<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Blogger proves flaws in Ecuadoran security system by hacking president&#039;s&#160;identity</title>
	<atom:link href="http://boingboing.net/2012/12/04/blogger-proves-flaws-in-ecuado.html/feed" rel="self" type="application/rss+xml" />
	<link>http://boingboing.net/2012/12/04/blogger-proves-flaws-in-ecuado.html</link>
	<description>Brain candy for Happy Mutants</description>
	<lastBuildDate>Tue, 21 May 2013 23:14:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: ffabian</title>
		<link>http://boingboing.net/2012/12/04/blogger-proves-flaws-in-ecuado.html#comment-1598497</link>
		<dc:creator>ffabian</dc:creator>
		<pubDate>Tue, 04 Dec 2012 22:15:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=198133#comment-1598497</guid>
		<description>&quot;prompted action from the president, who personally ordered Moreno&#039;s release&quot;
Guess what would&#039;ve happened if he tried this in the &quot;Land of the free&quot; instead of some third-world south-american backwater country...</description>
		<content:encoded><![CDATA[<p>&#8220;prompted action from the president, who personally ordered Moreno&#8217;s release&#8221;<br />
Guess what would&#8217;ve happened if he tried this in the &#8220;Land of the free&#8221; instead of some third-world south-american backwater country&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cowicide</title>
		<link>http://boingboing.net/2012/12/04/blogger-proves-flaws-in-ecuado.html#comment-1598397</link>
		<dc:creator>Cowicide</dc:creator>
		<pubDate>Tue, 04 Dec 2012 20:31:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=198133#comment-1598397</guid>
		<description>&lt;blockquote&gt;vociferous Twitter campaign&lt;/blockquote&gt;I wish all wars were fought this way.</description>
		<content:encoded><![CDATA[<blockquote><p>vociferous Twitter campaign</p></blockquote>
<p>I wish all wars were fought this way.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sean Nelson</title>
		<link>http://boingboing.net/2012/12/04/blogger-proves-flaws-in-ecuado.html#comment-1598327</link>
		<dc:creator>Sean Nelson</dc:creator>
		<pubDate>Tue, 04 Dec 2012 19:34:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=198133#comment-1598327</guid>
		<description>I would like some more information on the numbers that he &quot;simply guessed&quot;.  There must be more of a pattern than is mentioned in the wired article.  The number combination he guessed is: 

V23444 – E5444

Even understanding that the first character will be only A, E, or V, that still leaves 9 base-10 digits of entropy in addition to those two 3-character slots. 
If my understanding is correct, the number of permutations could be calculated with 3*10*10*10*10*10*3*10*10*10*10 =  9,000,000,000  (because 3 letters and 10 digits are possible in each position)

An online attack should be pretty infeasible with that many guesses.  At 10 guesses per second, it would take an average of about 14 years.

Sounds like there are some details that aren&#039;t available about this vulnerability yet.</description>
		<content:encoded><![CDATA[<p>I would like some more information on the numbers that he &#8220;simply guessed&#8221;.  There must be more of a pattern than is mentioned in the wired article.  The number combination he guessed is: </p>
<p>V23444 – E5444</p>
<p>Even understanding that the first character will be only A, E, or V, that still leaves 9 base-10 digits of entropy in addition to those two 3-character slots. <br />
If my understanding is correct, the number of permutations could be calculated with 3*10*10*10*10*10*3*10*10*10*10 =  9,000,000,000  (because 3 letters and 10 digits are possible in each position)</p>
<p>An online attack should be pretty infeasible with that many guesses.  At 10 guesses per second, it would take an average of about 14 years.</p>
<p>Sounds like there are some details that aren&#8217;t available about this vulnerability yet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marc Mielke</title>
		<link>http://boingboing.net/2012/12/04/blogger-proves-flaws-in-ecuado.html#comment-1598289</link>
		<dc:creator>Marc Mielke</dc:creator>
		<pubDate>Tue, 04 Dec 2012 19:10:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=198133#comment-1598289</guid>
		<description>&quot;The third was a set of two numbers from an identity card, which he simply guessed.&quot;

??? Unless he was happy with a 1% chance of success, there&#039;s more to this part. </description>
		<content:encoded><![CDATA[<p>&#8220;The third was a set of two numbers from an identity card, which he simply guessed.&#8221;</p>
<p>??? Unless he was happy with a 1% chance of success, there&#8217;s more to this part. </p>
]]></content:encoded>
	</item>
</channel>
</rss>
