<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MattJay Security &#187; Password</title>
	<atom:link href="http://www.mattjaysecurity.com/category/password/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mattjaysecurity.com</link>
	<description>The musings of a young information security professional on current security events.</description>
	<lastBuildDate>Wed, 02 Feb 2011 17:09:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Reveal Passwords Bookmarklet &#8211; What Could Go Wrong?</title>
		<link>http://www.mattjaysecurity.com/2011/02/reveal-passwords-bookmarklet-what-could-go-wrong/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://www.mattjaysecurity.com/2011/02/reveal-passwords-bookmarklet-what-could-go-wrong/#comments</comments>
		<pubDate>Wed, 02 Feb 2011 17:09:14 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[fundamentals]]></category>
		<category><![CDATA[Password]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=131</guid>
		<description><![CDATA[Lifehacker posted an article this AM about a Bookmarklet that would reveal passwords on your screen that are normally bulleted out. It is advertised as a way to help remember passwords that are saved in some sort of autofill application such as LastPass or just in your browser. Sounds terrific so you don&#8217;t forget them [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="whatcouldgowrong" src="http://www.liquidmatrix.org/blog/wp-content/uploads/2011/02/whatcouldgowrong.jpg" alt="" width="350" height="230" />Lifehacker posted an article this AM about a Bookmarklet that would reveal passwords on your screen that are normally bulleted out.</p>
<p>It is advertised as a way to help remember passwords that are saved in some sort of autofill application such as LastPass or just in your browser. Sounds terrific so you don&#8217;t forget them by heart.</p>
<p>I liken this to the fact that 10 years ago I had to dial everybody&#8217;s phone number on my home phone manually, and now I just pull up their contact in my cell and hit send. The funny thing is those friends and family I still call from the pre-cell phone era are the only people&#8217;s numbers I know by heart.</p>
<p>But even though this bookmarklet sounds like a good idea in theory, I have a problem with it. How many times have you been typing your login information in and started typing your password accidentally in the username field? For me it has happened a decent number of times and a handful of those were while people were behind me watching, which of course was followed by me changing my password. So now you are telling me there is a javascript bookmarklet being advertised to do such a thing *on purpose*?</p>
<p>What could go wrong here?</p>

<div class="sociable">
<div class="sociable_tagline">
<strong>Share and Enjoy:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;bodytext=Lifehacker%20posted%20an%20article%20this%20AM%20about%20a%20Bookmarklet%20that%20would%20reveal%20passwords%20on%20your%20screen%20that%20are%20normally%20bulleted%20out.%0D%0A%0D%0AIt%20is%20advertised%20as%20a%20way%20to%20help%20remember%20passwords%20that%20are%20saved%20in%20some%20sort%20of%20autofill%20application%20such%20as%20La" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;notes=Lifehacker%20posted%20an%20article%20this%20AM%20about%20a%20Bookmarklet%20that%20would%20reveal%20passwords%20on%20your%20screen%20that%20are%20normally%20bulleted%20out.%0D%0A%0D%0AIt%20is%20advertised%20as%20a%20way%20to%20help%20remember%20passwords%20that%20are%20saved%20in%20some%20sort%20of%20autofill%20application%20such%20as%20La" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;t=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;annotation=Lifehacker%20posted%20an%20article%20this%20AM%20about%20a%20Bookmarklet%20that%20would%20reveal%20passwords%20on%20your%20screen%20that%20are%20normally%20bulleted%20out.%0D%0A%0D%0AIt%20is%20advertised%20as%20a%20way%20to%20help%20remember%20passwords%20that%20are%20saved%20in%20some%20sort%20of%20autofill%20application%20such%20as%20La" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=Lifehacker%20posted%20an%20article%20this%20AM%20about%20a%20Bookmarklet%20that%20would%20reveal%20passwords%20on%20your%20screen%20that%20are%20normally%20bulleted%20out.%0D%0A%0D%0AIt%20is%20advertised%20as%20a%20way%20to%20help%20remember%20passwords%20that%20are%20saved%20in%20some%20sort%20of%20autofill%20application%20such%20as%20La" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;title=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F&amp;t=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F&amp;s=Lifehacker%20posted%20an%20article%20this%20AM%20about%20a%20Bookmarklet%20that%20would%20reveal%20passwords%20on%20your%20screen%20that%20are%20normally%20bulleted%20out.%0D%0A%0D%0AIt%20is%20advertised%20as%20a%20way%20to%20help%20remember%20passwords%20that%20are%20saved%20in%20some%20sort%20of%20autofill%20application%20such%20as%20La" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  href="http://twitter.com/home?status=Reveal%20Passwords%20Bookmarklet%20-%20What%20Could%20Go%20Wrong%3F%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2011%2F02%2Freveal-passwords-bookmarklet-what-could-go-wrong%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2011/02/reveal-passwords-bookmarklet-what-could-go-wrong/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Secure Password Win [Random]</title>
