<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: RoboForm &amp; RoboForm2Go Product Review</title>
	<atom:link href="http://www.technicallychris.com/2009/08/24/roboform-roboform2go-product-review/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.technicallychris.com/2009/08/24/roboform-roboform2go-product-review/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=roboform-roboform2go-product-review</link>
	<description>Technical and Personal Ramblings of a Bostonian</description>
	<lastBuildDate>Sun, 05 Sep 2010 12:46:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bill  Lawson</title>
		<link>http://www.technicallychris.com/2009/08/24/roboform-roboform2go-product-review/comment-page-1/#comment-357</link>
		<dc:creator>Bill  Lawson</dc:creator>
		<pubDate>Mon, 02 Nov 2009 03:03:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.technicallychris.com/?p=425#comment-357</guid>
		<description>Reviewer wrote: &quot;I copy the password to the clip board and use it to login once, allow RoboForm to remember it, and then I know I’m safer than using a pets name to login to Bank of America&quot;.


I do not recommend using that &quot;Copy&quot; function if you intend to use RoboForm2Go on a public computer. That password you just &quot;copied&quot; is easily accessed by preinstalled hacking software that views your clip board.</description>
		<content:encoded><![CDATA[<p>Reviewer wrote: &#8220;I copy the password to the clip board and use it to login once, allow RoboForm to remember it, and then I know I’m safer than using a pets name to login to Bank of America&#8221;.</p>
<p>I do not recommend using that &#8220;Copy&#8221; function if you intend to use RoboForm2Go on a public computer. That password you just &#8220;copied&#8221; is easily accessed by preinstalled hacking software that views your clip board.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: A</title>
		<link>http://www.technicallychris.com/2009/08/24/roboform-roboform2go-product-review/comment-page-1/#comment-339</link>
		<dc:creator>A</dc:creator>
		<pubDate>Thu, 08 Oct 2009 07:29:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.technicallychris.com/?p=425#comment-339</guid>
		<description>HMMMM... YES... This is definitely a security problem ETT. Still, you can encrypt this file and password protect it (ie folder lock) till you use it for the next time. What do you think about that?

And another thing… an unauthorised user can also rename usernames, delete them, move them… DISASTER!!!!

And I also realized that one (without loggin in) can also synchronize the roboform2go with the online password backups without using any login password. Imagine the result if this person first deletes all logins and then synchronizes!!!! I guess that this means bye bye backup...

So I stick to my initial proposal… encrypt the folder that contains this sensitive area. The cheap way to do it is using winrar and setting a password before zipping.</description>
		<content:encoded><![CDATA[<p>HMMMM&#8230; YES&#8230; This is definitely a security problem ETT. Still, you can encrypt this file and password protect it (ie folder lock) till you use it for the next time. What do you think about that?</p>
<p>And another thing… an unauthorised user can also rename usernames, delete them, move them… DISASTER!!!!</p>
<p>And I also realized that one (without loggin in) can also synchronize the roboform2go with the online password backups without using any login password. Imagine the result if this person first deletes all logins and then synchronizes!!!! I guess that this means bye bye backup&#8230;</p>
<p>So I stick to my initial proposal… encrypt the folder that contains this sensitive area. The cheap way to do it is using winrar and setting a password before zipping.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ETT</title>
		<link>http://www.technicallychris.com/2009/08/24/roboform-roboform2go-product-review/comment-page-1/#comment-312</link>
		<dc:creator>ETT</dc:creator>
		<pubDate>Tue, 15 Sep 2009 16:47:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.technicallychris.com/?p=425#comment-312</guid>
		<description>Thanks for your reply ...
&quot; I like that I can simply open the browser and select a passcard, or have the passcard immediately available when I go to a site that has one available.&quot;
- well, Roboform could still do all that, and in addition could potentially do it at least as securely as most other similar security products which put all the secure data inside one single &quot;vault&quot; file which is entirely encrypted and whose contents cannot be read.
The current Roboform design is a bit lazy - I can see why they have done it that way, to allow them to easily sync, passcard by passcard, without thinking too hard, but they have definitely compromised users&#039; security by doing it.
If Roboform reworked the product a little to use one single secure encrypted vault file, then the security would be excellent because it would betray nothing at all, but, at the moment, it is just not secure enough.
Unfortunately, the publisher&#039;s people just keep denying there&#039;s a problem.</description>
		<content:encoded><![CDATA[<p>Thanks for your reply &#8230;<br />
&#8221; I like that I can simply open the browser and select a passcard, or have the passcard immediately available when I go to a site that has one available.&#8221;<br />
- well, Roboform could still do all that, and in addition could potentially do it at least as securely as most other similar security products which put all the secure data inside one single &#8220;vault&#8221; file which is entirely encrypted and whose contents cannot be read.<br />
The current Roboform design is a bit lazy &#8211; I can see why they have done it that way, to allow them to easily sync, passcard by passcard, without thinking too hard, but they have definitely compromised users&#8217; security by doing it.<br />
If Roboform reworked the product a little to use one single secure encrypted vault file, then the security would be excellent because it would betray nothing at all, but, at the moment, it is just not secure enough.<br />
Unfortunately, the publisher&#8217;s people just keep denying there&#8217;s a problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.technicallychris.com/2009/08/24/roboform-roboform2go-product-review/comment-page-1/#comment-297</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Tue, 08 Sep 2009 18:52:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.technicallychris.com/?p=425#comment-297</guid>
		<description>&lt;a href=&quot;#comment-295&quot; rel=&quot;nofollow&quot;&gt;@ETT &lt;/a&gt; 
ETT - The thought has crossed my mind as well.  On the one hand, I like that I can simply open the browser and select a passcard, or have the passcard immediately available when I go to a site that has one available.

