<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: 6-1 reasons why you shouldn&#8217;t get Verisign Personal Identity Portal</title>
	<atom:link href="http://tinxmoney.com/6-1-reasons-why-you-shouldnt-get-verisign-personal-identity-portal/feed/" rel="self" type="application/rss+xml" />
	<link>http://tinxmoney.com/6-1-reasons-why-you-shouldnt-get-verisign-personal-identity-portal/</link>
	<description>My internet marketing tips and tricks. Think Money!</description>
	<lastBuildDate>Thu, 10 Sep 2009 22:26:57 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Roger Lee</title>
		<link>http://tinxmoney.com/6-1-reasons-why-you-shouldnt-get-verisign-personal-identity-portal/comment-page-1/#comment-16097</link>
		<dc:creator>Roger Lee</dc:creator>
		<pubDate>Thu, 19 Mar 2009 22:33:35 +0000</pubDate>
		<guid isPermaLink="false">http://tinxmoney.com/?p=68#comment-16097</guid>
		<description>&quot;Tinx&quot;
I manage Australia Post&#039;s VIP Online Security Service which is based on the VeriSign VIP platform. See: http://www.auspost.com.au/BCP/0,1467,CH4365%257EMO19,00.html .  If you reach me via the contact details on the web site I will be pleased to provide you with a free token that will work across all VIP network members including PayPal, eBay and the VeriSign PIP.
Cheers
RL</description>
		<content:encoded><![CDATA[<p>&#8220;Tinx&#8221;<br />
I manage Australia Post&#8217;s VIP Online Security Service which is based on the VeriSign VIP platform. See: <a href="http://www.auspost.com.au/BCP/0,1467,CH4365%257EMO19,00.html" rel="nofollow">http://www.auspost.com.au/BCP/0,1467,CH4365%257EMO19,00.html</a> .  If you reach me via the contact details on the web site I will be pleased to provide you with a free token that will work across all VIP network members including PayPal, eBay and the VeriSign PIP.<br />
Cheers<br />
RL</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Recent Links Tagged With "verisign" - JabberTags</title>
		<link>http://tinxmoney.com/6-1-reasons-why-you-shouldnt-get-verisign-personal-identity-portal/comment-page-1/#comment-229</link>
		<dc:creator>Recent Links Tagged With "verisign" - JabberTags</dc:creator>
		<pubDate>Wed, 24 Dec 2008 22:04:26 +0000</pubDate>
		<guid isPermaLink="false">http://tinxmoney.com/?p=68#comment-229</guid>
		<description>[...] public links &gt;&gt; verisign   6-1 reasons why you shouldn’t get Verisign Personal Identity Portal Saved by jeffmitchel on Wed 10-12-2008   VeriSign To Protect Against ‘Pump And Dump’ Schemes [...]</description>
		<content:encoded><![CDATA[<p>[...] public links &gt;&gt; verisign   6-1 reasons why you shouldn’t get Verisign Personal Identity Portal Saved by jeffmitchel on Wed 10-12-2008   VeriSign To Protect Against ‘Pump And Dump’ Schemes [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tinx</title>
		<link>http://tinxmoney.com/6-1-reasons-why-you-shouldnt-get-verisign-personal-identity-portal/comment-page-1/#comment-9</link>
		<dc:creator>Tinx</dc:creator>
		<pubDate>Tue, 26 Aug 2008 01:35:55 +0000</pubDate>
		<guid isPermaLink="false">http://tinxmoney.com/?p=68#comment-9</guid>
		<description>I am honestly didn&#039;t know that Paypal token is available for Australian users as well. :D
It&#039;s only AUD 7.50 
I might going to order one :)</description>
		<content:encoded><![CDATA[<p>I am honestly didn&#8217;t know that Paypal token is available for Australian users as well. <img src='http://tinxmoney.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /><br />
It&#8217;s only AUD 7.50<br />
I might going to order one <img src='http://tinxmoney.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gary Krall</title>
		<link>http://tinxmoney.com/6-1-reasons-why-you-shouldnt-get-verisign-personal-identity-portal/comment-page-1/#comment-8</link>
		<dc:creator>Gary Krall</dc:creator>
		<pubDate>Mon, 25 Aug 2008 16:14:53 +0000</pubDate>
		<guid isPermaLink="false">http://tinxmoney.com/?p=68#comment-8</guid>
		<description>Sven:  We *do not* know the credential information of our users.  I&#039;m not going to go into the details as to &quot;how&quot; we do this but the scenario you presented is not possible with our system.

