<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1176949257541686127.post697356497982978561..comments</id><updated>2009-11-18T13:14:31.732-08:00</updated><title type='text'>Comments on Google Online Security Blog: Password strength and account recovery options</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://googleonlinesecurity.blogspot.com/feeds/697356497982978561/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html'/><author><name>Molly Graham</name><uri>http://www.blogger.com/profile/14622034276288473028</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>20</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-4005327959608512367</id><published>2009-10-03T12:18:54.973-07:00</published><updated>2009-10-03T12:18:54.973-07:00</updated><title type='text'>The way to go is password less user authentication...</title><content type='html'>The way to go is password less user authentication which my company has developed.&lt;br /&gt;&lt;br /&gt;Here the user does not require to define or enter a password or remember it. The password is generated by the unique identity of the users computer or device and is not stored anywhere thus making it inherently more secured.&lt;br /&gt;&lt;br /&gt;Imagine an online database on a server such as google&amp;#39;s where there is no password field. &lt;br /&gt;&lt;br /&gt;you can head to easysecured.com to know more about this technology.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/4005327959608512367'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/4005327959608512367'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1254597534973#c4005327959608512367' title=''/><author><name>easysecured</name><uri>http://www.blogger.com/profile/12866471754533946051</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-2022588115865766847</id><published>2009-10-01T15:15:30.824-07:00</published><updated>2009-10-01T15:15:30.824-07:00</updated><title type='text'>Here's a way to add strong authentication includin...</title><content type='html'>Here&amp;#39;s a way to add strong authentication including Free Verisign VIP mobile tokens (yes, the same you use for accessing Paypal, etc) to your Google Apps.&lt;br /&gt;You do need to be a Google Apps Premier customer. Offered by www.myonelogin.com in partnership with Verisign.&lt;br /&gt;To signup go to: http://www.myonelogin.com/googleapps/</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/2022588115865766847'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/2022588115865766847'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1254435330824#c2022588115865766847' title=''/><author><name>Vijay</name><uri>http://www.blogger.com/profile/05473424068231604016</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-2706450483168022564</id><published>2009-09-18T14:58:39.316-07:00</published><updated>2009-09-18T14:58:39.316-07:00</updated><title type='text'>I have developed a way to address this issue and o...</title><content type='html'>I have developed a way to address this issue and on my way to setting up a business around it. &lt;br /&gt;&lt;br /&gt;founder, easysecured.com</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/2706450483168022564'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/2706450483168022564'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1253311119316#c2706450483168022564' title=''/><author><name>easysecured</name><uri>http://www.blogger.com/profile/12866471754533946051</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-9193903384852455545</id><published>2009-08-19T11:56:16.658-07:00</published><updated>2009-08-19T11:56:16.658-07:00</updated><title type='text'>Macduff: I am the admin of a Google Apps Education...</title><content type='html'>Macduff: I am the admin of a Google Apps Education domain (student.columbustech.edu). I spend more time resetting forgotten passwords than any other job I do.  Is there a way to add the password recovery feature to a domain? My LMS and SIS have that feature, but we do not have a SSO system.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/9193903384852455545'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/9193903384852455545'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1250708176658#c9193903384852455545' title=''/><author><name>RayTMercer</name><uri>http://www.blogger.com/profile/02886493223046092326</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-3866341606784568371</id><published>2009-08-13T01:00:58.556-07:00</published><updated>2009-08-13T01:00:58.556-07:00</updated><title type='text'>I've been getting some wrong email notification, d...</title><content type='html'>I&amp;#39;ve been getting some wrong email notification, due to new user mistakenly put my email address as his/her secondary. Then I can takeover that account by sending a &amp;#39;password forgotten&amp;#39; request.&lt;br /&gt;&lt;br /&gt;I believe GMail must add extra steps to verify secondary account ownership, to prevent this kind of attack.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/3866341606784568371'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/3866341606784568371'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1250150458556#c3866341606784568371' title=''/><author><name>andika</name><uri>http://www.blogger.com/profile/06010901468419290922</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-6388947159575814402</id><published>2009-07-29T13:45:03.160-07:00</published><updated>2009-07-29T13:45:03.160-07:00</updated><title type='text'>I really use a lot of ways to make my pass stronge...</title><content type='html'>I really use a lot of ways to make my pass stronger&lt;br /&gt;1- using numbers&lt;br /&gt;2- using alternating capital and small letters&lt;br /&gt;3- using symbols : &amp;amp; * $ &lt;br /&gt;&lt;br /&gt;this password would never be guesed by any program in million years</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/6388947159575814402'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/6388947159575814402'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1248900303160#c6388947159575814402' title=''/><author><name>Ellithy</name><uri>http://www.blogger.com/profile/05692725553710188150</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-6984167350892038276</id><published>2009-07-29T13:44:40.804-07:00</published><updated>2009-07-29T13:44:40.804-07:00</updated><title type='text'>I really use a lot of ways to make my pass stronge...</title><content type='html'>I really use a lot of ways to make my pass stronger&lt;br /&gt;1- using numbers&lt;br /&gt;2- using alternating capital and small letters&lt;br /&gt;3- using symbols : &amp;amp; * $ &lt;br /&gt;&lt;br /&gt;this password would never be guesed by any program in million years</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/6984167350892038276'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/6984167350892038276'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1248900280804#c6984167350892038276' title=''/><author><name>Ellithy</name><uri>http://www.blogger.com/profile/05692725553710188150</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-1664488387416784551</id><published>2009-07-28T01:56:45.583-07:00</published><updated>2009-07-28T01:56:45.583-07:00</updated><title type='text'>nice blog. i liked it!
