<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:wfw="http://wellformedweb.org/CommentAPI/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom"
    xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    >
<channel>
    <title>Comments for Windows Security</title>
    <atom:link href="http://www.sans.org/windows-security/comments/feed" rel="self" type="application/rss+xml" />
    <link>http://www.sans.org/windows-security</link>
    <description>Windows Security</description>
    <lastBuildDate>Wed, 02 Oct 2013 5:45:16 +0000</lastBuildDate>
    <language>en</language><item><title>Comment on Reset Local Administrator Password Using A Different Random String On Each Computer And Recover The Passwords Securely by Jason Fossen</title><link>http://www.sans.org/blog/2013/08/01/reset-local-administrator-password-automatically-with-a-different-password-across-the-enterprise/comment-page-1/#comment-2273</link><dc:creator>Jason Fossen</dc:creator><pubDate>Mon, 09 Sep 2013 16:09:51 +0000</pubDate><description><![CDATA[Hi OldguardMD:
I haven't tested this, but an EC certificate should work just fine.  The testing certificate provided in the zip file happens to be RSA, but it's just an example.  A 4096-bit RSA certificate could also be used if one's organization couldn't use an EC cert for some reason.
Cheers,
 Jason]]></description><content:encoded><![CDATA[Hi OldguardMD:
I haven't tested this, but an EC certificate should work just fine.  The testing certificate provided in the zip file happens to be RSA, but it's just an example.  A 4096-bit RSA certificate could also be used if one's organization couldn't use an EC cert for some reason.
Cheers,
 Jason]]></content:encoded></item><item><title>Comment on Reset Local Administrator Password Using A Different Random String On Each Computer And Recover The Passwords Securely by Jason Fossen</title><link>http://www.sans.org/blog/2013/08/01/reset-local-administrator-password-automatically-with-a-different-password-across-the-enterprise/comment-page-1/#comment-2273</link><dc:creator>Jason Fossen</dc:creator><pubDate>Mon, 09 Sep 2013 16:09:51 +0000</pubDate><description><![CDATA[Hi OldguardMD:
I haven't tested this, but an EC certificate should work just fine.  The testing certificate provided in the zip file happens to be RSA, but it's just an example.  A 4096-bit RSA certificate could also be used if one's organization couldn't use an EC cert for some reason.
Cheers,
 Jason]]></description><content:encoded><![CDATA[Hi OldguardMD:
I haven't tested this, but an EC certificate should work just fine.  The testing certificate provided in the zip file happens to be RSA, but it's just an example.  A 4096-bit RSA certificate could also be used if one's organization couldn't use an EC cert for some reason.
Cheers,
 Jason]]></content:encoded></item><item><title>Comment on Reset Local Administrator Password Using A Different Random String On Each Computer And Recover The Passwords Securely by Jason Fossen</title><link>http://www.sans.org/blog/2013/08/01/reset-local-administrator-password-automatically-with-a-different-password-across-the-enterprise/comment-page-1/#comment-2273</link><dc:creator>Jason Fossen</dc:creator><pubDate>Mon, 09 Sep 2013 16:09:51 +0000</pubDate><description><![CDATA[Hi OldguardMD:
I haven't tested this, but an EC certificate should work just fine.  The testing certificate provided in the zip file happens to be RSA, but it's just an example.  A 4096-bit RSA certificate could also be used if one's organization couldn't use an EC cert for some reason.
Cheers,
 Jason]]></description><content:encoded><![CDATA[Hi OldguardMD:
I haven't tested this, but an EC certificate should work just fine.  The testing certificate provided in the zip file happens to be RSA, but it's just an example.  A 4096-bit RSA certificate could also be used if one's organization couldn't use an EC cert for some reason.
Cheers,
 Jason]]></content:encoded></item><item><title>Comment on Reset Local Administrator Password Using A Different Random String On Each Computer And Recover The Passwords Securely by Jason Fossen</title><link>http://www.sans.org/blog/2013/08/01/reset-local-administrator-password-automatically-with-a-different-password-across-the-enterprise/comment-page-1/#comment-2273</link><dc:creator>Jason Fossen</dc:creator><pubDate>Mon, 09 Sep 2013 16:09:51 +0000</pubDate><description><![CDATA[Hi OldguardMD:
I haven't tested this, but an EC certificate should work just fine.  The testing certificate provided in the zip file happens to be RSA, but it's just an example.  A 4096-bit RSA certificate could also be used if one's organization couldn't use an EC cert for some reason.
Cheers,
 Jason]]></description><content:encoded><![CDATA[Hi OldguardMD:
I haven't tested this, but an EC certificate should work just fine.  The testing certificate provided in the zip file happens to be RSA, but it's just an example.  A 4096-bit RSA certificate could also be used if one's organization couldn't use an EC cert for some reason.
Cheers,
 Jason]]></content:encoded></item><item><title>Comment on Reset Local Administrator Password Using A Different Random String On Each Computer And Recover The Passwords Securely by Jason Fossen</title><link>http://www.sans.org/blog/2013/08/01/reset-local-administrator-password-automatically-with-a-different-password-across-the-enterprise/comment-page-1/#comment-2268</link><dc:creator>Jason Fossen</dc:creator><pubDate>Mon, 09 Sep 2013 15:59:08 +0000</pubDate><description><![CDATA[Hi Stephen:
With properly-implemented whole disk encryption under the right circumstances, it wouldn't be possible to boot to another OS and reset a local account's password.  Also, we have to worry about not just physical theft of portables, but also internal PCs and hackers who are try to leapfrog laterally from one box to another, in which case having a different local admin password on every computer is useful.
