<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: It’s all fun and games until someone brings up FiFi</title>
	<atom:link href="http://blog.privcom.gc.ca/index.php/2009/05/12/it%e2%80%99s-all-fun-and-games-until-someone-brings-up-fifi/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.privcom.gc.ca/index.php/2009/05/12/it%e2%80%99s-all-fun-and-games-until-someone-brings-up-fifi/</link>
	<description></description>
	<lastBuildDate>Thu, 26 Aug 2010 15:45:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Colin McKay</title>
		<link>http://blog.privcom.gc.ca/index.php/2009/05/12/it%e2%80%99s-all-fun-and-games-until-someone-brings-up-fifi/comment-page-1/#comment-3086</link>
		<dc:creator>Colin McKay</dc:creator>
		<pubDate>Wed, 20 May 2009 20:12:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.privcom.gc.ca/?p=330#comment-3086</guid>
		<description>First of all, I&#039;d like to thank Alice Cooper for dropping by. It&#039;s nice to see that we&#039;re connecting with the old school rockers. :-) 

I agree that there&#039;s a lot more to say about this. I also have to point out that my bank asks for my mother&#039;s maiden name as an identity check when I call the online service centre.</description>
		<content:encoded><![CDATA[<p>First of all, I&#8217;d like to thank Alice Cooper for dropping by. It&#8217;s nice to see that we&#8217;re connecting with the old school rockers. <img src='http://blog.privcom.gc.ca/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  </p>
<p>I agree that there&#8217;s a lot more to say about this. I also have to point out that my bank asks for my mother&#8217;s maiden name as an identity check when I call the online service centre.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alice Cooper</title>
		<link>http://blog.privcom.gc.ca/index.php/2009/05/12/it%e2%80%99s-all-fun-and-games-until-someone-brings-up-fifi/comment-page-1/#comment-3085</link>
		<dc:creator>Alice Cooper</dc:creator>
		<pubDate>Wed, 20 May 2009 20:07:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.privcom.gc.ca/?p=330#comment-3085</guid>
		<description>Nice post, and good advice - but I think it should go further. For one, middle names, and related family names can be picked out from numerous databases (many from the gov&#039;t itself). You don&#039;t need twitter to get this information, so perhaps the target of your article could have been web sites with terrible security, such as those described (banks, etc using middle names as passwords...).

At the same time, I&#039;ve never used a bank or website that asked such trivial information for a secret question...</description>
		<content:encoded><![CDATA[<p>Nice post, and good advice &#8211; but I think it should go further. For one, middle names, and related family names can be picked out from numerous databases (many from the gov&#8217;t itself). You don&#8217;t need twitter to get this information, so perhaps the target of your article could have been web sites with terrible security, such as those described (banks, etc using middle names as passwords&#8230;).</p>
<p>At the same time, I&#8217;ve never used a bank or website that asked such trivial information for a secret question&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Colin McKay</title>
		<link>http://blog.privcom.gc.ca/index.php/2009/05/12/it%e2%80%99s-all-fun-and-games-until-someone-brings-up-fifi/comment-page-1/#comment-3053</link>
		<dc:creator>Colin McKay</dc:creator>
		<pubDate>Tue, 19 May 2009 12:51:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.privcom.gc.ca/?p=330#comment-3053</guid>
		<description>Thanks, Mike. That&#039;s an important point. I guess the point of the post was to emphasize to people that they should safeguard their information more carefully, even if the existing security measures could be improved. We&#039;ll certainly talk about security measures in the future.</description>
		<content:encoded><![CDATA[<p>Thanks, Mike. That&#8217;s an important point. I guess the point of the post was to emphasize to people that they should safeguard their information more carefully, even if the existing security measures could be improved. We&#8217;ll certainly talk about security measures in the future.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Pelletier</title>
		<link>http://blog.privcom.gc.ca/index.php/2009/05/12/it%e2%80%99s-all-fun-and-games-until-someone-brings-up-fifi/comment-page-1/#comment-3052</link>
		<dc:creator>Mike Pelletier</dc:creator>
		<pubDate>Tue, 19 May 2009 12:39:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.privcom.gc.ca/?p=330#comment-3052</guid>
		<description>I wonder if this post would have been better spent explaining what is wrong with using information like this for security and identification purposes.

Anyone involved with security thinks these &quot;maiden name&quot; questions are used to provide the user with a feeling of security, not to actually make anything more secure.  There are genuine &quot;two factor&quot; authentication methods, methods that use a password and something else, but these questions do not represent a second factor, they are just a second password.  Passwords that we are encouraged to make as guessable as possible and never change.  It&#039;s absurd when you think about it.</description>
		<content:encoded><![CDATA[<p>I wonder if this post would have been better spent explaining what is wrong with using information like this for security and identification purposes.</p>
<p>Anyone involved with security thinks these &#8220;maiden name&#8221; questions are used to provide the user with a feeling of security, not to actually make anything more secure.  There are genuine &#8220;two factor&#8221; authentication methods, methods that use a password and something else, but these questions do not represent a second factor, they are just a second password.  Passwords that we are encouraged to make as guessable as possible and never change.  It&#8217;s absurd when you think about it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Garth</title>
		<link>http://blog.privcom.gc.ca/index.php/2009/05/12/it%e2%80%99s-all-fun-and-games-until-someone-brings-up-fifi/comment-page-1/#comment-3041</link>
		<dc:creator>Garth</dc:creator>
		<pubDate>Sun, 17 May 2009 14:58:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.privcom.gc.ca/?p=330#comment-3041</guid>
		<description>What a great blog! Kudos for communicating with Canadians this way. I&#039;ve tweeted this particular post @SocialMediaMash</description>
		<content:encoded><![CDATA[<p>What a great blog! Kudos for communicating with Canadians this way. I&#8217;ve tweeted this particular post @SocialMediaMash</p>
]]></content:encoded>
	</item>
</channel>
</rss>
