<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Small Is Beautiful</title>
	<link>http://www.blindside.org.uk/2007/12/06/small-is-beautiful/</link>
	<description>What's going to go wrong in our e-enabled world?</description>
	<pubDate>Thu, 20 Nov 2008 11:53:15 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.1</generator>
		<item>
		<title>By: Tom Fuller</title>
		<link>http://www.blindside.org.uk/2007/12/06/small-is-beautiful/#comment-4960</link>
		<dc:creator>Tom Fuller</dc:creator>
		<pubDate>Thu, 06 Dec 2007 10:35:46 +0000</pubDate>
		<guid>http://www.blindside.org.uk/2007/12/06/small-is-beautiful/#comment-4960</guid>
		<description>Hi Ian,

Thanks for this.

How many characters should the password contain, and what proportion should be non-alphabetic--do you happen to know? I think that a lot of mid-level government staff would be able to use this information.</description>
		<content:encoded><![CDATA[<p>Hi Ian,</p>
<p>Thanks for this.</p>
<p>How many characters should the password contain, and what proportion should be non-alphabetic&#8211;do you happen to know? I think that a lot of mid-level government staff would be able to use this information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian Brown</title>
		<link>http://www.blindside.org.uk/2007/12/06/small-is-beautiful/#comment-4957</link>
		<dc:creator>Ian Brown</dc:creator>
		<pubDate>Thu, 06 Dec 2007 09:59:32 +0000</pubDate>
		<guid>http://www.blindside.org.uk/2007/12/06/small-is-beautiful/#comment-4957</guid>
		<description>No. WinZip 9.0 contains AES (the recent US govt-approved Advanced Encryption Standard) which is secure *if* a password of adequate strength is used. A 10-character password does not qualify and could be guessed trivially by password cracking software. Key management is much harder than just using an appropriate cipher.</description>
		<content:encoded><![CDATA[<p>No. WinZip 9.0 contains AES (the recent US govt-approved Advanced Encryption Standard) which is secure *if* a password of adequate strength is used. A 10-character password does not qualify and could be guessed trivially by password cracking software. Key management is much harder than just using an appropriate cipher.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.069 seconds -->
