<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PhoneFactor 1.0</title>
	<atom:link href="http://alexking.org/blog/2008/06/27/phonefactor-10/feed" rel="self" type="application/rss+xml" />
	<link>http://alexking.org/blog/2008/06/27/phonefactor-10</link>
	<description>Alex King, Denver Web Developer</description>
	<lastBuildDate>Wed, 08 Feb 2012 13:45:57 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: MHeinrich</title>
		<link>http://alexking.org/blog/2008/06/27/phonefactor-10#comment-64883</link>
		<dc:creator>MHeinrich</dc:creator>
		<pubDate>Fri, 03 Oct 2008 04:18:23 +0000</pubDate>
		<guid isPermaLink="false">http://alexking.org/blog/2008/06/27/phonefactor-10#comment-64883</guid>
		<description>I think those are valid concerns, but I have to say that the reality of recovering from all of those situations with my phone is much simpler/convenient than any of the alternative problems with tokens. Have you ever had to carry a SecurID token or keep track of a PKI certificate? I prefer waterboarding to being the IT person that has to manage that. And if you&#039;re a consumer, way too expensive for anything but the most valuable of web properties (e.g. E*trade account with 50k in it). 

Worst case, I can&#039;t login unless I have a phone signal and my charger. If I lose my cell phone, I have to replace it anyhow. If I lose a token or cert, again ... waterboarding, please.</description>
		<content:encoded><![CDATA[<p>I think those are valid concerns, but I have to say that the reality of recovering from all of those situations with my phone is much simpler/convenient than any of the alternative problems with tokens. Have you ever had to carry a SecurID token or keep track of a PKI certificate? I prefer waterboarding to being the IT person that has to manage that. And if you&#8217;re a consumer, way too expensive for anything but the most valuable of web properties (e.g. E*trade account with 50k in it). </p>
<p>Worst case, I can&#8217;t login unless I have a phone signal and my charger. If I lose my cell phone, I have to replace it anyhow. If I lose a token or cert, again &#8230; waterboarding, please.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rich</title>
		<link>http://alexking.org/blog/2008/06/27/phonefactor-10#comment-64875</link>
		<dc:creator>Rich</dc:creator>
		<pubDate>Thu, 02 Oct 2008 15:05:36 +0000</pubDate>
		<guid isPermaLink="false">http://alexking.org/blog/2008/06/27/phonefactor-10#comment-64875</guid>
		<description>What happens if you lose your phone, run out of batteries, or just dont get a singnal?</description>
		<content:encoded><![CDATA[<p>What happens if you lose your phone, run out of batteries, or just dont get a singnal?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan</title>
		<link>http://alexking.org/blog/2008/06/27/phonefactor-10#comment-64624</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Tue, 09 Sep 2008 23:52:36 +0000</pubDate>
		<guid isPermaLink="false">http://alexking.org/blog/2008/06/27/phonefactor-10#comment-64624</guid>
		<description>This is fantastic!
Sorry for bumping and commenting on a old post, but this is a brilliant addon.</description>
		<content:encoded><![CDATA[<p>This is fantastic!<br />
Sorry for bumping and commenting on a old post, but this is a brilliant addon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Prevent Your WordPress Blog From Getting Hacked</title>
		<link>http://alexking.org/blog/2008/06/27/phonefactor-10#comment-64452</link>
		<dc:creator>Prevent Your WordPress Blog From Getting Hacked</dc:creator>
		<pubDate>Sat, 30 Aug 2008 03:33:13 +0000</pubDate>
		<guid isPermaLink="false">http://alexking.org/blog/2008/06/27/phonefactor-10#comment-64452</guid>
		<description>[...] You can learn more about Phone Factor and download it here. [...]</description>
		<content:encoded><![CDATA[<p>[...] You can learn more about Phone Factor and download it here. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hypotheek</title>
		<link>http://alexking.org/blog/2008/06/27/phonefactor-10#comment-64148</link>
		<dc:creator>hypotheek</dc:creator>
		<pubDate>Wed, 06 Aug 2008 07:25:49 +0000</pubDate>
		<guid isPermaLink="false">http://alexking.org/blog/2008/06/27/phonefactor-10#comment-64148</guid>
		<description>This is a very cool plugin. I do agree with some of the comments that there might be some limitations if there is any problem in the chain of layers. But i think if there is a concrete error, you can alway&#039;s enter your server and change and get into wordpress. I generaly like it.</description>
		<content:encoded><![CDATA[<p>This is a very cool plugin. I do agree with some of the comments that there might be some limitations if there is any problem in the chain of layers. But i think if there is a concrete error, you can alway&#8217;s enter your server and change and get into wordpress. I generaly like it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63973</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Wed, 23 Jul 2008 18:46:19 +0000</pubDate>
		<guid isPermaLink="false">http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63973</guid>
		<description>&lt;blockquote&gt;I presume if you MUST access your blog and the service is down, you can just log into the server and delete the plugin file?&lt;/blockquote&gt;

