<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: password lockouts</title>
	<atom:link href="http://angelsofsecurity.com/blog/2008/05/11/password-lockouts/feed/" rel="self" type="application/rss+xml" />
	<link>http://angelsofsecurity.com/blog/2008/05/11/password-lockouts/</link>
	<description>Musings of an infosec renegade</description>
	<lastBuildDate>Tue, 19 Jul 2011 19:43:52 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Brian</title>
		<link>http://angelsofsecurity.com/blog/2008/05/11/password-lockouts/comment-page-1/#comment-697</link>
		<dc:creator>Brian</dc:creator>
		<pubDate>Fri, 11 Jul 2008 04:11:59 +0000</pubDate>
		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/05/11/password-lockouts/#comment-697</guid>
		<description>I agree that increasing the number is an acceptable change.  What concerns me is the &quot;IT Security&quot; audit recommendation to lockout forever.  I got into a large argument with an audit supervisor over this.  His idea is to follow blindly even if the recommendation creates a DOS vulnerability.  Therefore any company following their &quot;auditor&#039;s&quot; well thought out standards can be crippled within minutes with a simple batch file.  How about 30 min lockout duration?  Self healing is better than dead in the water.  And any attacker desperate enough to attempt to brute force accounts will move on after having to wait for eternity every N tries.</description>
		<content:encoded><![CDATA[<p>I agree that increasing the number is an acceptable change.  What concerns me is the &#8220;IT Security&#8221; audit recommendation to lockout forever.  I got into a large argument with an audit supervisor over this.  His idea is to follow blindly even if the recommendation creates a DOS vulnerability.  Therefore any company following their &#8220;auditor&#8217;s&#8221; well thought out standards can be crippled within minutes with a simple batch file.  How about 30 min lockout duration?  Self healing is better than dead in the water.  And any attacker desperate enough to attempt to brute force accounts will move on after having to wait for eternity every N tries.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ty Sbano</title>
		<link>http://angelsofsecurity.com/blog/2008/05/11/password-lockouts/comment-page-1/#comment-630</link>
		<dc:creator>Ty Sbano</dc:creator>
		<pubDate>Fri, 20 Jun 2008 20:50:03 +0000</pubDate>
		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/05/11/password-lockouts/#comment-630</guid>
		<description>I disagree... I stand by three.  Cause three is my favorite number.</description>
		<content:encoded><![CDATA[<p>I disagree&#8230; I stand by three.  Cause three is my favorite number.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

