<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Now is a good time to re-set your Twitter password and disable Java in your&#160;browser</title>
	<atom:link href="http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html/feed" rel="self" type="application/rss+xml" />
	<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html</link>
	<description>Brain candy for Happy Mutants</description>
	<lastBuildDate>Wed, 22 May 2013 16:06:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Kimmo</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644845</link>
		<dc:creator>Kimmo</dc:creator>
		<pubDate>Sun, 03 Feb 2013 10:32:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644845</guid>
		<description>And that would be precisely what I seemed to recall.

&lt;3 Randall Munroe.</description>
		<content:encoded><![CDATA[<p>And that would be precisely what I seemed to recall.</p>
<p>&lt;3 Randall Munroe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charlie B</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644780</link>
		<dc:creator>Charlie B</dc:creator>
		<pubDate>Sun, 03 Feb 2013 04:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644780</guid>
		<description>Netscape&#039;s strategy of renaming livecript &quot;javascript&quot; was fscking brilliant, eh?  Several million bucks of advertising... paid for by Sun.  Of course in the end Oracle and Microsoft ate them both.</description>
		<content:encoded><![CDATA[<p>Netscape&#8217;s strategy of renaming livecript &#8220;javascript&#8221; was fscking brilliant, eh?  Several million bucks of advertising&#8230; paid for by Sun.  Of course in the end Oracle and Microsoft ate them both.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charlie B</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644778</link>
		<dc:creator>Charlie B</dc:creator>
		<pubDate>Sun, 03 Feb 2013 03:56:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644778</guid>
		<description>NASA.  I told them not to, but they got all pissed off.

I am totally not kidding. </description>
		<content:encoded><![CDATA[<p>NASA.  I told them not to, but they got all pissed off.</p>
<p>I am totally not kidding. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sign Ahead</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644686</link>
		<dc:creator>Sign Ahead</dc:creator>
		<pubDate>Sat, 02 Feb 2013 22:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644686</guid>
		<description>That&#039;s exactly what I was doing. Thank you, Aleknevicus!</description>
		<content:encoded><![CDATA[<p>That&#8217;s exactly what I was doing. Thank you, Aleknevicus!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aleknevicus</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644671</link>
		<dc:creator>Aleknevicus</dc:creator>
		<pubDate>Sat, 02 Feb 2013 21:16:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644671</guid>
		<description>Make sure you&#039;re not mistaking Javascript for Java (they&#039;re not the same). The former is very commonly used, the latter much less so. You&#039;d have to have very out of the ordinary browsing habits if most of the websites you use require Java.</description>
		<content:encoded><![CDATA[<p>Make sure you&#8217;re not mistaking Javascript for Java (they&#8217;re not the same). The former is very commonly used, the latter much less so. You&#8217;d have to have very out of the ordinary browsing habits if most of the websites you use require Java.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rindan</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644637</link>
		<dc:creator>Rindan</dc:creator>
		<pubDate>Sat, 02 Feb 2013 19:32:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644637</guid>
		<description>This is a valuable lesson in why you should use a password locker of some flavor.  When one of these sites gets hacked, I just setup another random string for a password and call it a day.  If all your passwords are different, you don&#039;t need to trust anyone to secure your password.  Toss on a layer of 2-step into your e-mail and baking stuff and you are golden.  You are not impervious to an attack, but you are far harder than most people and probably only are vulnerable if someone is specifically out to get you personally.</description>
		<content:encoded><![CDATA[<p>This is a valuable lesson in why you should use a password locker of some flavor.  When one of these sites gets hacked, I just setup another random string for a password and call it a day.  If all your passwords are different, you don&#8217;t need to trust anyone to secure your password.  Toss on a layer of 2-step into your e-mail and baking stuff and you are golden.  You are not impervious to an attack, but you are far harder than most people and probably only are vulnerable if someone is specifically out to get you personally.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sign Ahead</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644608</link>
		<dc:creator>Sign Ahead</dc:creator>
		<pubDate>Sat, 02 Feb 2013 17:51:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644608</guid>
		<description>My computer expertise is limited to some very specific applications. Outside of those, I&#039;m only moderately competent, so I think I missed something important in this discussion.