When I put my security hat on, however, I can see that any amount of information for a potential theif is too much.  Knowing that I have a gmail account or that I bank with XYZ Corp is a good start into hacking their way into what I&#039;m trying to protect.</description>
		<content:encoded><![CDATA[<p><a href="#comment-295" rel="nofollow">@ETT </a><br />
ETT &#8211; The thought has crossed my mind as well.  On the one hand, I like that I can simply open the browser and select a passcard, or have the passcard immediately available when I go to a site that has one available.</p>
<p>When I put my security hat on, however, I can see that any amount of information for a potential theif is too much.  Knowing that I have a gmail account or that I bank with XYZ Corp is a good start into hacking their way into what I&#8217;m trying to protect.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ETT</title>
		<link>http://www.technicallychris.com/2009/08/24/roboform-roboform2go-product-review/comment-page-1/#comment-295</link>
		<dc:creator>ETT</dc:creator>
		<pubDate>Wed, 02 Sep 2009 05:10:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.technicallychris.com/?p=425#comment-295</guid>
		<description>Unfortunately that list of passcards that you can see in the nice screen shot is available for anyone to view, in that same form, showing what services you log into and who the users are, unencrypted, in the Roboform Data folder on your PC and on your USB key.
While Roboform encrypts the passwords, it crucially does not encrypt the list.
This is a significant problem. Anyone &quot;finding&quot; your USB key can tell a lot about you and the sites you use, and the subject (although not the content) of your Secure notes - what you have written about.
I look forward to Roboform&#039;s fixing this fundamental failing before we can use it more extensively in our business.</description>
		<content:encoded><![CDATA[<p>Unfortunately that list of passcards that you can see in the nice screen shot is available for anyone to view, in that same form, showing what services you log into and who the users are, unencrypted, in the Roboform Data folder on your PC and on your USB key.<br />
While Roboform encrypts the passwords, it crucially does not encrypt the list.<br />
This is a significant problem. Anyone &#8220;finding&#8221; your USB key can tell a lot about you and the sites you use, and the subject (although not the content) of your Secure notes &#8211; what you have written about.<br />
I look forward to Roboform&#8217;s fixing this fundamental failing before we can use it more extensively in our business.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.technicallychris.com/2009/08/24/roboform-roboform2go-product-review/comment-page-1/#comment-294</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Tue, 01 Sep 2009 19:14:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.technicallychris.com/?p=425#comment-294</guid>
		<description>&lt;a href=&quot;#comment-293&quot; rel=&quot;nofollow&quot;&gt;@roboform&lt;/a&gt; 
Thanks for the product, Scott :)  Hope no one over at Ciber minds the stolen screen shots!</description>
		<content:encoded><![CDATA[<p><a href="#comment-293" rel="nofollow">@roboform</a><br />
Thanks for the product, Scott <img src='http://www.technicallychris.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />   Hope no one over at Ciber minds the stolen screen shots!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: roboform</title>
		<link>http://www.technicallychris.com/2009/08/24/roboform-roboform2go-product-review/comment-page-1/#comment-293</link>
		<dc:creator>roboform</dc:creator>
		<pubDate>Tue, 01 Sep 2009 18:11:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.technicallychris.com/?p=425#comment-293</guid>
		<description>Thanks for the great review Chris :-)</description>
		<content:encoded><![CDATA[<p>Thanks for the great review Chris <img src='http://www.technicallychris.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lisa Cox</title>
		<link>http://www.technicallychris.com/2009/08/24/roboform-roboform2go-product-review/comment-page-1/#comment-287</link>
		<dc:creator>Lisa Cox</dc:creator>
		<pubDate>Tue, 25 Aug 2009 07:33:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.technicallychris.com/?p=425#comment-287</guid>
		<description>RoboForm is a fantastic tool and the password generator is especially convenient when you just want to get through the sign up process fast. I use the Billeo toolbar nowadays though because I make lots of online transactions and it has a really helpful transaction manager. They&#039;re having a contest and giving away an iPhone to US residents who sign up by the 26th.</description>
		<content:encoded><![CDATA[<p>RoboForm is a fantastic tool and the password generator is especially convenient when you just want to get through the sign up process fast. I use the Billeo toolbar nowadays though because I make lots of online transactions and it has a really helpful transaction manager. They&#8217;re having a contest and giving away an iPhone to US residents who sign up by the 26th.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
