<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Security vs. usability</title>
	<atom:link href="http://log.reflectivesurface.com/2004/01/21/security-vs-usability/feed/" rel="self" type="application/rss+xml" />
	<link>http://log.reflectivesurface.com/2004/01/21/security-vs-usability/</link>
	<description>Still powered by a contradiction in terms</description>
	<pubDate>Thu, 20 Nov 2008 14:20:39 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: Ronaldo</title>
		<link>http://log.reflectivesurface.com/2004/01/21/security-vs-usability/#comment-250</link>
		<dc:creator>Ronaldo</dc:creator>
		<pubDate>Thu, 22 Jan 2004 03:13:31 +0000</pubDate>
		<guid isPermaLink="false">http://log.reflectivesurface.com/2004/01/21/security-vs-usability/#comment-250</guid>
		<description>You're quite right. I hadn't thought about it from this point of view. I guess that goes to prove that security is even harder to do right than it appears. Preventing the attack while still allowing valid users access to the system seems a tough problem.
</description>
		<content:encoded><![CDATA[<p>You&#8217;re quite right. I hadn&#8217;t thought about it from this point of view. I guess that goes to prove that security is even harder to do right than it appears. Preventing the attack while still allowing valid users access to the system seems a tough problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simon Willison</title>
		<link>http://log.reflectivesurface.com/2004/01/21/security-vs-usability/#comment-249</link>
		<dc:creator>Simon Willison</dc:creator>
		<pubDate>Wed, 21 Jan 2004 19:29:00 +0000</pubDate>
		<guid isPermaLink="false">http://log.reflectivesurface.com/2004/01/21/security-vs-usability/#comment-249</guid>
		<description>I actually see this feature as a security problem rather than a usability problem, as it introduces the ability for malicious parties to "deny service" to other users provided they know their user name. Enter the username and an incorrect password a few dozen times and you've locked your victim out of the system.</description>
		<content:encoded><![CDATA[<p>I actually see this feature as a security problem rather than a usability problem, as it introduces the ability for malicious parties to &#8220;deny service&#8221; to other users provided they know their user name. Enter the username and an incorrect password a few dozen times and you&#8217;ve locked your victim out of the system.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