Cheers,
Jason]]></description><content:encoded><![CDATA[Hi Stephen:
With properly-implemented whole disk encryption under the right circumstances, it wouldn't be possible to boot to another OS and reset a local account's password.  Also, we have to worry about not just physical theft of portables, but also internal PCs and hackers who are try to leapfrog laterally from one box to another, in which case having a different local admin password on every computer is useful.
Cheers,
Jason]]></content:encoded></item><item><title>Comment on Reset Local Administrator Password Using A Different Random String On Each Computer And Recover The Passwords Securely by Jason Fossen</title><link>http://www.sans.org/blog/2013/08/01/reset-local-administrator-password-automatically-with-a-different-password-across-the-enterprise/comment-page-1/#comment-2268</link><dc:creator>Jason Fossen</dc:creator><pubDate>Mon, 09 Sep 2013 15:59:08 +0000</pubDate><description><![CDATA[Hi Stephen:
With properly-implemented whole disk encryption under the right circumstances, it wouldn't be possible to boot to another OS and reset a local account's password.  Also, we have to worry about not just physical theft of portables, but also internal PCs and hackers who are try to leapfrog laterally from one box to another, in which case having a different local admin password on every computer is useful.
Cheers,
Jason]]></description><content:encoded><![CDATA[Hi Stephen:
With properly-implemented whole disk encryption under the right circumstances, it wouldn't be possible to boot to another OS and reset a local account's password.  Also, we have to worry about not just physical theft of portables, but also internal PCs and hackers who are try to leapfrog laterally from one box to another, in which case having a different local admin password on every computer is useful.
Cheers,
Jason]]></content:encoded></item><item><title>Comment on Reset Local Administrator Password Using A Different Random String On Each Computer And Recover The Passwords Securely by Jason Fossen</title><link>http://www.sans.org/blog/2013/08/01/reset-local-administrator-password-automatically-with-a-different-password-across-the-enterprise/comment-page-1/#comment-2268</link><dc:creator>Jason Fossen</dc:creator><pubDate>Mon, 09 Sep 2013 15:59:08 +0000</pubDate><description><![CDATA[Hi Stephen:
With properly-implemented whole disk encryption under the right circumstances, it wouldn't be possible to boot to another OS and reset a local account's password.  Also, we have to worry about not just physical theft of portables, but also internal PCs and hackers who are try to leapfrog laterally from one box to another, in which case having a different local admin password on every computer is useful.
Cheers,
Jason]]></description><content:encoded><![CDATA[Hi Stephen:
With properly-implemented whole disk encryption under the right circumstances, it wouldn't be possible to boot to another OS and reset a local account's password.  Also, we have to worry about not just physical theft of portables, but also internal PCs and hackers who are try to leapfrog laterally from one box to another, in which case having a different local admin password on every computer is useful.
Cheers,
Jason]]></content:encoded></item><item><title>Comment on Reset Local Administrator Password Using A Different Random String On Each Computer And Recover The Passwords Securely by Jason Fossen</title><link>http://www.sans.org/blog/2013/08/01/reset-local-administrator-password-automatically-with-a-different-password-across-the-enterprise/comment-page-1/#comment-2268</link><dc:creator>Jason Fossen</dc:creator><pubDate>Mon, 09 Sep 2013 15:59:08 +0000</pubDate><description><![CDATA[Hi Stephen:
With properly-implemented whole disk encryption under the right circumstances, it wouldn't be possible to boot to another OS and reset a local account's password.  Also, we have to worry about not just physical theft of portables, but also internal PCs and hackers who are try to leapfrog laterally from one box to another, in which case having a different local admin password on every computer is useful.
Cheers,
Jason]]></description><content:encoded><![CDATA[Hi Stephen:
With properly-implemented whole disk encryption under the right circumstances, it wouldn't be possible to boot to another OS and reset a local account's password.  Also, we have to worry about not just physical theft of portables, but also internal PCs and hackers who are try to leapfrog laterally from one box to another, in which case having a different local admin password on every computer is useful.
Cheers,
Jason]]></content:encoded></item><item><title>Comment on Reset Local Administrator Password Using A Different Random String On Each Computer And Recover The Passwords Securely by stephen</title><link>http://www.sans.org/blog/2013/08/01/reset-local-administrator-password-automatically-with-a-different-password-across-the-enterprise/comment-page-1/#comment-2263</link><dc:creator>stephen</dc:creator><pubDate>Mon, 09 Sep 2013 02:27:18 +0000</pubDate><description><![CDATA[As far as I know, no matter how strong the password is, you can break it in seconds with PCUnlocker Live CD.]]></description><content:encoded><![CDATA[As far as I know, no matter how strong the password is, you can break it in seconds with PCUnlocker Live CD.]]></content:encoded></item><item><title>Comment on Reset Local Administrator Password Using A Different Random String On Each Computer And Recover The Passwords Securely by stephen</title><link>http://www.sans.org/blog/2013/08/01/reset-local-administrator-password-automatically-with-a-different-password-across-the-enterprise/comment-page-1/#comment-2263</link><dc:creator>stephen</dc:creator><pubDate>Mon, 09 Sep 2013 02:27:18 +0000</pubDate><description><![CDATA[As far as I know, no matter how strong the password is, you can break it in seconds with PCUnlocker Live CD.]]></description><content:encoded><![CDATA[As far as I know, no matter how strong the password is, you can break it in seconds with PCUnlocker Live CD.]]></content:encoded></item></channel></rss