		<link>http://www.mattjaysecurity.com/2010/02/secure-password-win-random/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://www.mattjaysecurity.com/2010/02/secure-password-win-random/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 22:29:30 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Password]]></category>
		<category><![CDATA[Random]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=98</guid>
		<description><![CDATA[Usually can&#8217;t stand random chain emails from family/friends but every once in a while there is a good one. Thought I&#8217;d share this laugh: During a recent password audit at the Bank of Ireland it was found that Paddy O&#8217;Toole was using the following password: MickeyMinniePlutoHueyLouieDeweyDonaldGoofyDublin When Paddy was asked why he had such a [...]]]></description>
			<content:encoded><![CDATA[<p>Usually can&#8217;t stand random chain emails from family/friends but every once in a while there is a good one. Thought I&#8217;d share this laugh:</p>
<blockquote><p>
During a recent password audit at the  Bank of Ireland it was found that Paddy O&#8217;Toole was using the following password: MickeyMinniePlutoHueyLouieDeweyDonaldGoofyDublin</p>
<p>When Paddy was asked why he had such a  long password: he replied &#8221;Bejazus! are yez f*ckin&#8217; stupid? The bank told me password had to be at least 8 characters long and include  one capital&#8221;</p>
<p>Don&#8217;t ever  think you can outwit the Irish!
</p></blockquote>

<div class="sociable">
<div class="sociable_tagline">
<strong>Share and Enjoy:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D&amp;bodytext=Usually%20can%27t%20stand%20random%20chain%20emails%20from%20family%2Ffriends%20but%20every%20once%20in%20a%20while%20there%20is%20a%20good%20one.%20Thought%20I%27d%20share%20this%20laugh%3A%0D%0A%0D%0ADuring%20a%20recent%20password%20audit%20at%20the%20%20Bank%20of%20Ireland%20it%20was%20found%20that%20Paddy%20O%27Toole%20was%20using%20the%20following" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D&amp;notes=Usually%20can%27t%20stand%20random%20chain%20emails%20from%20family%2Ffriends%20but%20every%20once%20in%20a%20while%20there%20is%20a%20good%20one.%20Thought%20I%27d%20share%20this%20laugh%3A%0D%0A%0D%0ADuring%20a%20recent%20password%20audit%20at%20the%20%20Bank%20of%20Ireland%20it%20was%20found%20that%20Paddy%20O%27Toole%20was%20using%20the%20following" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;t=Secure%20Password%20Win%20%5BRandom%5D" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D&amp;annotation=Usually%20can%27t%20stand%20random%20chain%20emails%20from%20family%2Ffriends%20but%20every%20once%20in%20a%20while%20there%20is%20a%20good%20one.%20Thought%20I%27d%20share%20this%20laugh%3A%0D%0A%0D%0ADuring%20a%20recent%20password%20audit%20at%20the%20%20Bank%20of%20Ireland%20it%20was%20found%20that%20Paddy%20O%27Toole%20was%20using%20the%20following" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=Usually%20can%27t%20stand%20random%20chain%20emails%20from%20family%2Ffriends%20but%20every%20once%20in%20a%20while%20there%20is%20a%20good%20one.%20Thought%20I%27d%20share%20this%20laugh%3A%0D%0A%0D%0ADuring%20a%20recent%20password%20audit%20at%20the%20%20Bank%20of%20Ireland%20it%20was%20found%20that%20Paddy%20O%27Toole%20was%20using%20the%20following" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Secure%20Password%20Win%20%5BRandom%5D&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;t=Secure%20Password%20Win%20%5BRandom%5D&amp;s=Usually%20can%27t%20stand%20random%20chain%20emails%20from%20family%2Ffriends%20but%20every%20once%20in%20a%20while%20there%20is%20a%20good%20one.%20Thought%20I%27d%20share%20this%20laugh%3A%0D%0A%0D%0ADuring%20a%20recent%20password%20audit%20at%20the%20%20Bank%20of%20Ireland%20it%20was%20found%20that%20Paddy%20O%27Toole%20was%20using%20the%20following" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  href="http://twitter.com/home?status=Secure%20Password%20Win%20%5BRandom%5D%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2010/02/secure-password-win-random/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

