<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-4109121989878952716.post8366577778303840723..comments</id><updated>2010-02-08T08:17:27.017-08:00</updated><title type='text'>Comments on EHR Bloggers: Annals of Security: Don't Pass the Password</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.ehrbloggers.com/feeds/8366577778303840723/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4109121989878952716/8366577778303840723/comments/default'/><link rel='alternate' type='text/html' href='http://www.ehrbloggers.com/2010/02/annals-of-security-dont-pass-password.html'/><author><name>EHReditor</name><uri>http://www.blogger.com/profile/05554437768441364746</uri><email>emily@practicefusion.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4109121989878952716.post-3060536048790576342</id><published>2010-02-08T08:17:27.017-08:00</published><updated>2010-02-08T08:17:27.017-08:00</updated><title type='text'>I have 3 levels of username/password for the 3 lev...</title><content type='html'>I have 3 levels of username/password for the 3 levels of websites that I use. They are all based on one of 3 phrases that I have in my head and then plying a first character from the phrase. So long as I remember the phrase, I can pretty much always remember my password. An example which I often used while instructing the lawyers who used our legal software was: &amp;quot;We the people of the united states in order to form a more perfect union.&amp;quot; became wtPotU5mpU or something like that. As long as its over 10 characters, has a nice mix of stuff in it and isn&amp;#39;t dictionary recognizable, it&amp;#39;s a decent password.&lt;br /&gt;&lt;br /&gt;But the onus of protection is on the website itself. There are many layers of protection to use, but I think a great thing to do (and we did this on our legal website which required high-levels of security) was to publish a 3rd party report of a penetration test of our security. A double-edge sword, to be certain, but it showed that we took security seriously and were proactive in that. &lt;br /&gt;&lt;br /&gt;It&amp;#39;s one thing to say, &amp;quot;I&amp;#39;m secure&amp;quot;. It&amp;#39;s another to actually show it.&lt;br /&gt;&lt;br /&gt;Additional</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4109121989878952716/8366577778303840723/comments/default/3060536048790576342'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4109121989878952716/8366577778303840723/comments/default/3060536048790576342'/><link rel='alternate' type='text/html' href='http://www.ehrbloggers.com/2010/02/annals-of-security-dont-pass-password.html?showComment=1265645847017#c3060536048790576342' title=''/><author><name>Bernz</name><uri>http://www.blogger.com/profile/16451988884915833897</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.ehrbloggers.com/2010/02/annals-of-security-dont-pass-password.html' ref='tag:blogger.com,1999:blog-4109121989878952716.post-8366577778303840723' source='http://www.blogger.com/feeds/4109121989878952716/posts/default/8366577778303840723' type='text/html'/></entry></feed>