Yes, that would work fine.</description>
		<content:encoded><![CDATA[<blockquote><p>I presume if you MUST access your blog and the service is down, you can just log into the server and delete the plugin file?</p></blockquote>
<p>Yes, that would work fine.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paradox</title>
		<link>http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63972</link>
		<dc:creator>Paradox</dc:creator>
		<pubDate>Wed, 23 Jul 2008 18:45:06 +0000</pubDate>
		<guid isPermaLink="false">http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63972</guid>
		<description>Interesting. I saw the ad for this service on tv, and thought it might be useful.

Ill have to try it.

I presume if you MUST access your blog and the service is down, you can just log into the server and delete the plugin file?</description>
		<content:encoded><![CDATA[<p>Interesting. I saw the ad for this service on tv, and thought it might be useful.</p>
<p>Ill have to try it.</p>
<p>I presume if you MUST access your blog and the service is down, you can just log into the server and delete the plugin file?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63947</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Mon, 21 Jul 2008 13:32:20 +0000</pubDate>
		<guid isPermaLink="false">http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63947</guid>
		<description>Interesting. I&#039;ve got bit about Crowd Favorite on my home page, in my sidebar, and I listed this as a &quot;Case Study&quot;... I guess I thought I was making it clear that it was something we built. I never intended not to.</description>
		<content:encoded><![CDATA[<p>Interesting. I&#8217;ve got bit about Crowd Favorite on my home page, in my sidebar, and I listed this as a &#8220;Case Study&#8221;&#8230; I guess I thought I was making it clear that it was something we built. I never intended not to.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Guy Rintoul</title>
		<link>http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63946</link>
		<dc:creator>Guy Rintoul</dc:creator>
		<pubDate>Mon, 21 Jul 2008 11:38:30 +0000</pubDate>
		<guid isPermaLink="false">http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63946</guid>
		<description>Alex,

Just a suggestion - in the interests of openness, it may be better to explicitly call out that Crowd Favorite is your company. While I see you&#039;ve used &#039;we&#039; and &#039;us&#039; in the post, it does come across like you&#039;re trying to give an impartial review of a product - which you&#039;re not. Most bloggers would put an explicit disclaimer in their post to avoid any perception of underhand bias...

Guy</description>
		<content:encoded><![CDATA[<p>Alex,</p>
<p>Just a suggestion &#8211; in the interests of openness, it may be better to explicitly call out that Crowd Favorite is your company. While I see you&#8217;ve used &#8216;we&#8217; and &#8216;us&#8217; in the post, it does come across like you&#8217;re trying to give an impartial review of a product &#8211; which you&#8217;re not. Most bloggers would put an explicit disclaimer in their post to avoid any perception of underhand bias&#8230;</p>
<p>Guy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PhoneFactor Makes WordPress Logins More Secure than Most Online Bank Accounts &#124; PhoneFactor</title>
		<link>http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63904</link>
		<dc:creator>PhoneFactor Makes WordPress Logins More Secure than Most Online Bank Accounts &#124; PhoneFactor</dc:creator>
		<pubDate>Thu, 17 Jul 2008 14:12:16 +0000</pubDate>
		<guid isPermaLink="false">http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63904</guid>
		<description>[...] today announced that PhoneFactor, its phone-based authentication technology, is available as a free plug-in to WordPress, the largest self-hosted blogging tool in the world. With PhoneFactor, WordPressâ€™ hundreds of [...]</description>
		<content:encoded><![CDATA[<p>[...] today announced that PhoneFactor, its phone-based authentication technology, is available as a free plug-in to WordPress, the largest self-hosted blogging tool in the world. With PhoneFactor, WordPressâ€™ hundreds of [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff</title>
		<link>http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63748</link>
		<dc:creator>Jeff</dc:creator>
		<pubDate>Thu, 03 Jul 2008 20:29:15 +0000</pubDate>
		<guid isPermaLink="false">http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63748</guid>
		<description>Sorry about the spam everyone.

An overzealous intern recruited some friends back home (yes - India) and went a little post crazy.

They have been reprimanded and it has been stopped immediately.

Alex, nor his team at Crowd Favorite had anything to do with this.

Our apologies.