Web Design  India</title><content type='html'>nice blog. i liked it!&lt;br /&gt;&lt;a href="http://www.suhanasoft.com" rel="nofollow"&gt;Web Design  India&lt;/a&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/1664488387416784551'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/1664488387416784551'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1248771405583#c1664488387416784551' title=''/><author><name>soni</name><uri>http://www.blogger.com/profile/10404785132759787778</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-990068033935945420</id><published>2009-07-23T13:14:30.939-07:00</published><updated>2009-07-23T13:14:30.939-07:00</updated><title type='text'>Has there been any thought to supporting the use o...</title><content type='html'>Has there been any thought to supporting the use of client digital certicates to strengthen authentication to google apps / gmail?&lt;br /&gt;&lt;br /&gt;ie as available from entrust, verisign, thawte etc&lt;br /&gt;&lt;br /&gt;Craig Leppan.&lt;br /&gt;leppan.craig@gmail.com</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/990068033935945420'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/990068033935945420'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1248380070939#c990068033935945420' title=''/><author><name>K800</name><uri>http://www.blogger.com/profile/15119168256477784915</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-8419190204764443314</id><published>2009-07-21T03:00:08.177-07:00</published><updated>2009-07-21T03:00:08.177-07:00</updated><title type='text'>The reality is that relative risk is much higher i...</title><content type='html'>The reality is that relative risk is much higher if the account is a corporate one, and a whole lot of information is suddenly exposed.&lt;br /&gt;&lt;br /&gt;The reality also is that this is easy to guard against, and that any enterprise users should use two-factor authentication for Google Apps, SFDC or any other cloud platform.  &lt;br /&gt;&lt;br /&gt;Two-factor btw means that in addition to the username and password the system requires another unique bit of information.  We normally use a phone-based app for this: when coming in from the &amp;quot;outside&amp;quot; you get asked for your username, password, and the magic number displayed by our app on your phone.  Most people have their phone within reach at most times, so it&amp;#39;s easy.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Adding this level of control to your Google domain takes a day.&lt;/b&gt;  There is no excuse not to, if your information is valuable enough.  This isn&amp;#39;t rocket science.&lt;br /&gt;&lt;br /&gt;J</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/8419190204764443314'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/8419190204764443314'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1248170408177#c8419190204764443314' title=''/><author><name>Jan Zawadzki (Cloudbreak)</name><uri>http://www.blogger.com/profile/02694310331327019436</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-1241410734647421882</id><published>2009-07-20T13:43:51.297-07:00</published><updated>2009-07-20T13:43:51.297-07:00</updated><title type='text'>perhaps someone here could help.

