<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Is it possible to trust online password managers like PassPack and Clipperz?</title>
	<link>http://www.tummblr.com/security/is-it-possible-to-trust-online-password-managers-like-passpack-and-clipperz/</link>
	<description>Records of my tumblings through the intarwebs</description>
	<pubDate>Fri, 16 May 2008 03:49:59 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: Tara Kelly (PassPack)</title>
		<link>http://www.tummblr.com/security/is-it-possible-to-trust-online-password-managers-like-passpack-and-clipperz/#comment-292</link>
		<dc:creator>Tara Kelly (PassPack)</dc:creator>
		<pubDate>Wed, 20 Feb 2008 14:31:15 +0000</pubDate>
		<guid>http://www.tummblr.com/security/is-it-possible-to-trust-online-password-managers-like-passpack-and-clipperz/#comment-292</guid>
		<description>Thanks to you - I've added you to my feeds now. At least half my feeds are from great blogs I've discovered via PassPack-related issues.

I also just posted to our blog about our Profit Model:
http://passpack.wordpress.com/2008/02/20/passpacks-profit-model/

Now onto those collaboration suggestions...

Cheers!
Tara</description>
		<content:encoded><![CDATA[<p>Thanks to you - I&#8217;ve added you to my feeds now. At least half my feeds are from great blogs I&#8217;ve discovered via PassPack-related issues.</p>
<p>I also just posted to our blog about our Profit Model:<br />
<a href="http://passpack.wordpress.com/2008/02/20/passpacks-profit-model/" rel="nofollow" onclick="javascript:pageTracker._trackPageview ('/outbound/passpack.wordpress.com');">http://passpack.wordpress.com/2008/02/20/passpacks-profit-model/</a></p>
<p>Now onto those collaboration suggestions&#8230;</p>
<p>Cheers!<br />
Tara</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PassPack&#8217;s Profit Model &#171; PassPack Blog</title>
		<link>http://www.tummblr.com/security/is-it-possible-to-trust-online-password-managers-like-passpack-and-clipperz/#comment-291</link>
		<dc:creator>PassPack&#8217;s Profit Model &#171; PassPack Blog</dc:creator>
		<pubDate>Wed, 20 Feb 2008 14:27:57 +0000</pubDate>
		<guid>http://www.tummblr.com/security/is-it-possible-to-trust-online-password-managers-like-passpack-and-clipperz/#comment-291</guid>
		<description>[...] to Tummblr for spurring me on for this [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] to Tummblr for spurring me on for this [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Starhawk Laughingsun</title>
		<link>http://www.tummblr.com/security/is-it-possible-to-trust-online-password-managers-like-passpack-and-clipperz/#comment-289</link>
		<dc:creator>Starhawk Laughingsun</dc:creator>
		<pubDate>Tue, 19 Feb 2008 21:24:14 +0000</pubDate>
		<guid>http://www.tummblr.com/security/is-it-possible-to-trust-online-password-managers-like-passpack-and-clipperz/#comment-289</guid>
		<description>LOL

I subscribe to about 600 blogs just don't have time to comment on them all, but yeah yours is one of them ;)</description>
		<content:encoded><![CDATA[<p>LOL</p>
<p>I subscribe to about 600 blogs just don&#8217;t have time to comment on them all, but yeah yours is one of them <img src='http://www.tummblr.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tummblr</title>
		<link>http://www.tummblr.com/security/is-it-possible-to-trust-online-password-managers-like-passpack-and-clipperz/#comment-288</link>
		<dc:creator>Tummblr</dc:creator>
		<pubDate>Tue, 19 Feb 2008 21:09:46 +0000</pubDate>
		<guid>http://www.tummblr.com/security/is-it-possible-to-trust-online-password-managers-like-passpack-and-clipperz/#comment-288</guid>
		<description>@Marco and Tara: Thank you both for your comments.  Glad to hear that there are many great things in the pipelines.  Looking forward to them!

