<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-3604425971259502766.post1714665892060792237..comments</id><updated>2009-10-26T19:18:51.496+01:00</updated><title type='text'>Comments on damonkohler: Introducing hushnote</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.damonkohler.com/feeds/1714665892060792237/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3604425971259502766/1714665892060792237/comments/default'/><link rel='alternate' type='text/html' href='http://www.damonkohler.com/2009/10/hushnote-host-proof-password-manager.html'/><author><name>Damon</name><uri>http://www.blogger.com/profile/17362087152286203901</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3604425971259502766.post-7043696129880023991</id><published>2009-10-26T19:18:51.496+01:00</published><updated>2009-10-26T19:18:51.496+01:00</updated><title type='text'>@Will The plain-text password is a known issue. I ...</title><content type='html'>@Will The plain-text password is a known issue. I just haven&amp;#39;t found a way to fix it that I like yet. As for verifying that the content of hushnote hasn&amp;#39;t changed, I gave it some thought. I don&amp;#39;t think it&amp;#39;s possible to do that without having out-of-band monitoring or checking of the content. A browser extension would be ideal. In the mean time, I can offer you &lt;a href="http://code.google.com/p/hushnote/source/browse/hushnote_hash.py" rel="nofollow"&gt;this script&lt;/a&gt;. Also, I use Oplop to generate my hushnote password. If a baddie did change the source of the page, he could send himself anything he wanted (passwords, labels, notes, etc.).</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3604425971259502766/1714665892060792237/comments/default/7043696129880023991'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3604425971259502766/1714665892060792237/comments/default/7043696129880023991'/><link rel='alternate' type='text/html' href='http://www.damonkohler.com/2009/10/hushnote-host-proof-password-manager.html?showComment=1256581131496#c7043696129880023991' title=''/><author><name>Damon</name><uri>http://www.blogger.com/profile/17362087152286203901</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03757104139415985158'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.damonkohler.com/2009/10/hushnote-host-proof-password-manager.html' ref='tag:blogger.com,1999:blog-3604425971259502766.post-1714665892060792237' source='http://www.blogger.com/feeds/3604425971259502766/posts/default/1714665892060792237' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3604425971259502766.post-8665117527717537993</id><published>2009-10-26T16:00:21.045+01:00</published><updated>2009-10-26T16:00:21.045+01:00</updated><title type='text'>Sweet!  It would be nice if it didn't show my pass...</title><content type='html'>Sweet!  It would be nice if it didn&amp;#39;t show my passwords in plain text as I type, though.  (Happens in Chrome 4.0.220.1 on Linux and Chrome 3.0.195.27 on Windows at least).&lt;br /&gt;&lt;br /&gt;And another question from the paranoid peanut gallery: it seems that unless we want to audit the Javascript *every time* we use hushnote, we&amp;#39;re basically relying on you staying honest/secure.  (SSL just tells us that we&amp;#39;re really connected to hushnote.appspot.com; it doesn&amp;#39;t assure us that what&amp;#39;s hosted there is what we want).&lt;br /&gt;&lt;br /&gt;In other words, it seems like info stored on hushnote is only as secure (for all users) as Damon&amp;#39;s personal Google Account password.  When Evil Hacker {Wom,M}an hacks your google acct, they can then upload different code to hushnote that has an identical UI but that sends (say) my oplop master password and my hushnote label straight to the baddie.&lt;br /&gt;&lt;br /&gt;If not, then it seems like the right thing is to use a different oplop master password for hushnote than for everything else, and to only store things like oplop labels in my hushnote file.&lt;br /&gt;&lt;br /&gt;Am I missing something?&lt;br /&gt;&lt;br /&gt;Thanks for writing this.  If I can satisfy my paranoia, it will noticeably improve my life. :)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3604425971259502766/1714665892060792237/comments/default/8665117527717537993'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3604425971259502766/1714665892060792237/comments/default/8665117527717537993'/><link rel='alternate' type='text/html' href='http://www.damonkohler.com/2009/10/hushnote-host-proof-password-manager.html?showComment=1256569221045#c8665117527717537993' title=''/><author><name>Will Robinson</name><uri>http://www.blogger.com/profile/04869187254019491304</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.damonkohler.com/2009/10/hushnote-host-proof-password-manager.html' ref='tag:blogger.com,1999:blog-3604425971259502766.post-1714665892060792237' source='http://www.blogger.com/feeds/3604425971259502766/posts/default/1714665892060792237' type='text/html'/></entry></feed>