a good long-term motivator.  Hearing someone say, &quot;I&#039;d rather spend the money to secure this than read about its theft on the front page of the student paper,&quot; may work as a great short-term motivator but long-term fear is something that exhausts rather than bolsters.  I want people to see protected/valuable/sensitive/etc. data as something in which they&#039;re investing, not something they should fear.</description>
		<content:encoded><![CDATA[<p>I get that.  In general, I scan the use of &#8220;sensitive,&#8221; in the context of information security, to mean &#8220;oh shit what if this got stolen and someone found out?&#8221;  I don&#8217;t think fear makes a good long-term motivator.  Hearing someone say, &#8220;I&#8217;d rather spend the money to secure this than read about its theft on the front page of the student paper,&#8221; may work as a great short-term motivator but long-term fear is something that exhausts rather than bolsters.  I want people to see protected/valuable/sensitive/etc. data as something in which they&#8217;re investing, not something they should fear.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: A. Diggity</title>
		<link>http://www.robustmcmanlypants.org/blog/2009/06/17/sense-and-sensitivity/comment-page-1/#comment-13810</link>
		<dc:creator>A. Diggity</dc:creator>
		<pubDate>Thu, 18 Jun 2009 14:55:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.robustmcmanlypants.org/blog/?p=932#comment-13810</guid>
		<description>Now see, whenever I see the term  &quot;sensitive&quot; in a context like this, the first thing that leaps to my mind is  &quot;incriminating,&quot; e.g. a set of double books or insider trading or something.</description>
		<content:encoded><![CDATA[<p>Now see, whenever I see the term  &#8220;sensitive&#8221; in a context like this, the first thing that leaps to my mind is  &#8220;incriminating,&#8221; e.g. a set of double books or insider trading or something.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

