<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Life is grand - Latest Comments in Insecure usernames and passwords on Netvibes</title><link>http://lifeisgrand.disqus.com/</link><description></description><language>en</language><lastBuildDate>Tue, 13 Nov 2007 15:03:02 -0000</lastBuildDate><item><title>Re: Insecure usernames and passwords on Netvibes</title><link>http://paulmwatson.com/journal/2007/11/05/insecure-usernames-and-passwords-on-netvibes/#comment-1284784</link><description>Well spotted. This is crazy.&lt;br&gt;&lt;br&gt;For something crazier, see &lt;a href="http://Wordpress.com" rel="nofollow"&gt;Wordpress.com&lt;/a&gt;, a very popular blog site, with plain text login data sent to an http endpoint from their https page !&lt;br&gt;&lt;br&gt;Madness.&lt;br&gt;&lt;br&gt;Worse now imo, folks are using their &lt;a href="http://wordpress.com" rel="nofollow"&gt;wordpress.com&lt;/a&gt; blog address as an OpenID.&lt;br&gt;&lt;br&gt;Kinda mental to think that if you make the mistake of posting about, say your ski holiday in St. Anton from a Café while your there, somebody could sniff your password, and have access to all the on-line services you use OpenId with.&lt;br&gt;&lt;br&gt;I have emailed Wordpress, and posted on my test blog there, they have not responded, and today it's still not fixed !</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">dara</dc:creator><pubDate>Tue, 13 Nov 2007 15:03:02 -0000</pubDate></item></channel></rss>