<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Review: PassPack (v Clipperz) - passwords on the iPhone!</title>
	<atom:link href="http://comments.deasil.com/2007/08/17/review-passpack-v-clipperz-passwords-on-the-iphone/feed/" rel="self" type="application/rss+xml" />
	<link>http://comments.deasil.com/2007/08/17/review-passpack-v-clipperz-passwords-on-the-iphone/</link>
	<description>escape colon w q</description>
	<pubDate>Wed, 07 Jan 2009 17:44:48 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: The Dangers of Online Encryption</title>
		<link>http://comments.deasil.com/2007/08/17/review-passpack-v-clipperz-passwords-on-the-iphone/#comment-6938</link>
		<dc:creator>The Dangers of Online Encryption</dc:creator>
		<pubDate>Mon, 12 Nov 2007 16:34:57 +0000</pubDate>
		<guid isPermaLink="false">http://comments.deasil.com/2007/08/17/review-passpack-v-clipperz-passwords-on-the-iphone/#comment-6938</guid>
		<description>[...] secure but more convenient plain html interface. Now this is distinct from the html interface that Clipperz and PassPack use - their model is much closer to the java version but they use javascript instead of java - all [...]</description>
		<content:encoded><![CDATA[<p>[...] secure but more convenient plain html interface. Now this is distinct from the html interface that Clipperz and PassPack use - their model is much closer to the java version but they use javascript instead of java - all [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tara (PassPack)</title>
		<link>http://comments.deasil.com/2007/08/17/review-passpack-v-clipperz-passwords-on-the-iphone/#comment-4671</link>
		<dc:creator>Tara (PassPack)</dc:creator>
		<pubDate>Sun, 09 Sep 2007 20:30:16 +0000</pubDate>
		<guid isPermaLink="false">http://comments.deasil.com/2007/08/17/review-passpack-v-clipperz-passwords-on-the-iphone/#comment-4671</guid>
		<description>@felix,
Yes, you understood perfectly. That's exactly the way it works. 

If you wanted to, you could sign in, then disconnect from the internet before inserting your key. You'd simply need to go back online to save any changes you've made (ie. send your encrypted pack of data to the server for storage). 

Cheers,
Tara</description>
		<content:encoded><![CDATA[<p>@felix,<br />
Yes, you understood perfectly. That&#8217;s exactly the way it works. </p>
<p>If you wanted to, you could sign in, then disconnect from the internet before inserting your key. You&#8217;d simply need to go back online to save any changes you&#8217;ve made (ie. send your encrypted pack of data to the server for storage). </p>
<p>Cheers,<br />
Tara</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: felix</title>
		<link>http://comments.deasil.com/2007/08/17/review-passpack-v-clipperz-passwords-on-the-iphone/#comment-4481</link>
		<dc:creator>felix</dc:creator>
		<pubDate>Fri, 07 Sep 2007 19:59:00 +0000</pubDate>
		<guid isPermaLink="false">http://comments.deasil.com/2007/08/17/review-passpack-v-clipperz-passwords-on-the-iphone/#comment-4481</guid>
		<description>Brian, you are right, of course that if you had to send a site your key it would security would be greatly decreased. But both of these apps do not actually send your key over the net, decryption is handled locally on your machine, at worse you send over a name and password over ssl that gets you the encrypted file that you still need to decrypt locally.

So, as I see it, in the worst case where you don't trust the application provider, they would need the ability to brute force your decryption key - same goes if they are compromised and bad guys get access to your encrypted blocks. If you do trust them, then someone would first need to be able to eavesdrop on your ssl connection or watch your keyboard - the same sorts of problems online banks are dealing with today. The end result of which is still them needing to be able to break AES encryption.

That at least is my broad understanding of the way these services work.</description>
		<content:encoded><![CDATA[<p>Brian, you are right, of course that if you had to send a site your key it would security would be greatly decreased. But both of these apps do not actually send your key over the net, decryption is handled locally on your machine, at worse you send over a name and password over ssl that gets you the encrypted file that you still need to decrypt locally.</p>
<p>So, as I see it, in the worst case where you don&#8217;t trust the application provider, they would need the ability to brute force your decryption key - same goes if they are compromised and bad guys get access to your encrypted blocks. If you do trust them, then someone would first need to be able to eavesdrop on your ssl connection or watch your keyboard - the same sorts of problems online banks are dealing with today. The end result of which is still them needing to be able to break AES encryption.</p>
<p>That at least is my broad understanding of the way these services work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brian W. Rainey</title>
		<link>http://comments.deasil.com/2007/08/17/review-passpack-v-clipperz-passwords-on-the-iphone/#comment-4476</link>
		<dc:creator>Brian W. Rainey</dc:creator>
		<pubDate>Fri, 07 Sep 2007 19:35:41 +0000</pubDate>
		<guid isPermaLink="false">http://comments.deasil.com/2007/08/17/review-passpack-v-clipperz-passwords-on-the-iphone/#comment-4476</guid>
		<description>Online password storage "apps" are a very bad thing.  The nature of a security model is to protect valuable assets.  The moment you push your "key" out to a web-based site is the instant that your security model designed to protect your most valuable assets is compromised.</description>
		<content:encoded><![CDATA[<p>Online password storage &#8220;apps&#8221; are a very bad thing.  The nature of a security model is to protect valuable assets.  The moment you push your &#8220;key&#8221; out to a web-based site is the instant that your security model designed to protect your most valuable assets is compromised.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: felix</title>
		<link>http://comments.deasil.com/2007/08/17/review-passpack-v-clipperz-passwords-on-the-iphone/#comment-3439</link>
		<dc:creator>felix</dc:creator>
		<pubDate>Fri, 17 Aug 2007 21:26:35 +0000</pubDate>
		<guid isPermaLink="false">http://comments.deasil.com/2007/08/17/review-passpack-v-clipperz-passwords-on-the-iphone/#comment-3439</guid>
		<description>Yeah, I'm a user of it. :) 

