<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Life is grand - Latest Comments in Insecure usernames and passwords on Netvibes</title><link>http://lifeisgrand.disqus.com/</link><description></description><atom:link href="https://lifeisgrand.disqus.com/insecure_usernames_and_passwords_on_netvibes/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Tue, 13 Nov 2007 15:03:02 -0000</lastBuildDate><item><title>Re: Insecure usernames and passwords on Netvibes</title><link>http://paulmwatson.com/journal/2007/11/05/insecure-usernames-and-passwords-on-netvibes/#comment-1284784</link><description>&lt;p&gt;Well spotted. This is crazy.&lt;/p&gt;&lt;p&gt;For something crazier, see &lt;a href="http://Wordpress.com" rel="nofollow noopener" target="_blank" title="Wordpress.com"&gt;Wordpress.com&lt;/a&gt;, a very popular blog site, with plain text login data sent to an http endpoint from their https page !&lt;/p&gt;&lt;p&gt;Madness.&lt;/p&gt;&lt;p&gt;Worse now imo, folks are using their &lt;a href="http://wordpress.com" rel="nofollow noopener" target="_blank" title="wordpress.com"&gt;wordpress.com&lt;/a&gt; blog address as an OpenID.&lt;/p&gt;&lt;p&gt;Kinda mental to think that if you make the mistake of posting about, say your ski holiday in St. Anton from a Café while your there, somebody could sniff your password, and have access to all the on-line services you use OpenId with.&lt;/p&gt;&lt;p&gt;I have emailed Wordpress, and posted on my test blog there, they have not responded, and today it's still not fixed !&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">dara</dc:creator><pubDate>Tue, 13 Nov 2007 15:03:02 -0000</pubDate></item></channel></rss>