<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Using captcha instead of usernames and passwords</title>
	<atom:link href="http://www.sowrey.org/2007/04/using-captcha-instead-of-usernames-and-passwords/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sowrey.org/2007/04/using-captcha-instead-of-usernames-and-passwords/</link>
	<description>A miscellany of know-it-all-isms by Geoff Sowrey</description>
	<lastBuildDate>Fri, 06 Jan 2012 04:27:17 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: Geoff</title>
		<link>http://www.sowrey.org/2007/04/using-captcha-instead-of-usernames-and-passwords/#comment-1677</link>
		<dc:creator>Geoff</dc:creator>
		<pubDate>Thu, 26 Apr 2007 15:05:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.sowrey.org/2007/04/18/using-captcha-instead-of-usernames-and-passwords/#comment-1677</guid>
		<description>If we always stick the &quot;tried and true&quot;, there&#039;s never any change for improvement. Frankly, I think Vidoop sounds like an improvement over our decades-old text-based system. It&#039;s prone to error and security issues, and as we move forward with technology, other solutions make more sense. I think Vidoop sounds like a good solution. 

Assuming SOX doesn&#039;t prevent it, that is. ;)</description>
		<content:encoded><![CDATA[<p>If we always stick the &#8220;tried and true&#8221;, there&#8217;s never any change for improvement. Frankly, I think Vidoop sounds like an improvement over our decades-old text-based system. It&#8217;s prone to error and security issues, and as we move forward with technology, other solutions make more sense. I think Vidoop sounds like a good solution. </p>
<p>Assuming SOX doesn&#8217;t prevent it, that is. <img src='http://www.sowrey.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Koesmanto Bong</title>
		<link>http://www.sowrey.org/2007/04/using-captcha-instead-of-usernames-and-passwords/#comment-1676</link>
		<dc:creator>Koesmanto Bong</dc:creator>
		<pubDate>Thu, 26 Apr 2007 14:26:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.sowrey.org/2007/04/18/using-captcha-instead-of-usernames-and-passwords/#comment-1676</guid>
		<description>Thank you for blogging about us  :-)  you have my email address if you&#039;d like some invite codes. (koesmanto &#124;dot&#124; bong &#124;at&#124; vidoop &#124;dot&#124; com)</description>
		<content:encoded><![CDATA[<p>Thank you for blogging about us  <img src='http://www.sowrey.org/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />   you have my email address if you&#8217;d like some invite codes. (koesmanto |dot| bong |at| vidoop |dot| com)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Geoff</title>
		<link>http://www.sowrey.org/2007/04/using-captcha-instead-of-usernames-and-passwords/#comment-1668</link>
		<dc:creator>Geoff</dc:creator>
		<pubDate>Wed, 25 Apr 2007 02:59:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.sowrey.org/2007/04/18/using-captcha-instead-of-usernames-and-passwords/#comment-1668</guid>
		<description>Koesmanto, thank you very much for the extra information! This helps understand the system a lot more. I think I might hit you up for a trial, too.</description>
		<content:encoded><![CDATA[<p>Koesmanto, thank you very much for the extra information! This helps understand the system a lot more. I think I might hit you up for a trial, too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Koesmanto Bong</title>
		<link>http://www.sowrey.org/2007/04/using-captcha-instead-of-usernames-and-passwords/#comment-1665</link>
		<dc:creator>Koesmanto Bong</dc:creator>
		<pubDate>Tue, 24 Apr 2007 19:42:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.sowrey.org/2007/04/18/using-captcha-instead-of-usernames-and-passwords/#comment-1665</guid>
		<description>Hey,

To answer your questions, the size of the grid can be changed.  the demo showed a 3x3 grid, while on myvidoop it&#039;s a 3x4 grid.  you can also customize whether or not sequencing matters; you can turn on case sensitivity, adding numbers, or even have more than 1 alphanumeric character per image.

Now, onto statistics:

On a 3x4 grid, where you have 3 secret categories and sequencing isn&#039;t enforced, the probability of someone guessing your secrets is 1 in 73 attempts.  When sequencing matters, it is 1 in 440 attempts.

On a 4x4 grid, it increases to 1 in 187 attempts when sequencing doesn&#039;t matter, and 1 in 607 attempts when sequencing matters. (assuming 3 secret categories needed).

On myVidoop, we allow 3 failures before an account lockout.

The above scenario also assumes that someone actually uses computers that you have activated.  if they are trying to see your grid on an unactivated computer, they&#039;d have to have access to your email address or your phone.

Please let me know if you have any more questions or feedbacks.  I would be happy to give you an invitation code if you&#039;d like to try myVidoop out.</description>
		<content:encoded><![CDATA[<p>Hey,</p>
<p>To answer your questions, the size of the grid can be changed.  the demo showed a 3&#215;3 grid, while on myvidoop it&#8217;s a 3&#215;4 grid.  you can also customize whether or not sequencing matters; you can turn on case sensitivity, adding numbers, or even have more than 1 alphanumeric character per image.</p>
<p>Now, onto statistics:</p>
<p>On a 3&#215;4 grid, where you have 3 secret categories and sequencing isn&#8217;t enforced, the probability of someone guessing your secrets is 1 in 73 attempts.  When sequencing matters, it is 1 in 440 attempts.</p>
<p>On a 4&#215;4 grid, it increases to 1 in 187 attempts when sequencing doesn&#8217;t matter, and 1 in 607 attempts when sequencing matters. (assuming 3 secret categories needed).</p>
<p>On myVidoop, we allow 3 failures before an account lockout.</p>
<p>The above scenario also assumes that someone actually uses computers that you have activated.  if they are trying to see your grid on an unactivated computer, they&#8217;d have to have access to your email address or your phone.</p>
<p>Please let me know if you have any more questions or feedbacks.  I would be happy to give you an invitation code if you&#8217;d like to try myVidoop out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andre</title>
		<link>http://www.sowrey.org/2007/04/using-captcha-instead-of-usernames-and-passwords/#comment-1653</link>
		<dc:creator>Andre</dc:creator>
		<pubDate>Wed, 18 Apr 2007 19:53:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.sowrey.org/2007/04/18/using-captcha-instead-of-usernames-and-passwords/#comment-1653</guid>
		<description>Did you give their OpenID implementation a try?  

Based on talking to a couple of people at the booth it appears that the demo only scratches the surface and you can scale up in terms of categories and images.  They have a team made up of people from the Navy, Microsoft, and a number of other hard core organizations so if they are not SOX compliant at this second I&#039;m sure they are on the way.  Considering banks are one of their target markets and all.

They did stress that they are a security company that leverages the goodness adn freshness of web 2.0 and not the other way around.</description>
		<content:encoded><![CDATA[<p>Did you give their OpenID implementation a try?  </p>
<p>Based on talking to a couple of people at the booth it appears that the demo only scratches the surface and you can scale up in terms of categories and images.  They have a team made up of people from the Navy, Microsoft, and a number of other hard core organizations so if they are not SOX compliant at this second I&#8217;m sure they are on the way.  Considering banks are one of their target markets and all.</p>
<p>They did stress that they are a security company that leverages the goodness adn freshness of web 2.0 and not the other way around.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