@Starhawk: You must be the only one who follows my random ramblings.  Thanks, it certainly makes my day. ^_^</description>
		<content:encoded><![CDATA[<p>@Marco and Tara: Thank you both for your comments.  Glad to hear that there are many great things in the pipelines.  Looking forward to them!</p>
<p>@Starhawk: You must be the only one who follows my random ramblings.  Thanks, it certainly makes my day. ^_^</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Starhawk Laughingsun</title>
		<link>http://www.tummblr.com/security/is-it-possible-to-trust-online-password-managers-like-passpack-and-clipperz/#comment-287</link>
		<dc:creator>Starhawk Laughingsun</dc:creator>
		<pubDate>Tue, 19 Feb 2008 20:50:59 +0000</pubDate>
		<guid>http://www.tummblr.com/security/is-it-possible-to-trust-online-password-managers-like-passpack-and-clipperz/#comment-287</guid>
		<description>Wow this sure got some attention. lmao

Anyway I use Clipperz and love it. It solves my problem of having many passwords and using many machines, some not even my own. Having the source code public was one of the reasons I choose that site. I did look at the source code tho I'm no security expert I can code a bit. I have no data there truly important tho just passwords to e-mail and social sites and stuff. 

Great article.</description>
		<content:encoded><![CDATA[<p>Wow this sure got some attention. lmao</p>
<p>Anyway I use Clipperz and love it. It solves my problem of having many passwords and using many machines, some not even my own. Having the source code public was one of the reasons I choose that site. I did look at the source code tho I&#8217;m no security expert I can code a bit. I have no data there truly important tho just passwords to e-mail and social sites and stuff. </p>
<p>Great article.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tara Kelly (PassPack)</title>
		<link>http://www.tummblr.com/security/is-it-possible-to-trust-online-password-managers-like-passpack-and-clipperz/#comment-286</link>
		<dc:creator>Tara Kelly (PassPack)</dc:creator>
		<pubDate>Tue, 19 Feb 2008 11:32:20 +0000</pubDate>
		<guid>http://www.tummblr.com/security/is-it-possible-to-trust-online-password-managers-like-passpack-and-clipperz/#comment-286</guid>
		<description>Hi there.
First - great post! Thank you for taking the time to do such an in depth analysis. You touched on a lot of points, so I'm going to just list off some bullets below:

* Compete.com
I checked their FAQ [http://compete.com/help#snp8] and it seems the trust score uses GeoTrust. We have our SSL certificate via Comodo, Clipperz has theirs on Equifax (which is owned by GeoTrust http://tinyurl.com/2azzvc). I've written their support team to understand how this effects my trust score. THANK you for pointing this out. I'll let you know Compete's reply.

* Traffic &#38; Users
Yeah, we're still just getting started. But there is growth. I'll let you know when we get to a million ;)

* Releasing the source code for public review
Absolutely. We will be doing this.

* Third-party Security Audits
Yes, we'll be doing these too. It's in the budget.

* Business &#38; Profit Model
We actually have a business plan :) We'll be using the Freemium model. I believe the first time I mentioned upgrades was here: http://tinyurl.com/347h8z and we actually wound up changing our pricing plan based on user feedback in the comments. The paid packages will expand accounts and also add some features, mostly for businesses http://tinyurl.com/36lxhc

With the upcoming release of Beta 6, we'll also be doing a site redesign so I'll make sure to make this info more easily available.

* Funding
I can't release any information now about funding, but it is undoubtedly top of the list for us.

* Other ideas
I LOVE your ideas on collaboration and getting some free security audits. I'll definitely look into that. Thanks.

