<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Insecure Cryptographic Storage</title>
	<atom:link href="http://misc-security.com/2009/09/16/insecure-cryptographic-storage/feed/" rel="self" type="application/rss+xml" />
	<link>http://misc-security.com/2009/09/16/insecure-cryptographic-storage/</link>
	<description></description>
	<lastBuildDate>Wed, 03 Feb 2010 20:34:51 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Aaron Grattafiori</title>
		<link>http://misc-security.com/2009/09/16/insecure-cryptographic-storage/comment-page-1/#comment-41</link>
		<dc:creator>Aaron Grattafiori</dc:creator>
		<pubDate>Wed, 30 Sep 2009 04:09:05 +0000</pubDate>
		<guid isPermaLink="false">http://misc-security.com/?p=250#comment-41</guid>
		<description>Also.. People that store hashes of CC #s without properly salting them can be asking for trouble, the &quot;keyspace&quot; for  of CC numbers isn&#039;t very big.</description>
		<content:encoded><![CDATA[<p>Also.. People that store hashes of CC #s without properly salting them can be asking for trouble, the &#8220;keyspace&#8221; for  of CC numbers isn&#8217;t very big.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron Grattafiori</title>
		<link>http://misc-security.com/2009/09/16/insecure-cryptographic-storage/comment-page-1/#comment-40</link>
		<dc:creator>Aaron Grattafiori</dc:creator>
		<pubDate>Wed, 30 Sep 2009 04:05:36 +0000</pubDate>
		<guid isPermaLink="false">http://misc-security.com/?p=250#comment-40</guid>
		<description>Bruce Schneier in one of his books wrote something along the lines of: &quot;The person that invents their own crypto algorithm (I think he said primitive) is either a genius, or a fool.  Looking at the typical ratio, the odds aren&#039;t good.&quot;. I thought that was a clever way to do it and honestly quite truthful.</description>
		<content:encoded><![CDATA[<p>Bruce Schneier in one of his books wrote something along the lines of: &#8220;The person that invents their own crypto algorithm (I think he said primitive) is either a genius, or a fool.  Looking at the typical ratio, the odds aren&#8217;t good.&#8221;. I thought that was a clever way to do it and honestly quite truthful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BrettH</title>
		<link>http://misc-security.com/2009/09/16/insecure-cryptographic-storage/comment-page-1/#comment-35</link>
		<dc:creator>BrettH</dc:creator>
		<pubDate>Mon, 21 Sep 2009 17:08:50 +0000</pubDate>
		<guid isPermaLink="false">http://misc-security.com/?p=250#comment-35</guid>
		<description>I hope that the team lead and the project manager realized this was a bad idea and changed the way that passwords are being encrypted.

These are the types of security problems that should have maximum visibility to the whole business unit.</description>
		<content:encoded><![CDATA[<p>I hope that the team lead and the project manager realized this was a bad idea and changed the way that passwords are being encrypted.</p>
<p>These are the types of security problems that should have maximum visibility to the whole business unit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nitin Reddy Katkam</title>
		<link>http://misc-security.com/2009/09/16/insecure-cryptographic-storage/comment-page-1/#comment-34</link>
		<dc:creator>Nitin Reddy Katkam</dc:creator>
		<pubDate>Mon, 21 Sep 2009 16:42:22 +0000</pubDate>
		<guid isPermaLink="false">http://misc-security.com/?p=250#comment-34</guid>
		<description>I recently hear a conversation in which the project manager asked a lead developer, &quot;How are we encrypting passwords while storing them in the database?&quot;  The response was, &quot;I don&#039;t know. We downloaded a Microsoft Enterprise Library block from the Internet and are using it through the membership provider in ASP.NET.&quot;

Even if we are using a very weak algorithm with a private key copy-pasted directly off a web page on the Internet, the response by the team lead created a pretty good sense of security for the project manager. :-D</description>
		<content:encoded><![CDATA[<p>I recently hear a conversation in which the project manager asked a lead developer, &#8220;How are we encrypting passwords while storing them in the database?&#8221;  The response was, &#8220;I don&#8217;t know. We downloaded a Microsoft Enterprise Library block from the Internet and are using it through the membership provider in ASP.NET.&#8221;</p>
<p>Even if we are using a very weak algorithm with a private key copy-pasted directly off a web page on the Internet, the response by the team lead created a pretty good sense of security for the project manager. :-D</p>
]]></content:encoded>
	</item>
</channel>
</rss>