And as mentioned above you do not need to have a token to get second-factor authentication a VeriSign provided free browser certificate can provide the same level of comfort.</description>
		<content:encoded><![CDATA[<p>Sven:  We *do not* know the credential information of our users.  I&#8217;m not going to go into the details as to &#8220;how&#8221; we do this but the scenario you presented is not possible with our system.</p>
<p>And as mentioned above you do not need to have a token to get second-factor authentication a VeriSign provided free browser certificate can provide the same level of comfort.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gary Krall</title>
		<link>http://tinxmoney.com/6-1-reasons-why-you-shouldnt-get-verisign-personal-identity-portal/comment-page-1/#comment-7</link>
		<dc:creator>Gary Krall</dc:creator>
		<pubDate>Mon, 25 Aug 2008 16:10:41 +0000</pubDate>
		<guid isPermaLink="false">http://tinxmoney.com/?p=68#comment-7</guid>
		<description>Thanks a lot &quot;Tinx&quot; for your comments.  With regards to providing users with tokens (you may email me under a separate cover...:-)) but in general the cost of a Paypal token makes it very advantageous to users:  https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/cps/securitycenter/general/PPSecurityKey-outside

Also one thing to keep in mind is our Browser Certificate feature.  If a user does not have a physical token but wants the comfort of having their username/password backed by a second-factor (&quot;something you know, something you have&quot;) installation of a certificate that is bound to the browser can provide this.

So essentially you can store your credentials and have access into the PiP backed up by a browser certificate to provide a high-level of security.

Check that out and let me know what you think.</description>
		<content:encoded><![CDATA[<p>Thanks a lot &#8220;Tinx&#8221; for your comments.  With regards to providing users with tokens (you may email me under a separate cover&#8230;:-)) but in general the cost of a Paypal token makes it very advantageous to users:  <a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/cps/securitycenter/general/PPSecurityKey-outside" rel="nofollow">https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/cps/securitycenter/general/PPSecurityKey-outside</a></p>
<p>Also one thing to keep in mind is our Browser Certificate feature.  If a user does not have a physical token but wants the comfort of having their username/password backed by a second-factor (&#8221;something you know, something you have&#8221;) installation of a certificate that is bound to the browser can provide this.</p>
<p>So essentially you can store your credentials and have access into the PiP backed up by a browser certificate to provide a high-level of security.</p>
<p>Check that out and let me know what you think.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sven J. Koerner</title>
		<link>http://tinxmoney.com/6-1-reasons-why-you-shouldnt-get-verisign-personal-identity-portal/comment-page-1/#comment-5</link>
		<dc:creator>Sven J. Koerner</dc:creator>
		<pubDate>Mon, 25 Aug 2008 10:53:08 +0000</pubDate>
		<guid isPermaLink="false">http://tinxmoney.com/?p=68#comment-5</guid>
		<description>Hi Tinx, hi Gary,

I also have to add some thoughts and ideas to the topic.
First I would like to point out that we are a German-based service doing essentially the same as our pals from VeriSign. We have been out in the beta phase since march, 08. We are currently working on the localization; no English frontend available at the moment, but is just around the corner (in case you want to try it out, just give us a couple of more days or let me walk you through the German interface).
I will stick to the enumerated numbers Gary used when replying so we all know what we&#039;re talking about.

1.) Gary, if you store the encrypted data in your database, you still log on the user directly. Is this correct? So your system needs to know the pw/user combination. Having a malicious in-house attack on your database would still lead to the disclosure of all your users passwords. Correct? Or how could you possibly log a user in without having the passwords?
Do you encrypt your traffic to other sites you log in? If so, how do you handle sites that are not based on https/ssl (since there are numerous examples).

2. Eingelogged.de is fully capable of that. Just wait for the multi-language interface

3. We address the keylogger issue and are fully aware of the problem. Unfortunately I cannot present the solution at this very moment in public as it will be available very soon. We have to keep this under the radar for a couple of more days.

4. We directly log you in. No form-filling needed. I might want to point out that we use a 128bit ssl encryption for your traffic.

5. We also lack this feature. It&#039;s on the roadmap.

6. Totally possible with eingelogged.de
And yes, we agree that this is one of the very strong features of the internet. This is in our view also one of the main drawbacks that OpenID and others have: Sometimes I just want to be somebody else cruisin&#039; the net and not myself.
Various identities for various jobs are just one of the big features of the internet: And we all have to admit we do this every once in a while.

additional features we offer:
-Log-in all (one-button-login for all services in certain profiles)
-profiles for your logins (to especially refer to Tinx&#039;s point #6: We totally address this issue)
-You don&#039;t have to carry anything with you; not even a USB device. Just an internet connection and a browser (this especially refers to #3; as of yet, you still have to wait for the availabilty of the solution some more days).