I've been a huge...</title><content type='html'>perhaps someone here could help.&lt;br /&gt;&lt;br /&gt;I&amp;#39;ve been a huge gmail/blogger fan for the last five years.  i&amp;#39;ve misplaced my pw and can only read my mobile gmail on my iphone and can no longer log into google to blog - www.fixbuffalo.blogspot.com - and no nolonger have access to my secondary email to do the pw recovery routine.&lt;br /&gt;&lt;br /&gt;Any work arounds?  Thanks in advance for your help.&lt;br /&gt;&lt;br /&gt;david torke @ gmail.com</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/1241410734647421882'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/1241410734647421882'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1248122631297#c1241410734647421882' title=''/><author><name>david</name><uri>http://www.blogger.com/profile/00078162828910271270</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-6516989639582584535</id><published>2009-07-19T10:12:24.890-07:00</published><updated>2009-07-19T10:12:24.890-07:00</updated><title type='text'>2-3 weeks back my wife's gmail account got comprom...</title><content type='html'>2-3 weeks back my wife&amp;#39;s gmail account got compromised and her pwd got changed. She changed it 3-4 times and everytime she changed it should to get hacked or god knows what the next day. &lt;br /&gt;&lt;br /&gt;There is no way to get access back to the gmail account. The password recovery form asks questions like date/month and year of account creation, how does google think that an individual will remember such things. It has all these questions with months and dates that it is next to impossible to get your account back. &lt;br /&gt;&lt;br /&gt;There is no way to write to google for help, there is just no email or contact form. You just keep going round and round and eventually land at the same place.&lt;br /&gt;&lt;br /&gt;Can you pls help us out.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/6516989639582584535'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/6516989639582584535'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1248023544890#c6516989639582584535' title=''/><author><name>Raman</name><uri>http://www.blogger.com/profile/05003885932069342033</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-8551090204420046219</id><published>2009-07-17T16:59:08.369-07:00</published><updated>2009-07-17T16:59:08.369-07:00</updated><title type='text'>One word: Gtoken (2-factor authentication).  Where...</title><content type='html'>One word: Gtoken (2-factor authentication).  Where is it?  Should be a paid upgrade for Gmail and Google Apps.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/8551090204420046219'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/8551090204420046219'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1247875148369#c8551090204420046219' title=''/><author><name>Chris</name><uri>http://www.blogger.com/profile/12452424766132750993</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-2103683051155606917</id><published>2009-07-17T08:38:45.061-07:00</published><updated>2009-07-17T08:38:45.061-07:00</updated><title type='text'>Is there a reason you can't adjust the password le...</title><content type='html'>Is there a reason you can&amp;#39;t adjust the password length requirements on Google Apps standard edition?  I know that&amp;#39;s the free version, but isn&amp;#39;t security just as important, free or not?&lt;br /&gt;&lt;br /&gt;Just wondering.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/2103683051155606917'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/2103683051155606917'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1247845125061#c2103683051155606917' title=''/><author><name>Josh Turmel</name><uri>http://www.blogger.com/profile/07666118261605225467</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-6566045347707381754</id><published>2009-07-16T18:52:05.666-07:00</published><updated>2009-07-16T18:52:05.666-07:00</updated><title type='text'>Protecting my personal gmail account is something ...</title><content type='html'>Protecting my personal gmail account is something I take seriously, I really wish that Google would enable me, a personal free email account user, to purchase and use a 2 factor token. For me there is no problem coming up with 20 bucks for a token like I did for Paypal. The cloud is here to stay and that means much more exposure to risk for everyone. Corporations (like Google) can fend for themselves and protect their assets with 2 factor authentication. It hurts know that Google will not offer their customers a way to protect themselves, even if they are willing to bear the cost.  Please make 2 factor authentication available for the all users.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/6566045347707381754'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/6566045347707381754'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1247795525666#c6566045347707381754' title=''/><author><name>Carl</name><uri>http://www.blogger.com/profile/17744980628844288720</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-4277424780651021594</id><published>2009-07-16T07:51:27.403-07:00</published><updated>2009-07-16T07:51:27.403-07:00</updated><title type='text'>I do like the idea of having an authenticator that...</title><content type='html'>I do like the idea of having an authenticator that can be used for apps or email.&lt;br /&gt;&lt;br /&gt;This way the password could be different every time you log-in.&lt;br /&gt;&lt;br /&gt;World of Warcraft does this as someone already posted, and that is for a game.&lt;br /&gt;&lt;br /&gt;The app could be made for Pre, Iphone, or other smart phone devices or as a device you buy for say 5-10 dollars.&lt;br /&gt;&lt;br /&gt;A pretty low price to pay for more security.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/4277424780651021594'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/4277424780651021594'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1247755887403#c4277424780651021594' title=''/><author><name>Crimsonwar</name><uri>http://www.blogger.com/profile/15979466414481445260</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-840739222179555401</id><published>2009-07-16T06:40:07.740-07:00</published><updated>2009-07-16T06:40:07.740-07:00</updated><title type='text'>IMO, most small companies see a net increase in se...