<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Chocolate Owns Your Passwords</title>
	<atom:link href="http://www.darknet.org.uk/2008/04/chocolate-owns-your-passwords/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/04/chocolate-owns-your-passwords/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<pubDate>Fri, 21 Nov 2008 07:19:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: backbone</title>
		<link>http://www.darknet.org.uk/2008/04/chocolate-owns-your-passwords/#comment-122868</link>
		<dc:creator>backbone</dc:creator>
		<pubDate>Tue, 29 Apr 2008 15:08:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=839#comment-122868</guid>
		<description>I have some chocolate leftovers from last years christmas... anybody interested?</description>
		<content:encoded><![CDATA[<p>I have some chocolate leftovers from last years christmas&#8230; anybody interested?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ZaD MoFo</title>
		<link>http://www.darknet.org.uk/2008/04/chocolate-owns-your-passwords/#comment-122852</link>
		<dc:creator>ZaD MoFo</dc:creator>
		<pubDate>Sun, 27 Apr 2008 04:37:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=839#comment-122852</guid>
		<description>This is my password: $Fogo.-%qBBRallOpe-n

Do those folks are idiots? No. 

Here is spontaneous honesty but viewed at distance by pals who know the importance of restricting access to computers.

Passwords are bothersome to remember. One password is ok but when you must remember ten or twenty (bank, social number, computer, access code for your house, your alarm system, your blog access, your social network page and so on, and many more if youre a sysop, it may appear to be a valuable technique to conglomerate thoses numbers, to simplify by having five passwords or less. But you know youre in trouble when a single password is the root access for your bank account, your computer, your house. On the other hand, if you think as criminal do like us we do (remember: to protect our stuff we must know all the  tricks), it's nonsense to give such a thing so "precious" for candy that we forgot: "all are not criminals". 

Sure, times have changed over the years.  Computers &#38; IT stuff is serious busyness now. Money and data fly all over the wires but like the guy who let the motor run the time to fetch a pack of cigs, simplicity = speed = smart.
Bad luck or shit happend anyway.

By the way, it's impressive what you could learn from someone unknow to you before, just by asking, even if you are not a blond girl.

So, this was my password: $F0g0.-%`97BRallOpe-n
Here is the &#62; CHOCOLATE &#60;.</description>
		<content:encoded><![CDATA[<p>This is my password: $Fogo.-%qBBRallOpe-n</p>
<p>Do those folks are idiots? No. </p>
<p>Here is spontaneous honesty but viewed at distance by pals who know the importance of restricting access to computers.</p>
<p>Passwords are bothersome to remember. One password is ok but when you must remember ten or twenty (bank, social number, computer, access code for your house, your alarm system, your blog access, your social network page and so on, and many more if youre a sysop, it may appear to be a valuable technique to conglomerate thoses numbers, to simplify by having five passwords or less. But you know youre in trouble when a single password is the root access for your bank account, your computer, your house. On the other hand, if you think as criminal do like us we do (remember: to protect our stuff we must know all the  tricks), it&#8217;s nonsense to give such a thing so &#8220;precious&#8221; for candy that we forgot: &#8220;all are not criminals&#8221;. </p>
<p>Sure, times have changed over the years.  Computers &amp; IT stuff is serious busyness now. Money and data fly all over the wires but like the guy who let the motor run the time to fetch a pack of cigs, simplicity = speed = smart.<br />
Bad luck or shit happend anyway.</p>
<p>By the way, it&#8217;s impressive what you could learn from someone unknow to you before, just by asking, even if you are not a blond girl.</p>
<p>So, this was my password: $F0g0.-%`97BRallOpe-n<br />
Here is the &gt; CHOCOLATE &lt;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BlueRaja</title>
		<link>http://www.darknet.org.uk/2008/04/chocolate-owns-your-passwords/#comment-122851</link>
		<dc:creator>BlueRaja</dc:creator>
		<pubDate>Sat, 26 Apr 2008 21:47:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=839#comment-122851</guid>
		<description>This story is tiring.  As &lt;a href="http://www.schneier.com/blog/archives/2008/04/giving_up_passw.html" rel="nofollow"&gt;Bruce Schneier&lt;/a&gt; put it, "I would certainly give up a fake password for a bar of chocolate."

