<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Amazon.com &#8220;PayPhrase&#8221; shortcut for paying</title>
	<atom:link href="http://tamebay.com/2009/11/amazon-com-payphrase-shortcut-for-paying.html/feed" rel="self" type="application/rss+xml" />
	<link>http://tamebay.com/2009/11/amazon-com-payphrase-shortcut-for-paying.html</link>
	<description>eBay &#38; ecommerce made easy</description>
	<lastBuildDate>Sun, 12 Feb 2012 08:10:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: John</title>
		<link>http://tamebay.com/2009/11/amazon-com-payphrase-shortcut-for-paying.html#comment-53270</link>
		<dc:creator>John</dc:creator>
		<pubDate>Sun, 15 Nov 2009 22:10:06 +0000</pubDate>
		<guid isPermaLink="false">http://tamebay.com/?p=9579#comment-53270</guid>
		<description>I would like to see Amazon releasing seller funds alot quicker than they do...currently it takes a couple of weeks to get funds from them.</description>
		<content:encoded><![CDATA[<p>I would like to see Amazon releasing seller funds alot quicker than they do&#8230;currently it takes a couple of weeks to get funds from them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://tamebay.com/2009/11/amazon-com-payphrase-shortcut-for-paying.html#comment-53151</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Thu, 12 Nov 2009 15:58:38 +0000</pubDate>
		<guid isPermaLink="false">http://tamebay.com/?p=9579#comment-53151</guid>
		<description>This is slightly worrying. Amazon appear to be trying to reinvent the username and password. Rather than suggesting to customers use mixed case, letters and a combination of numbers - they are trying to push the use of standardised dictionary phrases or something which you can easily associate with an individual. Username and passwords should always have some input of randomness - this project needs a good rethink or should be scrapped.</description>
		<content:encoded><![CDATA[<p>This is slightly worrying. Amazon appear to be trying to reinvent the username and password. Rather than suggesting to customers use mixed case, letters and a combination of numbers &#8211; they are trying to push the use of standardised dictionary phrases or something which you can easily associate with an individual. Username and passwords should always have some input of randomness &#8211; this project needs a good rethink or should be scrapped.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ebuyerfb</title>
		<link>http://tamebay.com/2009/11/amazon-com-payphrase-shortcut-for-paying.html#comment-53096</link>
		<dc:creator>ebuyerfb</dc:creator>
		<pubDate>Wed, 11 Nov 2009 02:08:01 +0000</pubDate>
		<guid isPermaLink="false">http://tamebay.com/?p=9579#comment-53096</guid>
		<description>Do you have to be logged into Amazon payments for this to work?  Otherwise this looks like it has a huge security hole in it.  The fact that no two pay phrases are identical suggests that you don&#039;t need to be logged in.

All they&#039;ve basically done is made a complex username (one with a first and last name).  But that username is very easy to guess.  And they attached a 4 digit pin (extremely weak).

1)  pick a common phrase like &quot;pay now&quot;, &quot;buy now&quot;, two word movie titles, etc
2)  see if registration fails
3)  guess pin

It says after a number of incorrect guesses it locks out the person but if this takes off there will be plenty of pay phrases to hack.</description>
		<content:encoded><![CDATA[<p>Do you have to be logged into Amazon payments for this to work?  Otherwise this looks like it has a huge security hole in it.  The fact that no two pay phrases are identical suggests that you don&#8217;t need to be logged in.</p>
<p>All they&#8217;ve basically done is made a complex username (one with a first and last name).  But that username is very easy to guess.  And they attached a 4 digit pin (extremely weak).</p>
<p>1)  pick a common phrase like &#8220;pay now&#8221;, &#8220;buy now&#8221;, two word movie titles, etc<br />
2)  see if registration fails<br />
3)  guess pin</p>
<p>It says after a number of incorrect guesses it locks out the person but if this takes off there will be plenty of pay phrases to hack.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