I think I addressed all the macro issues you raised, but please me know if you want more or different information.
Cheers to you,
Tara
PassPack Founding Partner</description>
		<content:encoded><![CDATA[<p>Hi there.<br />
First - great post! Thank you for taking the time to do such an in depth analysis. You touched on a lot of points, so I&#8217;m going to just list off some bullets below:</p>
<p>* Compete.com<br />
I checked their FAQ [http://compete.com/help#snp8] and it seems the trust score uses GeoTrust. We have our SSL certificate via Comodo, Clipperz has theirs on Equifax (which is owned by GeoTrust <a href="http://tinyurl.com/2azzvc" rel="nofollow" onclick="javascript:pageTracker._trackPageview ('/outbound/tinyurl.com');">http://tinyurl.com/2azzvc</a>). I&#8217;ve written their support team to understand how this effects my trust score. THANK you for pointing this out. I&#8217;ll let you know Compete&#8217;s reply.</p>
<p>* Traffic &amp; Users<br />
Yeah, we&#8217;re still just getting started. But there is growth. I&#8217;ll let you know when we get to a million <img src='http://www.tummblr.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>* Releasing the source code for public review<br />
Absolutely. We will be doing this.</p>
<p>* Third-party Security Audits<br />
Yes, we&#8217;ll be doing these too. It&#8217;s in the budget.</p>
<p>* Business &amp; Profit Model<br />
We actually have a business plan <img src='http://www.tummblr.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> We&#8217;ll be using the Freemium model. I believe the first time I mentioned upgrades was here: <a href="http://tinyurl.com/347h8z" rel="nofollow" onclick="javascript:pageTracker._trackPageview ('/outbound/tinyurl.com');">http://tinyurl.com/347h8z</a> and we actually wound up changing our pricing plan based on user feedback in the comments. The paid packages will expand accounts and also add some features, mostly for businesses <a href="http://tinyurl.com/36lxhc" rel="nofollow" onclick="javascript:pageTracker._trackPageview ('/outbound/tinyurl.com');">http://tinyurl.com/36lxhc</a></p>
<p>With the upcoming release of Beta 6, we&#8217;ll also be doing a site redesign so I&#8217;ll make sure to make this info more easily available.</p>
<p>* Funding<br />
I can&#8217;t release any information now about funding, but it is undoubtedly top of the list for us.</p>
<p>* Other ideas<br />
I LOVE your ideas on collaboration and getting some free security audits. I&#8217;ll definitely look into that. Thanks.</p>
<p>I think I addressed all the macro issues you raised, but please me know if you want more or different information.<br />
Cheers to you,<br />
Tara<br />
PassPack Founding Partner</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marco Barulli</title>
		<link>http://www.tummblr.com/security/is-it-possible-to-trust-online-password-managers-like-passpack-and-clipperz/#comment-285</link>
		<dc:creator>Marco Barulli</dc:creator>
		<pubDate>Tue, 19 Feb 2008 09:08:21 +0000</pubDate>
		<guid>http://www.tummblr.com/security/is-it-possible-to-trust-online-password-managers-like-passpack-and-clipperz/#comment-285</guid>
		<description>Dear Tummblr,
thanks for the great post!

Host-proof hosting, ie. encryption on the browser, is not enough to drift the attention away from trusting us, the developers, and let users focus on trusting the application.

Clipperz is the first "zero-knowledge web application" and it's based on the following rules:
- encryption on the browser (host-proof hosting)
- hide nothing (source code available, tools for checking code integrity, ...)
- prevent code changes (download all the code before login, avoid code injections, ...)
- learn nothing!

The password manager is just our first experiment, but we have plenty of ideas about other contexts that could benefit from a zero-knowledge approach.
Think of corporate wikis, online poker sites, web chats, health records, ...

With regard to the business model, Clipperz password manager is free and it will always be free. We need a large community of users, a large number of eyeballs looking at our code to validate the zero-knowledge paradigm!

We are currently accepting donations to sustain the project.

Thanks again, great post,
Marco
Clipperz co-founder</description>
		<content:encoded><![CDATA[<p>Dear Tummblr,<br />
thanks for the great post!</p>
<p>Host-proof hosting, ie. encryption on the browser, is not enough to drift the attention away from trusting us, the developers, and let users focus on trusting the application.</p>
<p>Clipperz is the first &#8220;zero-knowledge web application&#8221; and it&#8217;s based on the following rules:<br />
- encryption on the browser (host-proof hosting)<br />
- hide nothing (source code available, tools for checking code integrity, &#8230;)<br />
- prevent code changes (download all the code before login, avoid code injections, &#8230;)<br />
- learn nothing!</p>
<p>The password manager is just our first experiment, but we have plenty of ideas about other contexts that could benefit from a zero-knowledge approach.<br />
Think of corporate wikis, online poker sites, web chats, health records, &#8230;</p>
<p>With regard to the business model, Clipperz password manager is free and it will always be free. We need a large community of users, a large number of eyeballs looking at our code to validate the zero-knowledge paradigm!</p>
<p>We are currently accepting donations to sustain the project.</p>
<p>Thanks again, great post,<br />
Marco<br />
Clipperz co-founder</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.143 seconds -->
