<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Safe logins in Norton Internet Security / Norton AntiVirus</title>
    <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3927#M1504</link>
    <description>&lt;p&gt;The problem is how it is designed, they just need to password protect the manage login part. They just forgot to check that hole, I don't think it would be that hard to fix.&lt;/p&gt;</description>
    <pubDate>Tue, 27 May 2008 15:39:56 GMT</pubDate>
    <dc:creator>CyberBlaster</dc:creator>
    <dc:date>2008-05-27T15:39:56Z</dc:date>
    <item>
      <title>Identity Safe logins</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3536#M1341</link>
      <description>&lt;p&gt;I like the Identity Safe feature in NIS 2008 but I have a question. You give us the option to ask for our password before entering a &lt;font color="#333333"&gt;specific login information, (which is a great option) and the rest just automatic get entered. The only thing is, since there is no lock or password needed to manage the logins and that option, someone can just turn it off or review my password for it anyway. You could just say just logout of the service but that defeats the purpose of the option I am talking about.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#333333"&gt; &lt;/font&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 21 May 2008 17:44:47 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3536#M1341</guid>
      <dc:creator>CyberBlaster</dc:creator>
      <dc:date>2008-05-21T17:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Safe logins</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3562#M1348</link>
      <description>&lt;p&gt;Go to Control Panel and create a password protected sign on with your self as the admistrator.&lt;/p&gt;&lt;p&gt;You can create different user profiles for others who use your computer, if any. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;While you are there if you'r using XP Pro or Vista Pro turn off file sharing and turn on your file encryption.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Each time you leave your computer sign off.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Wed, 21 May 2008 21:47:35 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3562#M1348</guid>
      <dc:creator>Rasputin</dc:creator>
      <dc:date>2008-05-21T21:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Safe logins</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3587#M1365</link>
      <description>&lt;p&gt;Thats great now everyone knows how to make a new user on windows xp but that isn't the issue.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;If you have used the Identity safe login manger before you know there is an option to prompt for your password (this can be set for each site). Thats what I am talking about. I'm just saying symantec there is a hole in your setup here, because I can turn that option off without the password.&lt;/p&gt;</description>
      <pubDate>Wed, 21 May 2008 23:30:12 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3587#M1365</guid>
      <dc:creator>CyberBlaster</dc:creator>
      <dc:date>2008-05-21T23:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Safe logins</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3614#M1373</link>
      <description>&lt;p&gt;Simply log out of ID safe when you are done using it.  It is not automatic, and I don't think that option is available yet.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Thu, 22 May 2008 13:09:29 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3614#M1373</guid>
      <dc:creator>Phil</dc:creator>
      <dc:date>2008-05-22T13:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Safe logins</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3685#M1393</link>
      <description>Yeah there is an option to ask for the password after 15 mins of inactivity but, take a look in the Manage Login menu. They give the option to prompt for your Identity safe password (there is a little check box for EACH login infomation that says: Require Identity Safe password before filling). So for example the login infomation for, lets say a forum you could have it setup so it just logs in as soon as you go to the site, no questions asked. However lets say you go to your online banking, you can have it ask for your Identity Safe password just to make sure, before it logs you in. This is what I like about it, the only thing is and what I am trying to get across is, that little check box can be unchecked without the password. So you can just uncheck it then go to the online banking then magicly it logs you in. I'm just saying we need a option to put the password on the manage Logins menu so that can't happen.</description>
      <pubDate>Thu, 22 May 2008 23:43:45 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3685#M1393</guid>
      <dc:creator>CyberBlaster</dc:creator>
      <dc:date>2008-05-22T23:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Safe logins</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3693#M1395</link>
      <description>&lt;blockquote&gt;&lt;hr&gt;CyberBlaster wrote: &lt;br&gt;[ .... ] This is what I like about it, the only thing is and what I am trying to get across is, that little check box can be unchecked without the password. So you can just uncheck it then go to the online banking then magicly it logs you in. I'm just saying we need a option to put the password on the manage Logins menu so that can't happen.&lt;hr&gt;&lt;/blockquote&gt;&lt;p&gt;Seems to me that this is a valid and important point -- that that check box should be &lt;em&gt;inside&lt;/em&gt; the controlled area.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Let's see what Norton say about this?&lt;/p&gt;</description>
      <pubDate>Fri, 23 May 2008 01:46:24 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3693#M1395</guid>
      <dc:creator>huwyngr</dc:creator>
      <dc:date>2008-05-23T01:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Safe logins</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3758#M1413</link>