I'm glad to hear your going for full disclosure! That's my only real complaint. Everything else was just little preferency things.

I had enabled remember me - and it's cool. My fear about this, though, is my memory sucks so that if I don't log in every time I won't remember the login when I next need to. (I don't like carrying the info around with me). So as a safety measure I didn't use it on my iPhone. Again, just a personal quirk. I do hope, though, that you'lll allow a means to put in a weaker password - I should be allowed to shoot myself in the foot for the sake of convenience. :)

Thanks for your suggestions! I'll be following development and seeing how things.. develop.</description>
		<content:encoded><![CDATA[<p>Yeah, I&#8217;m a user of it. :) </p>
<p>I&#8217;m glad to hear your going for full disclosure! That&#8217;s my only real complaint. Everything else was just little preferency things.</p>
<p>I had enabled remember me - and it&#8217;s cool. My fear about this, though, is my memory sucks so that if I don&#8217;t log in every time I won&#8217;t remember the login when I next need to. (I don&#8217;t like carrying the info around with me). So as a safety measure I didn&#8217;t use it on my iPhone. Again, just a personal quirk. I do hope, though, that you&#8217;lll allow a means to put in a weaker password - I should be allowed to shoot myself in the foot for the sake of convenience. :)</p>
<p>Thanks for your suggestions! I&#8217;ll be following development and seeing how things.. develop.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tara Kelly (PassPack)</title>
		<link>http://comments.deasil.com/2007/08/17/review-passpack-v-clipperz-passwords-on-the-iphone/#comment-3436</link>
		<dc:creator>Tara Kelly (PassPack)</dc:creator>
		<pubDate>Fri, 17 Aug 2007 16:48:05 +0000</pubDate>
		<guid isPermaLink="false">http://comments.deasil.com/2007/08/17/review-passpack-v-clipperz-passwords-on-the-iphone/#comment-3436</guid>
		<description>Hi,
First - thanks for giving PassPack a try, and for sharing with others. Let me jump right in and answer a few of your questions.

On Security Disclosure.
Agreed. We're in the process of setting up an area dedicated to this, and to the various libraries that we've developed and will be released as open source. It's coming.

On too much typing.
Have you tried the "Remember me" feature? This will keep you logged in for a week so you'll just enter your Packing key to get in - much less typing. Here's more info: http://tinyurl.com/2bgncm

On the entries.
Only the Title is required - and one other filed of your choice. The link isn't mandatory. On custom fields, we talked about that a little bit here (scroll down to the "Custom Fields" section): http://tinyurl.com/2nbqvn

I hope I didn't come off as short, just trying not to leave an endless comment. :) Please let me know if you'd like any more, or different, information. I'll be happy to provide it.

Cheers,
Tara Kelly
PassPack Founding Partner</description>
		<content:encoded><![CDATA[<p>Hi,<br />
First - thanks for giving PassPack a try, and for sharing with others. Let me jump right in and answer a few of your questions.</p>
<p>On Security Disclosure.<br />
Agreed. We&#8217;re in the process of setting up an area dedicated to this, and to the various libraries that we&#8217;ve developed and will be released as open source. It&#8217;s coming.</p>
<p>On too much typing.<br />
Have you tried the &#8220;Remember me&#8221; feature? This will keep you logged in for a week so you&#8217;ll just enter your Packing key to get in - much less typing. Here&#8217;s more info: <a href="http://tinyurl.com/2bgncm" rel="nofollow">http://tinyurl.com/2bgncm</a></p>
<p>On the entries.<br />
Only the Title is required - and one other filed of your choice. The link isn&#8217;t mandatory. On custom fields, we talked about that a little bit here (scroll down to the &#8220;Custom Fields&#8221; section): <a href="http://tinyurl.com/2nbqvn" rel="nofollow">http://tinyurl.com/2nbqvn</a></p>
<p>I hope I didn&#8217;t come off as short, just trying not to leave an endless comment. :) Please let me know if you&#8217;d like any more, or different, information. I&#8217;ll be happy to provide it.</p>
<p>Cheers,<br />
Tara Kelly<br />
PassPack Founding Partner</p>
]]></content:encoded>
	</item>
</channel>
</rss>
