<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: SuperGenPass is not that&#160;secure</title>
	<atom:link href="http://akibjorklund.com/2009/supergenpass-is-not-that-secure/feed" rel="self" type="application/rss+xml" />
	<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure</link>
	<description>web generalist</description>
	<lastBuildDate>Thu, 09 Sep 2010 04:39:43 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Aki Björklund</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-18403</link>
		<dc:creator>Aki Björklund</dc:creator>
		<pubDate>Thu, 09 Sep 2010 04:39:43 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-18403</guid>
		<description>Yes, it will.</description>
		<content:encoded><![CDATA[<p>Yes, it will.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: c</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-18402</link>
		<dc:creator>c</dc:creator>
		<pubDate>Wed, 08 Sep 2010 22:44:23 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-18402</guid>
		<description>If I use the applet in a blank tab and then paste in the password, will  it be secure?</description>
		<content:encoded><![CDATA[<p>If I use the applet in a blank tab and then paste in the password, will  it be secure?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Anderson</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-17236</link>
		<dc:creator>Tim Anderson</dc:creator>
		<pubDate>Wed, 14 Apr 2010 10:16:18 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-17236</guid>
		<description>@Andres Riofrio That doesn&#039;t work in firefox 3.5.6</description>
		<content:encoded><![CDATA[<p>@Andres Riofrio That doesn&#8217;t work in firefox 3.5.6</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: asaens</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-17156</link>
		<dc:creator>asaens</dc:creator>
		<pubDate>Fri, 02 Apr 2010 22:36:25 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-17156</guid>
		<description>correction: cut and paste with a mouse</description>
		<content:encoded><![CDATA[<p>correction: cut and paste with a mouse</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: asaens</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-17155</link>
		<dc:creator>asaens</dc:creator>
		<pubDate>Fri, 02 Apr 2010 22:34:20 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-17155</guid>
		<description>for whatever it&#039;s worth: I cut and paste some text to the end of the master password as a form of salt ... doesn&#039;t help the hard-core keyboard users but might help others</description>
		<content:encoded><![CDATA[<p>for whatever it&#8217;s worth: I cut and paste some text to the end of the master password as a form of salt &#8230; doesn&#8217;t help the hard-core keyboard users but might help others</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-16739</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Thu, 04 Mar 2010 13:22:16 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-16739</guid>
		<description>I&#039;ve tried the advanced version of the bookmarklet generator (http://supergenpass.com/customize/?advanced) which adds a &quot;stealth&quot; password as salt in the hash.  The salted bookmarklet still shows the Master password in Aki&#039;s demo pages but the stealth password and the added salt appear immune. Or have I missed something?  Adding your own salt seems to address the point George was (indirectly) trying to make.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve tried the advanced version of the bookmarklet generator (<a href="http://supergenpass.com/customize/?advanced">http://supergenpass.com/customize/?advanced</a>) which adds a &#8220;stealth&#8221; password as salt in the hash.  The salted bookmarklet still shows the Master password in Aki&#8217;s demo pages but the stealth password and the added salt appear immune. Or have I missed something?  Adding your own salt seems to address the point George was (indirectly) trying to make.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: YinYanger</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-16702</link>
		<dc:creator>YinYanger</dc:creator>
		<pubDate>Tue, 02 Mar 2010 13:35:23 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-16702</guid>
		<description>Hi!
I&#039;ve found why your demos didn&#039;t work on my Opera! 
I&#039;m using a little UserJS for ad-blocking from Thomas von Frommannshausen at http://www.miurasoft.de/opera/docInspector/blog/ 
As I&#039;m not a java script programmer, I don&#039;t know why it has this effect on your demos. Just a coincidence, maybe?
If you want to take a look to the file: http://files.myopera.com/YinYanger/files/adBlocking.js</description>
		<content:encoded><![CDATA[<p>Hi!<br />
I&#8217;ve found why your demos didn&#8217;t work on my Opera!<br />
I&#8217;m using a little UserJS for ad-blocking from Thomas von Frommannshausen at <a href="http://www.miurasoft.de/opera/docInspector/blog/">http://www.miurasoft.de/opera/docInspector/blog/</a><br />
As I&#8217;m not a java script programmer, I don&#8217;t know why it has this effect on your demos. Just a coincidence, maybe?<br />
If you want to take a look to the file: <a href="http://files.myopera.com/YinYanger/files/adBlocking.js">http://files.myopera.com/YinYanger/files/adBlocking.js</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andres Riofrio</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-16698</link>
		<dc:creator>Andres Riofrio</dc:creator>
		<pubDate>Tue, 02 Mar 2010 03:05:33 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-16698</guid>
		<description>I think probably the best way to circumvent this is to use an iframe with a data: URL. I haven&#039;t tested it, but I think that major browsers will see any access to this iframe as a XSS violation and forbid it, thus making the SuperGenPass form secure.</description>
		<content:encoded><![CDATA[<p>I think probably the best way to circumvent this is to use an iframe with a data: URL. I haven&#8217;t tested it, but I think that major browsers will see any access to this iframe as a XSS violation and forbid it, thus making the SuperGenPass form secure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Anderson</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-16126</link>
		<dc:creator>Tim Anderson</dc:creator>
		<pubDate>Sun, 31 Jan 2010 04:20:03 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-16126</guid>
		<description>I have created a bookmarklet version of SuperGenPass that only stores your password in a modal pop-up. As the pop-up is modal, all JavaScript in the host page is stopped and thus it cannot read the master password. It is availiable &lt;a href=&#039;http://www.timando.net/sgpbkmk/&#039; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>I have created a bookmarklet version of SuperGenPass that only stores your password in a modal pop-up. As the pop-up is modal, all JavaScript in the host page is stopped and thus it cannot read the master password. It is availiable <a href='http://www.timando.net/sgpbkmk/'>here</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Gough</title>
		<link>http://akibjorklund.com/2009/supergenpass-is-not-that-secure#comment-15941</link>
		<dc:creator>Michael Gough</dc:creator>
		<pubDate>Wed, 13 Jan 2010 14:17:57 +0000</pubDate>
		<guid isPermaLink="false">http://akibjorklund.com/?p=1497#comment-15941</guid>
		<description>That is why many of us use and LOVE No Script... so any malicious scripts while we logon to a website do NOT affect things like SuperGenPass</description>
		<content:encoded><![CDATA[<p>That is why many of us use and LOVE No Script&#8230; so any malicious scripts while we logon to a website do NOT affect things like SuperGenPass</p>
]]></content:encoded>
	</item>
</channel>
</rss>