</title><content type='html'>IMO, most small companies see a net increase in security by outsourcing their IT.  It is just too hard to keep up with patches, attacks etc while maintaining valued services for employees.  &lt;br /&gt;&lt;br /&gt;That being said, if you rely on a basket of web-based apps, you should watch that basket.  &lt;br /&gt;&lt;br /&gt;Here&amp;#39;s a tutorial I wrote on how to use the open-source version of &lt;a href="http://www.howtoforge.net/two-factor-authentication-for-google-apps-for-your-domain-using-sso-saml-and-wikid-strong-authentication-server" rel="nofollow"&gt; WiKID Strong  Authentication with Google Apps Enterprise&lt;/a&gt; for those interested in adding two-factor to Google Apps.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/840739222179555401'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/840739222179555401'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1247751607740#c840739222179555401' title=''/><author><name>Nick Owen</name><uri>http://www.blogger.com/profile/14110140129040101523</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-7839301664090115889</id><published>2009-07-15T21:52:41.057-07:00</published><updated>2009-07-15T21:52:41.057-07:00</updated><title type='text'>Security has always been our major concern in this...</title><content type='html'>Security has always been our major concern in this online world. Almost everybody is maintaining accounts online like emails, on purchasing products, online game subscriptions and a lot more. You may also want to check this article about online safety: http://www.articlesbase.com/video-games-articles/safety-in-the-world-of-warcraft-1014729.html</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/7839301664090115889'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/7839301664090115889'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1247719961057#c7839301664090115889' title=''/><author><name>George</name><uri>http://www.blogger.com/profile/17235679276481399548</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-3069818642905633640</id><published>2009-07-15T15:47:45.839-07:00</published><updated>2009-07-15T15:47:45.839-07:00</updated><title type='text'>I thin Google should allow to add up security toke...</title><content type='html'>I thin Google should allow to add up security tokens with the Google apps account so people able to do the check. as you know that ATM cards works only with the combination of pin and card..if both things not matched then nothing gonna happen..&lt;br /&gt;&lt;br /&gt;same thing should be here..a Google apps password and a security card like an ATM without the combination no access to Google Apps..and Google should not put security as a feature..all premium level security feature should get in all Google Apps account weather its free or paid..&lt;br /&gt;&lt;br /&gt;If possible attach Google apps authentication system with fingerprint reader ...that would be much accurate than the password security..&lt;br /&gt;&lt;br /&gt;i think all companies should think beyond passwords..web 2 has come so I think in security it&amp;#39;s time to implement new level of protocols..password is old thing now..</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/3069818642905633640'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/3069818642905633640'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1247698065839#c3069818642905633640' title=''/><author><name>Aniruddh D</name><uri>http://www.blogger.com/profile/14158712405572278328</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1176949257541686127.post-8595613989854310983</id><published>2009-07-15T13:56:12.467-07:00</published><updated>2009-07-15T13:56:12.467-07:00</updated><title type='text'>Thanks for opening up a conversation about this su...</title><content type='html'>Thanks for opening up a conversation about this subject.  One thought I&amp;#39;ve had recently is that it is in the best interest of Google and all vendors of web apps to have a high level of security.  If free Google Apps accounts and/or Google accounts are getting routinely broken into, it is bad for Google in several ways:&lt;br /&gt;&lt;br /&gt;* Trust for Google decreases&lt;br /&gt;&lt;br /&gt;* Fear of trusting data to the cloud increases&lt;br /&gt;&lt;br /&gt;* Spam increases (spam bots get contacts)&lt;br /&gt;&lt;br /&gt;* Expense for Google increases (support requests to help users recover compromised accounts)&lt;br /&gt;&lt;br /&gt;On the other hand, if Google can enable a user experience which makes data MORE secure than desktop data, then it will help secure more corporate customers.&lt;br /&gt;&lt;br /&gt;Given these incentives, I think it is in Google&amp;#39;s best interests to trickle down some of the features from Premier Apps down to Free Apps and Google Accounts.  Specifically (for free accounts):&lt;br /&gt;&lt;br /&gt;* SAML SSO enabling two factor authentication&lt;br /&gt;&lt;br /&gt;* Allow administrators to set password length requirements&lt;br /&gt;&lt;br /&gt;* Make it possible for a Google Apps administrator to remove administrative rights from any user (including the one that established the Google Apps account - if this ends up as a frequently used account, then it is more likely to get compromised than a rarely used account that is only used to administer Google Apps)&lt;br /&gt;&lt;br /&gt;I certainly understand that Google needs to differentiate between Premier and free versions of Google Apps.  And I think the free version of Google Apps is an incredible product.  But adding just a couple of extra security features to the free version could be of great help to both users and to Google.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/8595613989854310983'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1176949257541686127/697356497982978561/comments/default/8595613989854310983'/><link rel='alternate' type='text/html' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html?showComment=1247691372467#c8595613989854310983' title=''/><author><name>FilterJoe</name><uri>http://www.blogger.com/profile/02773405895049488914</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://googleonlinesecurity.blogspot.com/2009/07/password-strength-and-account-recovery.html' ref='tag:blogger.com,1999:blog-1176949257541686127.post-697356497982978561' source='http://www.blogger.com/feeds/1176949257541686127/posts/default/697356497982978561' type='text/html'/></entry></feed>