<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Weak passwords – curable with pam_cracklib</title>
	<atom:link href="http://www.ratliff.net/blog/2009/04/12/weak-passwords-%e2%80%93-curable-with-pam_cracklib/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ratliff.net/blog/2009/04/12/weak-passwords-%e2%80%93-curable-with-pam_cracklib/</link>
	<description>A blog about open source and security and open source security</description>
	<lastBuildDate>Wed, 18 Aug 2010 15:12:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: George Wilson</title>
		<link>http://www.ratliff.net/blog/2009/04/12/weak-passwords-%e2%80%93-curable-with-pam_cracklib/comment-page-1/#comment-3622</link>
		<dc:creator>George Wilson</dc:creator>
		<pubDate>Mon, 13 Apr 2009 23:59:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.ratliff.net/blog/?p=125#comment-3622</guid>
		<description>Hi Bryan,

Thanks for the informative post. Folks should know better than to use trivial passwords but we all seem to need constant reminding. pam_cracklib is certainly helpful for improving passwords. You might also want to make use of the pam_passwdqc (password quality check) module [http://linux.die.net/man/8/pam_passwdqc]. There is overlap with pam_cracklib&#039;s functionality. But pam_passwdqc allows you to enforce some additional characteristics, particularly for passphrases.

Regards,
George Wilson</description>
		<content:encoded><![CDATA[<p>Hi Bryan,</p>
<p>Thanks for the informative post. Folks should know better than to use trivial passwords but we all seem to need constant reminding. pam_cracklib is certainly helpful for improving passwords. You might also want to make use of the pam_passwdqc (password quality check) module [http://linux.die.net/man/8/pam_passwdqc]. There is overlap with pam_cracklib&#8217;s functionality. But pam_passwdqc allows you to enforce some additional characteristics, particularly for passphrases.</p>
<p>Regards,<br />
George Wilson</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Emily Ratliff</title>
		<link>http://www.ratliff.net/blog/2009/04/12/weak-passwords-%e2%80%93-curable-with-pam_cracklib/comment-page-1/#comment-3621</link>
		<dc:creator>Emily Ratliff</dc:creator>
		<pubDate>Mon, 13 Apr 2009 14:48:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.ratliff.net/blog/?p=125#comment-3621</guid>
		<description>Hi Bryan,

Thanks for leading off the guest blog entries!

Dark Reading also had a recent article about analyzing passwords used on phpbb.com which shown that passwords have not really improved all that much since 2006! See http://www.darkreading.com/blog/archives/2009/02/phpbb_password.html

Thanks for posting this useful info!

Emily</description>
		<content:encoded><![CDATA[<p>Hi Bryan,</p>
<p>Thanks for leading off the guest blog entries!</p>
<p>Dark Reading also had a recent article about analyzing passwords used on phpbb.com which shown that passwords have not really improved all that much since 2006! See <a href="http://www.darkreading.com/blog/archives/2009/02/phpbb_password.html" rel="nofollow">http://www.darkreading.com/blog/archives/2009/02/phpbb_password.html</a></p>
<p>Thanks for posting this useful info!</p>
<p>Emily</p>
]]></content:encoded>
	</item>
</channel>
</rss>
