<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: MySQL password security</title>
	<atom:link href="http://mituzas.lt/2009/03/08/mysql-password-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://mituzas.lt/2009/03/08/mysql-password-security/</link>
	<description></description>
	<lastBuildDate>Fri, 30 Jul 2010 21:52:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1-alpha</generator>
	<item>
		<title>By: tobe</title>
		<link>http://mituzas.lt/2009/03/08/mysql-password-security/comment-page-1/#comment-188935</link>
		<dc:creator>tobe</dc:creator>
		<pubDate>Mon, 09 Mar 2009 21:58:28 +0000</pubDate>
		<guid isPermaLink="false">http://dammit.lt/?p=383#comment-188935</guid>
		<description>Anyway, thermal cryptanalysis can be involved against any cryptosystem. Take a hot iron and apply it on the DBA untill THE password is recovered.

P.S. Congratulations. 

P.P.S The devil hides in detail (a.k.a key exchange). Hopefully not this time.</description>
		<content:encoded><![CDATA[<p>Anyway, thermal cryptanalysis can be involved against any cryptosystem. Take a hot iron and apply it on the DBA untill THE password is recovered.</p>
<p>P.S. Congratulations. </p>
<p>P.P.S The devil hides in detail (a.k.a key exchange). Hopefully not this time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Domas Mituzas</title>
		<link>http://mituzas.lt/2009/03/08/mysql-password-security/comment-page-1/#comment-188930</link>
		<dc:creator>Domas Mituzas</dc:creator>
		<pubDate>Mon, 09 Mar 2009 07:55:33 +0000</pubDate>
		<guid isPermaLink="false">http://dammit.lt/?p=383#comment-188930</guid>
		<description>Arjen, the very original design cover both, but not at the same time. 
Did you suggest asymmetric encryption? That is the only way to pass a token over internet without tradeoffs of usual challenge-response schemes.

Of course, there is also Diffie-Hellman style key exchange, but it is quite an overhead for unencrypted fast connection... </description>
		<content:encoded><![CDATA[<p>Arjen, the very original design cover both, but not at the same time.<br />
Did you suggest asymmetric encryption? That is the only way to pass a token over internet without tradeoffs of usual challenge-response schemes.</p>
<p>Of course, there is also Diffie-Hellman style key exchange, but it is quite an overhead for unencrypted fast connection&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arjen Lentz</title>
		<link>http://mituzas.lt/2009/03/08/mysql-password-security/comment-page-1/#comment-188927</link>
		<dc:creator>Arjen Lentz</dc:creator>
		<pubDate>Sun, 08 Mar 2009 23:39:37 +0000</pubDate>
		<guid isPermaLink="false">http://dammit.lt/?p=383#comment-188927</guid>
		<description>The original design for the 4.1 scheme (by serg and I) did have both covered, but the implementation got completely borked.</description>
		<content:encoded><![CDATA[<p>The original design for the 4.1 scheme (by serg and I) did have both covered, but the implementation got completely borked.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Suzanne Axtell</title>
		<link>http://mituzas.lt/2009/03/08/mysql-password-security/comment-page-1/#comment-188926</link>
		<dc:creator>Suzanne Axtell</dc:creator>
		<pubDate>Sun, 08 Mar 2009 21:11:02 +0000</pubDate>
		<guid isPermaLink="false">http://dammit.lt/?p=383#comment-188926</guid>
		<description>Thanks, Domas, that is a *great* shameless plug! :)</description>
		<content:encoded><![CDATA[<p>Thanks, Domas, that is a *great* shameless plug! :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