Yesterday, I disabled Java (in Google Chrome) and tried navigating the web. Most of the sites I use regularly, for work and entertainment, stopped working. There were key functions I simply couldn&#039;t use without Java enabled. Is there a workaround for this? Or is it simply a choice between usability and safety?</description>
		<content:encoded><![CDATA[<p>My computer expertise is limited to some very specific applications. Outside of those, I&#8217;m only moderately competent, so I think I missed something important in this discussion.</p>
<p>Yesterday, I disabled Java (in Google Chrome) and tried navigating the web. Most of the sites I use regularly, for work and entertainment, stopped working. There were key functions I simply couldn&#8217;t use without Java enabled. Is there a workaround for this? Or is it simply a choice between usability and safety?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dragonfrog</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644567</link>
		<dc:creator>dragonfrog</dc:creator>
		<pubDate>Sat, 02 Feb 2013 16:01:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644567</guid>
		<description>As ohbejoyful says - lots and lots of enterprise-y systems rely on Java on the desktop, to overcome the horribleness of IE 6, which the entire organization is stuck using because their online timesheet system isn&#039;t supported on other browsers (it may work better on other browsers, but it isn&#039;t &lt;i&gt;supported&lt;/i&gt;).</description>
		<content:encoded><![CDATA[<p>As ohbejoyful says &#8211; lots and lots of enterprise-y systems rely on Java on the desktop, to overcome the horribleness of IE 6, which the entire organization is stuck using because their online timesheet system isn&#8217;t supported on other browsers (it may work better on other browsers, but it isn&#8217;t <i>supported</i>).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hugh Johnson</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644553</link>
		<dc:creator>Hugh Johnson</dc:creator>
		<pubDate>Sat, 02 Feb 2013 15:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644553</guid>
		<description> Shocked kitty!</description>
		<content:encoded><![CDATA[<p> Shocked kitty!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: millie fink</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644534</link>
		<dc:creator>millie fink</dc:creator>
		<pubDate>Sat, 02 Feb 2013 13:59:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644534</guid>
		<description>Can&#039;t be good if it&#039;s not weird.</description>
		<content:encoded><![CDATA[<p>Can&#8217;t be good if it&#8217;s not weird.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MarcVader</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644519</link>
		<dc:creator>MarcVader</dc:creator>
		<pubDate>Sat, 02 Feb 2013 12:20:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644519</guid>
		<description> Dammit! I&#039;ll have to change all these passwords from &quot;password&quot; to &quot;1234password&quot; now!! FML</description>
		<content:encoded><![CDATA[<p> Dammit! I&#8217;ll have to change all these passwords from &#8220;password&#8221; to &#8220;1234password&#8221; now!! FML</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aleknevicus</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644429</link>
		<dc:creator>Aleknevicus</dc:creator>
		<pubDate>Sat, 02 Feb 2013 07:44:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644429</guid>
		<description>I think you&#039;ve missed what Kimmo was suggesting/enquiring about: Rather that using 6 characters chosen from a set of 72, isn&#039;t it better to choose more than 6 characters from a set of 26?

The answer is yes, so long as you choose 8 or more characters:

72^6 ~= 139 billion
26^8 ~= 208 billion

(And importantly, as per the XKCD reference, it can actually be *easier* for a human to remember a 20-character password made up from the lowercase alphabet, than it is to remember a 10-character password made up from a set of 72.)</description>
		<content:encoded><![CDATA[<p>I think you&#8217;ve missed what Kimmo was suggesting/enquiring about: Rather that using 6 characters chosen from a set of 72, isn&#8217;t it better to choose more than 6 characters from a set of 26?</p>
<p>The answer is yes, so long as you choose 8 or more characters:</p>
<p>72^6 ~= 139 billion<br />
26^8 ~= 208 billion</p>
<p>(And importantly, as per the XKCD reference, it can actually be *easier* for a human to remember a 20-character password made up from the lowercase alphabet, than it is to remember a 10-character password made up from a set of 72.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rezeya Montecore</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644386</link>
		<dc:creator>Rezeya Montecore</dc:creator>
		<pubDate>Sat, 02 Feb 2013 05:31:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644386</guid>
		<description>And they forgot to tell us about their &quot;1 weird clue.&quot;</description>
		<content:encoded><![CDATA[<p>And they forgot to tell us about their &#8220;1 weird clue.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: robuluz</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644377</link>
		<dc:creator>robuluz</dc:creator>
		<pubDate>Sat, 02 Feb 2013 05:12:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644377</guid>
		<description>I kind of thought it would be someone like that.</description>
		<content:encoded><![CDATA[<p>I kind of thought it would be someone like that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ohbejoyful</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644368</link>
		<dc:creator>ohbejoyful</dc:creator>
		<pubDate>Sat, 02 Feb 2013 05:01:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644368</guid>
		<description>The html interface to a lot of Oracle systems use java, which means lots of people in very large companies have to have it turned on, at least in one browser.</description>
		<content:encoded><![CDATA[<p>The html interface to a lot of Oracle systems use java, which means lots of people in very large companies have to have it turned on, at least in one browser.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dragonfrog</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644359</link>
		<dc:creator>dragonfrog</dc:creator>
		<pubDate>Sat, 02 Feb 2013 04:39:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644359</guid>
		<description> Only if you&#039;re choosing fully at random among the character set for your password.  Which you&#039;re not.</description>
		<content:encoded><![CDATA[<p> Only if you&#8217;re choosing fully at random among the character set for your password.  Which you&#8217;re not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: compfeznetau</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644327</link>
		<dc:creator>compfeznetau</dc:creator>
		<pubDate>Sat, 02 Feb 2013 03:36:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644327</guid>
		<description> Link is down?</description>
		<content:encoded><![CDATA[<p> Link is down?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David_Gervais</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644321</link>
		<dc:creator>David_Gervais</dc:creator>
		<pubDate>Sat, 02 Feb 2013 03:22:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644321</guid>
		<description>It&#039;s the other way round.  If you have 6 characters, all lower case, you have 26^6 possible passwords, easily brute-force broken.
Use upper and lower case; 52^6;
add ten digits;  62^6;
add 10 other chars; 72^6; at present, almost unbreakable. 
This works even better with 8 characters.



</description>
		<content:encoded><![CDATA[<p>It&#8217;s the other way round.  If you have 6 characters, all lower case, you have 26^6 possible passwords, easily brute-force broken.<br />
Use upper and lower case; 52^6;<br />
add ten digits;  62^6;<br />
add 10 other chars; 72^6; at present, almost unbreakable. <br />
This works even better with 8 characters.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: coop</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644301</link>
		<dc:creator>coop</dc:creator>
		<pubDate>Sat, 02 Feb 2013 02:57:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644301</guid>
		<description> Obligatory XKCD reference: http://xkcd.com/936/</description>
		<content:encoded><![CDATA[<p> Obligatory XKCD reference: <a href="http://xkcd.com/936/" rel="nofollow">http://xkcd.com/936/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: robuluz</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644273</link>
		<dc:creator>robuluz</dc:creator>
		<pubDate>Sat, 02 Feb 2013 02:16:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644273</guid>
		<description>Who&#039;s still running Java?</description>
		<content:encoded><![CDATA[<p>Who&#8217;s still running Java?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kimmo</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644266</link>
		<dc:creator>Kimmo</dc:creator>
		<pubDate>Sat, 02 Feb 2013 02:05:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644266</guid>
		<description>I seem to recall seeing something that said password length matters a lot more than special characters, so wouldn&#039;t something like this be quite secure?