Looking forward to your feedback.</description>
		<content:encoded><![CDATA[<p>Hi Tinx, hi Gary,</p>
<p>I also have to add some thoughts and ideas to the topic.<br />
First I would like to point out that we are a German-based service doing essentially the same as our pals from VeriSign. We have been out in the beta phase since march, 08. We are currently working on the localization; no English frontend available at the moment, but is just around the corner (in case you want to try it out, just give us a couple of more days or let me walk you through the German interface).<br />
I will stick to the enumerated numbers Gary used when replying so we all know what we&#8217;re talking about.</p>
<p>1.) Gary, if you store the encrypted data in your database, you still log on the user directly. Is this correct? So your system needs to know the pw/user combination. Having a malicious in-house attack on your database would still lead to the disclosure of all your users passwords. Correct? Or how could you possibly log a user in without having the passwords?<br />
Do you encrypt your traffic to other sites you log in? If so, how do you handle sites that are not based on https/ssl (since there are numerous examples).</p>
<p>2. Eingelogged.de is fully capable of that. Just wait for the multi-language interface</p>
<p>3. We address the keylogger issue and are fully aware of the problem. Unfortunately I cannot present the solution at this very moment in public as it will be available very soon. We have to keep this under the radar for a couple of more days.</p>
<p>4. We directly log you in. No form-filling needed. I might want to point out that we use a 128bit ssl encryption for your traffic.</p>
<p>5. We also lack this feature. It&#8217;s on the roadmap.</p>
<p>6. Totally possible with eingelogged.de<br />
And yes, we agree that this is one of the very strong features of the internet. This is in our view also one of the main drawbacks that OpenID and others have: Sometimes I just want to be somebody else cruisin&#8217; the net and not myself.<br />
Various identities for various jobs are just one of the big features of the internet: And we all have to admit we do this every once in a while.</p>
<p>additional features we offer:<br />
-Log-in all (one-button-login for all services in certain profiles)<br />
-profiles for your logins (to especially refer to Tinx&#8217;s point #6: We totally address this issue)<br />
-You don&#8217;t have to carry anything with you; not even a USB device. Just an internet connection and a browser (this especially refers to #3; as of yet, you still have to wait for the availabilty of the solution some more days).</p>
<p>Looking forward to your feedback.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tinx</title>
		<link>http://tinxmoney.com/6-1-reasons-why-you-shouldnt-get-verisign-personal-identity-portal/comment-page-1/#comment-3</link>
		<dc:creator>Tinx</dc:creator>
		<pubDate>Fri, 22 Aug 2008 04:51:54 +0000</pubDate>
		<guid isPermaLink="false">http://tinxmoney.com/?p=68#comment-3</guid>
		<description>Hi Gary,

Thank you for post a comment on my post :)

Regarding your comment :

1. Thank you for clarifying this, I forgot the fact that you encrypt the login details in the first place :) I just realized this after I signed up to your PiP. That&#039;s right! I&#039;ve decided to give it a try :)
2. If you could also support multiple logins for the same site, that would be great :)
3. Well, Paypal token is not available for Australian users :( Is it possible to use a token from my local bank ? And if there&#039;s a backdoor trojan in my computer, then the browser certificate is pretty much useless, right ?
But if I use Roboform Portable, no one can access my data unless they get my USB Token :)
4. That&#039;s great. Another reason why I would use PiP :)
5. Thanks :)
6. It was related to #2. With Roboform I could manage several identities. Even thought there&#039;s one 1 person (me), I could use 1 identity for real / useful sites, 1 identity for probably a scam / trash sites, etc.

