<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Our provider has been hacked, but Passpack is safe. Zero data compromised.</title>
	<atom:link href="http://blog.passpack.com/2011/10/our-provider-has-been-hacked-but-passpack-is-safe-zero-data-compromised/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.passpack.com/2011/10/our-provider-has-been-hacked-but-passpack-is-safe-zero-data-compromised/</link>
	<description>Passpack keeps your logins safe, organized and available 24/7. You can share passwords with your team in 100% privacy.</description>
	<lastBuildDate>Fri, 10 May 2013 18:12:33 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4</generator>
	<item>
		<title>By: Francesco</title>
		<link>http://blog.passpack.com/2011/10/our-provider-has-been-hacked-but-passpack-is-safe-zero-data-compromised/comment-page-1/#comment-5599</link>
		<dc:creator>Francesco</dc:creator>
		<pubDate>Mon, 24 Oct 2011 17:30:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.passpack.com/?p=4278#comment-5599</guid>
		<description>@Dave, Firehost is a good solution, but it is expensive. Currently our 4 dedicated servers cost about 300 dollars a month. On Firehost we will spend ten times this amount.</description>
		<content:encoded><![CDATA[<p>@Dave, Firehost is a good solution, but it is expensive. Currently our 4 dedicated servers cost about 300 dollars a month. On Firehost we will spend ten times this amount.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://blog.passpack.com/2011/10/our-provider-has-been-hacked-but-passpack-is-safe-zero-data-compromised/comment-page-1/#comment-5598</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Mon, 24 Oct 2011 16:55:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.passpack.com/?p=4278#comment-5598</guid>
		<description>Is there any point on you hosting on FireHost.com ?? It sounds as a perfect match for you. Please let us know.</description>
		<content:encoded><![CDATA[<p>Is there any point on you hosting on FireHost.com ?? It sounds as a perfect match for you. Please let us know.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lorenzo</title>
		<link>http://blog.passpack.com/2011/10/our-provider-has-been-hacked-but-passpack-is-safe-zero-data-compromised/comment-page-1/#comment-5297</link>
		<dc:creator>Lorenzo</dc:creator>
		<pubDate>Fri, 07 Oct 2011 11:17:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.passpack.com/?p=4278#comment-5297</guid>
		<description>Well done Francesco! ;)</description>
		<content:encoded><![CDATA[<p>Well done Francesco! ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Francesco</title>
		<link>http://blog.passpack.com/2011/10/our-provider-has-been-hacked-but-passpack-is-safe-zero-data-compromised/comment-page-1/#comment-5293</link>
		<dc:creator>Francesco</dc:creator>
		<pubDate>Fri, 07 Oct 2011 00:40:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.passpack.com/?p=4278#comment-5293</guid>
		<description>@John, the code injection is the primary risk for a Javascript application. So we constantly monitor all the files, with an automatic procedure that, if there is any anomaly, overwrites the files and immediately alerts us.

Until now, I received alerts only during tests.
And I hope that I will never receive further alerts :)</description>
		<content:encoded><![CDATA[<p>@John, the code injection is the primary risk for a Javascript application. So we constantly monitor all the files, with an automatic procedure that, if there is any anomaly, overwrites the files and immediately alerts us.</p>
<p>Until now, I received alerts only during tests.<br />
And I hope that I will never receive further alerts :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://blog.passpack.com/2011/10/our-provider-has-been-hacked-but-passpack-is-safe-zero-data-compromised/comment-page-1/#comment-5291</link>
		<dc:creator>John</dc:creator>
		<pubDate>Thu, 06 Oct 2011 23:29:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.passpack.com/?p=4278#comment-5291</guid>
		<description>I&#039;m concerned about the Javascript that deals with my passpack password locally in my browser; did you store, and have you checked the hashes of the Passpack Javascript files that actually handle the local password interaction and decryption?

Thanks.</description>
		<content:encoded><![CDATA[<p>I&#8217;m concerned about the Javascript that deals with my passpack password locally in my browser; did you store, and have you checked the hashes of the Passpack Javascript files that actually handle the local password interaction and decryption?</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Francesco</title>
		<link>http://blog.passpack.com/2011/10/our-provider-has-been-hacked-but-passpack-is-safe-zero-data-compromised/comment-page-1/#comment-5290</link>
		<dc:creator>Francesco</dc:creator>
		<pubDate>Thu, 06 Oct 2011 22:50:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.passpack.com/?p=4278#comment-5290</guid>
		<description>@Luca, I still don&#039;t trust cloud infrastructure for critical data. And, in fact, our servers are physical machines.
Also, I prefer software raid for our disks, because you must turn off the server to take a snapshot.
So: no downtime, no snapshot :)</description>
		<content:encoded><![CDATA[<p>@Luca, I still don&#8217;t trust cloud infrastructure for critical data. And, in fact, our servers are physical machines.<br />
Also, I prefer software raid for our disks, because you must turn off the server to take a snapshot.<br />
So: no downtime, no snapshot :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luca</title>
		<link>http://blog.passpack.com/2011/10/our-provider-has-been-hacked-but-passpack-is-safe-zero-data-compromised/comment-page-1/#comment-5289</link>
		<dc:creator>Luca</dc:creator>
		<pubDate>Thu, 06 Oct 2011 22:22:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.passpack.com/?p=4278#comment-5289</guid>
		<description>Full transparency is always appreciated. Thanks!

Having said that, I just want to raise another concern. Paranoia is a virtue, isn&#039;t it?

I assume that the provider is actually using virtual machines. In that case, having access to the provider’s management system, they could have created a snapshot (no noticeable downtime here).

Having physical access, full filesystem encryption is the only real mitigation.

Cheers,
L.</description>
		<content:encoded><![CDATA[<p>Full transparency is always appreciated. Thanks!</p>
<p>Having said that, I just want to raise another concern. Paranoia is a virtue, isn&#8217;t it?</p>
<p>I assume that the provider is actually using virtual machines. In that case, having access to the provider’s management system, they could have created a snapshot (no noticeable downtime here).</p>
<p>Having physical access, full filesystem encryption is the only real mitigation.</p>
<p>Cheers,<br />
L.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