I know I would.</description>
		<content:encoded><![CDATA[<p>This story is tiring.  As <a href="http://www.schneier.com/blog/archives/2008/04/giving_up_passw.html" rel="nofollow">Bruce Schneier</a> put it, &#8220;I would certainly give up a fake password for a bar of chocolate.&#8221;</p>
<p>I know I would.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fever</title>
		<link>http://www.darknet.org.uk/2008/04/chocolate-owns-your-passwords/#comment-122838</link>
		<dc:creator>fever</dc:creator>
		<pubDate>Fri, 25 Apr 2008 19:52:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=839#comment-122838</guid>
		<description>to think that someone would give out a password in exchange for a chocolate bar is hilarious. hopfully the were smart enough to change the pass immediatley or give a false one, if not than they are stupid people. but a very interesting bit of social engineering. i wonder how big the chocolate bar was? was the lady a blonde or a brunette? 

too much fun.</description>
		<content:encoded><![CDATA[<p>to think that someone would give out a password in exchange for a chocolate bar is hilarious. hopfully the were smart enough to change the pass immediatley or give a false one, if not than they are stupid people. but a very interesting bit of social engineering. i wonder how big the chocolate bar was? was the lady a blonde or a brunette? </p>
<p>too much fun.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zupakomputer</title>
		<link>http://www.darknet.org.uk/2008/04/chocolate-owns-your-passwords/#comment-122833</link>
		<dc:creator>zupakomputer</dc:creator>
		<pubDate>Fri, 25 Apr 2008 15:34:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=839#comment-122833</guid>
		<description>Let's hope you guys are right &#38; they were just making them up.

I would think the personal info has long been one of those moot points; just about anybody these days has access to databases that can look up postcodes, phone numbers, names, and house numbers. For example in the UK these are based on electoral registers, and they can and have been used to list people on the likes of automated phonecall lists (where you're offered prizes and so forth).

I've lost count of the amount of times on the phone I've had to give out personal details as routine (even say, checking up an insurance quote - or they won't tell you anything); usually they only need your postcode and they're able to look up the other details from there.</description>
		<content:encoded><![CDATA[<p>Let&#8217;s hope you guys are right &amp; they were just making them up.</p>
<p>I would think the personal info has long been one of those moot points; just about anybody these days has access to databases that can look up postcodes, phone numbers, names, and house numbers. For example in the UK these are based on electoral registers, and they can and have been used to list people on the likes of automated phonecall lists (where you&#8217;re offered prizes and so forth).</p>
<p>I&#8217;ve lost count of the amount of times on the phone I&#8217;ve had to give out personal details as routine (even say, checking up an insurance quote - or they won&#8217;t tell you anything); usually they only need your postcode and they&#8217;re able to look up the other details from there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogwitch</title>
		<link>http://www.darknet.org.uk/2008/04/chocolate-owns-your-passwords/#comment-122830</link>
		<dc:creator>Bogwitch</dc:creator>
		<pubDate>Fri, 25 Apr 2008 14:13:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=839#comment-122830</guid>
		<description>Abolutely. Hell, if a pretty girl asks me WITHOUT chocolate, I'd be sure to tell her my password is 'password' That way, I can skew the results of any survey to show that password security is still weak and needs infosec professionals like me to fix it!</description>
		<content:encoded><![CDATA[<p>Abolutely. Hell, if a pretty girl asks me WITHOUT chocolate, I&#8217;d be sure to tell her my password is &#8216;password&#8217; That way, I can skew the results of any survey to show that password security is still weak and needs infosec professionals like me to fix it!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David</title>
		<link>http://www.darknet.org.uk/2008/04/chocolate-owns-your-passwords/#comment-122828</link>
		<dc:creator>David</dc:creator>
		<pubDate>Fri, 25 Apr 2008 12:51:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=839#comment-122828</guid>
		<description>Hey, if you're a pretty girl and you're offering me chocolate, I, too, will be delighted make up a password and give it to you to write on your clipboard.

Did they test even one of those passwords to see if it was good for anything?</description>
		<content:encoded><![CDATA[<p>Hey, if you&#8217;re a pretty girl and you&#8217;re offering me chocolate, I, too, will be delighted make up a password and give it to you to write on your clipboard.</p>
<p>Did they test even one of those passwords to see if it was good for anything?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