In summary, it&#039;s almost comparable to Roboform and it might be better when it&#039;s out from Beta. 
My suggestion is to provide all users with a physical token. I&#039;m sure that more people will use PiP if this given for FREE or at very low price :) OR if you could make something like online fingerprint / retina reader to authenticate the user ? :D
Add more features, and PiP will be my selected password manager in the future !</description>
		<content:encoded><![CDATA[<p>Hi Gary,</p>
<p>Thank you for post a comment on my post <img src='http://tinxmoney.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Regarding your comment :</p>
<p>1. Thank you for clarifying this, I forgot the fact that you encrypt the login details in the first place <img src='http://tinxmoney.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  I just realized this after I signed up to your PiP. That&#8217;s right! I&#8217;ve decided to give it a try <img src='http://tinxmoney.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
2. If you could also support multiple logins for the same site, that would be great <img src='http://tinxmoney.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
3. Well, Paypal token is not available for Australian users <img src='http://tinxmoney.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  Is it possible to use a token from my local bank ? And if there&#8217;s a backdoor trojan in my computer, then the browser certificate is pretty much useless, right ?<br />
But if I use <a rel="nofollow" href='http://tinxmoney.com/wp-content/plugins/wp-affiliate-pro.php?id=2' onmouseover="top.window.status='http://www.roboform.com'; return true" onmouseout="top.window.status=''; return true" target="_blank">Roboform</a> Portable, no one can access my data unless they get my USB Token <img src='http://tinxmoney.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
4. That&#8217;s great. Another reason why I would use PiP <img src='http://tinxmoney.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
5. Thanks <img src='http://tinxmoney.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
6. It was related to #2. With <a rel="nofollow" href='http://tinxmoney.com/wp-content/plugins/wp-affiliate-pro.php?id=2' onmouseover="top.window.status='http://www.roboform.com'; return true" onmouseout="top.window.status=''; return true" target="_blank">Roboform</a> I could manage several identities. Even thought there&#8217;s one 1 person (me), I could use 1 identity for real / useful sites, 1 identity for probably a scam / trash sites, etc.</p>
<p>In summary, it&#8217;s almost comparable to <a rel="nofollow" href='http://tinxmoney.com/wp-content/plugins/wp-affiliate-pro.php?id=2' onmouseover="top.window.status='http://www.roboform.com'; return true" onmouseout="top.window.status=''; return true" target="_blank">Roboform</a> and it might be better when it&#8217;s out from Beta.<br />
My suggestion is to provide all users with a physical token. I&#8217;m sure that more people will use PiP if this given for FREE or at very low price <img src='http://tinxmoney.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  OR if you could make something like online fingerprint / retina reader to authenticate the user ? <img src='http://tinxmoney.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /><br />
Add more features, and PiP will be my selected password manager in the future !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gary Krall</title>
		<link>http://tinxmoney.com/6-1-reasons-why-you-shouldnt-get-verisign-personal-identity-portal/comment-page-1/#comment-2</link>
		<dc:creator>Gary Krall</dc:creator>
		<pubDate>Thu, 21 Aug 2008 19:26:18 +0000</pubDate>
		<guid isPermaLink="false">http://tinxmoney.com/?p=68#comment-2</guid>
		<description>Hi:  As the technical director for the PiP/SeatBelt project here at VeriSign I had to respond.  :-)

With regards to your points:

1)  That is simply not true.  The information that is stored in our database is an encrypted blob that only you have the key for (which is what you create when you initially enable this feature in the PiP).  There is no way for us to gain access to your personal credentials.

2)  This is correct.  Currently we only support a single set of credentials.  Since this is an initial launch of the service we had to limit things and for now that is one of the limiting factors.  In your situation both you and your wife would need separate accounts on the PiP.

3)  One of the features of the PiP is that it offers two additional security features.  One is a browser certificate which can be used as a second factor authentication mechanism and the other is binding say your Paypal token to the service.  The combination allows for an additional level of security when accessing your account.

4)  By &quot;form filling&quot; do you mean form filling of username and passwords?  If yes than for sites requiring this we provide that facility and for other sites this is not required as we&#039;ll directly log you in.

5)  This is currently correct.  It is a good suggestion.

6)  Is this related to your point #2?  Or is this related to multiple OpenID identities?  If it is the latter than that is absolutely supported.

Clearly the functionality is not as complete as Roboform nor is it intended to be.   This is meant as a handy feature to allow you the flexibility across multiple devices to safely store usernames/passwords.

Hope that helps.</description>
		<content:encoded><![CDATA[<p>Hi:  As the technical director for the PiP/SeatBelt project here at VeriSign I had to respond.  <img src='http://tinxmoney.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>With regards to your points:</p>
<p>1)  That is simply not true.  The information that is stored in our database is an encrypted blob that only you have the key for (which is what you create when you initially enable this feature in the PiP).  There is no way for us to gain access to your personal credentials.</p>
<p>2)  This is correct.  Currently we only support a single set of credentials.  Since this is an initial launch of the service we had to limit things and for now that is one of the limiting factors.  In your situation both you and your wife would need separate accounts on the PiP.</p>
<p>3)  One of the features of the PiP is that it offers two additional security features.  One is a browser certificate which can be used as a second factor authentication mechanism and the other is binding say your Paypal token to the service.  The combination allows for an additional level of security when accessing your account.</p>
<p>4)  By &#8220;form filling&#8221; do you mean form filling of username and passwords?  If yes than for sites requiring this we provide that facility and for other sites this is not required as we&#8217;ll directly log you in.</p>
<p>5)  This is currently correct.  It is a good suggestion.</p>
<p>6)  Is this related to your point #2?  Or is this related to multiple OpenID identities?  If it is the latter than that is absolutely supported.</p>
<p>Clearly the functionality is not as complete as <a rel="nofollow" href='http://tinxmoney.com/wp-content/plugins/wp-affiliate-pro.php?id=2' onmouseover="top.window.status='http://www.roboform.com'; return true" onmouseout="top.window.status=''; return true" target="_blank">Roboform</a> nor is it intended to be.   This is meant as a handy feature to allow you the flexibility across multiple devices to safely store usernames/passwords.</p>
<p>Hope that helps.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