ohmydobbsicantbelievewhatapaininthearsethisis</description>
		<content:encoded><![CDATA[<p>I seem to recall seeing something that said password length matters a lot more than special characters, so wouldn&#8217;t something like this be quite secure?</p>
<p>ohmydobbsicantbelievewhatapaininthearsethisis</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rick Adams</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644263</link>
		<dc:creator>Rick Adams</dc:creator>
		<pubDate>Sat, 02 Feb 2013 01:57:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644263</guid>
		<description>How do you expect anyone to fall for this when you use appropriate grammar?</description>
		<content:encoded><![CDATA[<p>How do you expect anyone to fall for this when you use appropriate grammar?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644252</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Sat, 02 Feb 2013 01:48:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644252</guid>
		<description>It&#039;s OK. After the last twitter compromise, I used a random-password generator. My password for twitter is now

&#124;uO(f}af94e^`GPwjjL5F7.sSRos]z~5r9Jb!MJH2A6;g7DRqk

if you can believe that. Takes me forever to type, but there&#039;s no way it&#039;s going to be cracked.</description>
		<content:encoded><![CDATA[<p>It&#8217;s OK. After the last twitter compromise, I used a random-password generator. My password for twitter is now</p>
<p>|uO(f}af94e^`GPwjjL5F7.sSRos]z~5r9Jb!MJH2A6;g7DRqk</p>
<p>if you can believe that. Takes me forever to type, but there&#8217;s no way it&#8217;s going to be cracked.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Guysmiley</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644249</link>
		<dc:creator>Guysmiley</dc:creator>
		<pubDate>Sat, 02 Feb 2013 01:39:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644249</guid>
		<description>There are so many zero day Java exploits in the wild, unless you have a clear need to have it enabled in your browser (and no, Minecraft doesn&#039;t count, download the standalone) you should have it OFF. </description>
		<content:encoded><![CDATA[<p>There are so many zero day Java exploits in the wild, unless you have a clear need to have it enabled in your browser (and no, Minecraft doesn&#8217;t count, download the standalone) you should have it OFF. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cameronhorsburgh</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644246</link>
		<dc:creator>cameronhorsburgh</dc:creator>
		<pubDate>Sat, 02 Feb 2013 01:32:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644246</guid>
		<description>So 250,000 people are going to get an email claiming to be from Twitter saying their passwords have been compromised and they need to create new ones.

Somehow, just somehow, I think a few more than 250,000 people are going to get email claiming to be from Twitter saying their passwords have been compromised and they need to create new ones. </description>
		<content:encoded><![CDATA[<p>So 250,000 people are going to get an email claiming to be from Twitter saying their passwords have been compromised and they need to create new ones.</p>
<p>Somehow, just somehow, I think a few more than 250,000 people are going to get email claiming to be from Twitter saying their passwords have been compromised and they need to create new ones. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anne Onimos</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644243</link>
		<dc:creator>Anne Onimos</dc:creator>
		<pubDate>Sat, 02 Feb 2013 01:25:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644243</guid>
		<description>Seems like it&#039;s probably an even better time to re-set your Facebook, iTunes, Google, YouTube, Pinterest, Tumblr, etc., etc. password. </description>
		<content:encoded><![CDATA[<p>Seems like it&#8217;s probably an even better time to re-set your Facebook, iTunes, Google, YouTube, Pinterest, Tumblr, etc., etc. password. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brainspore</title>
		<link>http://boingboing.net/2013/02/01/now-is-a-good-time-to-re-set-y.html#comment-1644239</link>
		<dc:creator>Brainspore</dc:creator>
		<pubDate>Sat, 02 Feb 2013 01:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=210270#comment-1644239</guid>
		<description>I CAN&#039;T BELIEVE MY MOTHER&#039;S FRIEND MAKES $21,283 A DAY WATCHING CAT VIDEOS ONLINE. BEST QUALITY PHARMACEUTICALS http://www.totallylegitproducts.cn #notascam #bejing</description>
		<content:encoded><![CDATA[<p>I CAN&#8217;T BELIEVE MY MOTHER&#8217;S FRIEND MAKES $21,283 A DAY WATCHING CAT VIDEOS ONLINE. BEST QUALITY PHARMACEUTICALS <a href="http://www.totallylegitproducts.cn" rel="nofollow">http://www.totallylegitproducts.cn</a> #notascam #bejing</p>
]]></content:encoded>
	</item>
</channel>
</rss>