      <description>&lt;p class="MsoNormal"&gt;&lt;a target="_blank" href="http://community.norton.com/norton/view_profile?user.id=1384"&gt;&lt;strong&gt;CyberBlaster&lt;/strong&gt;&lt;/a&gt;, I regret that you were disappointed in my post which you apparently thought was off topic. You pointed out that you think that Symantec should correct a defect in the pass word interface which you believe is a security hazard.&lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt;I agree with you on this.&lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt;My experience in dealing with large corporation is that getting a problem corrected like this is a little like waiting for some one turn the Titanic around using a paddle.&lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt;Until the problem is corrected the end users are left with the idea that we are not defenseless if we can come up with an effective work around that will protect the pass word.&lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt;In addition to the above there usually are a number of pass words and other sensitive information that needs to be protected.&lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt;If no one else uses your pc then using a start up password for start up access, turning off file sharing and the using of AES 256 encrytpion is likely to protect not only the potentially exposed vault pass word but all off the pass words and sensitive information including financial, medical and other information.&lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt;Beyond this if a person is really concerned about pass word protection then if the computer can be made to boot from a UPC drive then the windows start up keys can be moved off of drive C to a UPC drive. With out the presence of the windows start up keys an attacker would encounter the Blue Screen of Death and possibly a little note from BIOS saying “No Operating System Found”.&lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt;Safety would dictate that one makes sure that the system will boot from the UPC before any one tries this and backing up the Windows Start up Keys is really a good idea.&lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt;In Addition to the above, if the entire PC is backed up to an external HD or an off premise server then the user should be aware that the back ups should be backed up to AES 256 or other high grade ciphers.&lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;</description>
      <pubDate>Sat, 24 May 2008 00:08:46 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3758#M1413</guid>
      <dc:creator>Rasputin</dc:creator>
      <dc:date>2008-05-24T00:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Safe logins</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3789#M1429</link>
      <description>&lt;p&gt;Yeah, sorry I posted the response kinda harshly I wasn't it the greatest mood at the time :smileytongue:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;The problem isn't a big deal for me since I have a computer to myself and no one else uses it (except in rare cases). I was just hopeing to point it out and have Norton work on fixing it. I agree sometimes you can point these thing out and they go unanswered from companies. But, since Norton has just started these forums and trying out the whole user interaction thing, I was hopeing to see someone from Norton say something about it by now. Even if its the standard one liner message that they will work on it lol :smileywink:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sat, 24 May 2008 22:25:32 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3789#M1429</guid>
      <dc:creator>CyberBlaster</dc:creator>
      <dc:date>2008-05-24T22:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Safe logins</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3800#M1437</link>
      <description>&lt;p&gt;hi CyberBlaster - i know SYMC folks are watching and i've seen posts from their folks about changes that coincide with what users are posting about, so i think you have a good idea. i'd recommend a more straightforward strategy - list the steps, confirm whether it is as designed or a defect and make your case. i don't see much value doing it otherwise...&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;quot;enhancement request&amp;quot; - recommend SYMC password protect  ID Safe login options to protect secure information. sound about right?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;mel &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sun, 25 May 2008 07:37:59 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3800#M1437</guid>
      <dc:creator>MelodicWynd</dc:creator>
      <dc:date>2008-05-25T07:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Safe logins</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3829#M1451</link>
      <description>&lt;p class="MsoNormal"&gt;“We are aware of the problem and our engineers are working on a solution”.&lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt;I saw this so many times on America Off Line that I thought it was their company logo.&lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt;Cheers&lt;/p&gt;</description>
      <pubDate>Sun, 25 May 2008 22:08:43 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3829#M1451</guid>
      <dc:creator>Rasputin</dc:creator>
      <dc:date>2008-05-25T22:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Safe logins</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3927#M1504</link>
      <description>&lt;p&gt;The problem is how it is designed, they just need to password protect the manage login part. They just forgot to check that hole, I don't think it would be that hard to fix.&lt;/p&gt;</description>
      <pubDate>Tue, 27 May 2008 15:39:56 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/3927#M1504</guid>
      <dc:creator>CyberBlaster</dc:creator>
      <dc:date>2008-05-27T15:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Safe logins</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/4076#M1561</link>
      <description>Thanks, CyberBlaster. I've communicated this information to our product teams to review this suggestion. Great job!</description>
      <pubDate>Wed, 28 May 2008 23:48:10 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/4076#M1561</guid>
      <dc:creator>Tony_Weiss</dc:creator>
      <dc:date>2008-05-28T23:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Safe logins</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/4736#M1859</link>
      <description>&lt;span&gt;Thank you for your question about Identity Safe. We are planning to change the way this feature works in our NIS 2009 release. We will require the Identity Safe password to change this setting. If your subscription to NIS 2008 is up-to-date, you will be able to download and install NIS 2009 once it becomes available.  &lt;/span&gt;</description>
      <pubDate>Wed, 04 Jun 2008 23:20:20 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/4736#M1859</guid>
      <dc:creator>BillR</dc:creator>
      <dc:date>2008-06-04T23:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Safe logins</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/5116#M2015</link>
      <description>&lt;p&gt;Nice, thanks for letting me know.&lt;/p&gt;</description>
      <pubDate>Sun, 08 Jun 2008 17:20:22 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Identity-Safe-logins/m-p/5116#M2015</guid>
      <dc:creator>CyberBlaster</dc:creator>
      <dc:date>2008-06-08T17:20:22Z</dc:date>
    </item>
  </channel>
</rss>