PhoneFactor Product Team</description>
		<content:encoded><![CDATA[<p>Sorry about the spam everyone.</p>
<p>An overzealous intern recruited some friends back home (yes &#8211; India) and went a little post crazy.</p>
<p>They have been reprimanded and it has been stopped immediately.</p>
<p>Alex, nor his team at Crowd Favorite had anything to do with this.</p>
<p>Our apologies.</p>
<p>PhoneFactor Product Team</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Nielsen</title>
		<link>http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63746</link>
		<dc:creator>Chris Nielsen</dc:creator>
		<pubDate>Thu, 03 Jul 2008 19:42:48 +0000</pubDate>
		<guid isPermaLink="false">http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63746</guid>
		<description>I&#039;m here as well because someone named &quot;breanan&quot; posted about this WP plugin:

 I DARE YOU TO STEAL MY BLOG

You canâ€™t with this new WP plugin. Developed by the master himself, alex king.
http://wordpress.org/extend/plugins/phonefactor/

I find it hard to believe that you don&#039;t know this person or have not hired them to promote your plug in. Perhaps they are connected with the phone service that is used...?

But if it&#039;s true I would distance yourself from them as much as possible and consider using another phone service that doesn&#039;t need to spam. Nice feature, by the way, but overkill in my opinion just to keep someone from logging into a blog. And it still has nice options for abuse... :-)</description>
		<content:encoded><![CDATA[<p>I&#8217;m here as well because someone named &#8220;breanan&#8221; posted about this WP plugin:</p>
<p> I DARE YOU TO STEAL MY BLOG</p>
<p>You canâ€™t with this new WP plugin. Developed by the master himself, alex king.<br />
<a href="http://wordpress.org/extend/plugins/phonefactor/" rel="nofollow">http://wordpress.org[...]phonefactor/</a></p>
<p>I find it hard to believe that you don&#8217;t know this person or have not hired them to promote your plug in. Perhaps they are connected with the phone service that is used&#8230;?</p>
<p>But if it&#8217;s true I would distance yourself from them as much as possible and consider using another phone service that doesn&#8217;t need to spam. Nice feature, by the way, but overkill in my opinion just to keep someone from logging into a blog. And it still has nice options for abuse&#8230; <img src='http://alexking.org/wp/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63740</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Thu, 03 Jul 2008 15:49:53 +0000</pubDate>
		<guid isPermaLink="false">http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63740</guid>
		<description>I have no idea who is doing the spamming, but I can assure you it is &lt;em&gt;not&lt;/em&gt; Crowd Favorite (which is my company). We built the plugin and I posted this blog post, which is all we&#039;ve done the publicize it.</description>
		<content:encoded><![CDATA[<p>I have no idea who is doing the spamming, but I can assure you it is <em>not</em> Crowd Favorite (which is my company). We built the plugin and I posted this blog post, which is all we&#8217;ve done the publicize it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dr. Mike Wendell</title>
		<link>http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63739</link>
		<dc:creator>Dr. Mike Wendell</dc:creator>
		<pubDate>Thu, 03 Jul 2008 15:26:51 +0000</pubDate>
		<guid isPermaLink="false">http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63739</guid>
		<description>Alex, while I agree with you that this is a great idea, could you please drop a hint to Crowd Favorite to knock off the spamming.  They&#039;ve hit a large number of sites, including the typepad, movable type, drupal, and edublogs support forums.  It really gives wordpress a bad name to see a plugin promoted via spam and to see your name associated with this.

http://wordpress.org/support/topic/186359</description>
		<content:encoded><![CDATA[<p>Alex, while I agree with you that this is a great idea, could you please drop a hint to Crowd Favorite to knock off the spamming.  They&#8217;ve hit a large number of sites, including the typepad, movable type, drupal, and edublogs support forums.  It really gives wordpress a bad name to see a plugin promoted via spam and to see your name associated with this.</p>
<p><a href="http://wordpress.org/support/topic/186359" rel="nofollow">http://wordpress.org[...]topic/186359</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: paan</title>
		<link>http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63729</link>
		<dc:creator>paan</dc:creator>
		<pubDate>Thu, 03 Jul 2008 01:50:53 +0000</pubDate>
		<guid isPermaLink="false">http://alexking.org/blog/2008/06/27/phonefactor-10#comment-63729</guid>
		<description>the phone calls acts as a second authentication channel. 
It is typical in security to add another, usually from a diffferent technology domain, authetication channel so that anyone that wants to steal your account will have to get your credential on both channel. 

In other words. Some one trying to steal your account will have to get your password AND have access to your phone calls. 

You don&#039;t authenticate yourself with the phone number but as david said the phone call is the authentication process.</description>
		<content:encoded><![CDATA[<p>the phone calls acts as a second authentication channel.<br />
It is typical in security to add another, usually from a diffferent technology domain, authetication channel so that anyone that wants to steal your account will have to get your credential on both channel. </p>
<p>In other words. Some one trying to steal your account will have to get your password AND have access to your phone calls. </p>
<p>You don&#8217;t authenticate yourself with the phone number but as david said the phone call is the authentication process.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

