<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments for Alf’s blog about geek stuffs</title>
	<link>http://blog.alfbox.net</link>
	<description>News about Wisss and other free softwares</description>
	<pubDate>Thu, 11 Mar 2010 22:34:38 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>Comment on Wrapping text for Zend Pdf by greg</title>
		<link>http://blog.alfbox.net/index.php/2008/06/04/wrapping-text-for-zend-pdf/#comment-328</link>
		<dc:creator>greg</dc:creator>
		<pubDate>Tue, 31 Mar 2009 13:12:14 +0000</pubDate>
		<guid>http://blog.alfbox.net/index.php/2008/06/04/wrapping-text-for-zend-pdf/#comment-328</guid>
		<description>You have an error in your widthForStringUsingFontSize function.

$glyphs = $font-&#62;glyphNumbersForCharacters($characters);

should be:

$glyphs = $font-&#62;cmap-&#62;glyphNumbersForCharacters($characters);

based on the referenced link you provided.</description>
		<content:encoded><![CDATA[<p>You have an error in your widthForStringUsingFontSize function.</p>
<p>$glyphs = $font-&gt;glyphNumbersForCharacters($characters);</p>
<p>should be:</p>
<p>$glyphs = $font-&gt;cmap-&gt;glyphNumbersForCharacters($characters);</p>
<p>based on the referenced link you provided.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Demo of Wisss 0.2.0 by alf</title>
		<link>http://blog.alfbox.net/index.php/2008/01/28/demo-of-wisss-020/#comment-122</link>
		<dc:creator>alf</dc:creator>
		<pubDate>Mon, 16 Jun 2008 08:10:06 +0000</pubDate>
		<guid>http://blog.alfbox.net/index.php/2008/01/28/demo-of-wisss-020/#comment-122</guid>
		<description>Bonjour Christophe,

je me rends compte que je n'ai jamais taggé la version 0.2 sur le svn :-/

Je suis actuellement en route pour la 0.3 et beaucoup de choses ont changé au niveau du metamodèle. Je t'invite à télécharger directement à partir du SVN, surtout que j'ai pas mal bossé dessus ce week end.

Je devrais sortir la 0.3 d'ici peu. Je commence à approcher des concepts de la 1.0. N'hésite pas à venir me poser des questions sur #wisss sur freenode.</description>
		<content:encoded><![CDATA[<p>Bonjour Christophe,</p>
<p>je me rends compte que je n&#8217;ai jamais taggé la version 0.2 sur le svn :-/</p>
<p>Je suis actuellement en route pour la 0.3 et beaucoup de choses ont changé au niveau du metamodèle. Je t&#8217;invite à télécharger directement à partir du SVN, surtout que j&#8217;ai pas mal bossé dessus ce week end.</p>
<p>Je devrais sortir la 0.3 d&#8217;ici peu. Je commence à approcher des concepts de la 1.0. N&#8217;hésite pas à venir me poser des questions sur #wisss sur freenode.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Demo of Wisss 0.2.0 by Christophe Bresso</title>
		<link>http://blog.alfbox.net/index.php/2008/01/28/demo-of-wisss-020/#comment-121</link>
		<dc:creator>Christophe Bresso</dc:creator>
		<pubDate>Sun, 15 Jun 2008 22:35:21 +0000</pubDate>
		<guid>http://blog.alfbox.net/index.php/2008/01/28/demo-of-wisss-020/#comment-121</guid>
		<description>Bonsoir,
J'ai vu votre démo impressionnant!
Par contre sur le site d'accéléo, je n'ai pu installer que la version 0.1. Où puis-je trouver la 0.2?
Merci</description>
		<content:encoded><![CDATA[<p>Bonsoir,<br />
J&#8217;ai vu votre démo impressionnant!<br />
Par contre sur le site d&#8217;accéléo, je n&#8217;ai pu installer que la version 0.1. Où puis-je trouver la 0.2?<br />
Merci</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Zend Pdf and PNG transparency issue by alf</title>
		<link>http://blog.alfbox.net/index.php/2008/06/05/zend-pdf-and-png-transparency-issue/#comment-119</link>
		<dc:creator>alf</dc:creator>
		<pubDate>Tue, 10 Jun 2008 02:06:16 +0000</pubDate>
		<guid>http://blog.alfbox.net/index.php/2008/06/05/zend-pdf-and-png-transparency-issue/#comment-119</guid>
		<description>Sorry, it was a hard day with 3h sleeping ... of course you can generate image by yourself ;-)</description>
		<content:encoded><![CDATA[<p>Sorry, it was a hard day with 3h sleeping &#8230; of course you can generate image by yourself <img src='http://blog.alfbox.net/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Zend Pdf and PNG transparency issue by Alexander Veremyev</title>
		<link>http://blog.alfbox.net/index.php/2008/06/05/zend-pdf-and-png-transparency-issue/#comment-118</link>
		<dc:creator>Alexander Veremyev</dc:creator>
		<pubDate>Mon, 09 Jun 2008 18:07:22 +0000</pubDate>
		<guid>http://blog.alfbox.net/index.php/2008/06/05/zend-pdf-and-png-transparency-issue/#comment-118</guid>
		<description>Aha, I'll try to generate image by myself and test it.</description>
		<content:encoded><![CDATA[<p>Aha, I&#8217;ll try to generate image by myself and test it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Zend Pdf and PNG transparency issue by alf</title>
		<link>http://blog.alfbox.net/index.php/2008/06/05/zend-pdf-and-png-transparency-issue/#comment-117</link>
		<dc:creator>alf</dc:creator>
		<pubDate>Mon, 09 Jun 2008 14:15:55 +0000</pubDate>
		<guid>http://blog.alfbox.net/index.php/2008/06/05/zend-pdf-and-png-transparency-issue/#comment-117</guid>
		<description>I can't, it's a copyrighted image of the customer but I think any A4 image with a lot of transparency may cause the problem. I'll test during the week with an other (home made) image to check.</description>
		<content:encoded><![CDATA[<p>I can&#8217;t, it&#8217;s a copyrighted image of the customer but I think any A4 image with a lot of transparency may cause the problem. I&#8217;ll test during the week with an other (home made) image to check.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Zend Pdf and PNG transparency issue by Alexander Veremyev</title>
		<link>http://blog.alfbox.net/index.php/2008/06/05/zend-pdf-and-png-transparency-issue/#comment-115</link>
		<dc:creator>Alexander Veremyev</dc:creator>
		<pubDate>Fri, 06 Jun 2008 11:58:16 +0000</pubDate>
		<guid>http://blog.alfbox.net/index.php/2008/06/05/zend-pdf-and-png-transparency-issue/#comment-115</guid>
		<description>Great thanks for the comment and registered issue!

Could I also ask you to attache the image to the issue for testing? :)</description>
		<content:encoded><![CDATA[<p>Great thanks for the comment and registered issue!</p>
<p>Could I also ask you to attache the image to the issue for testing? <img src='http://blog.alfbox.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Secure authentication without SSL (part2) by pepe</title>
		<link>http://blog.alfbox.net/index.php/2008/02/21/secure-authentication-without-ssl-part2/#comment-99</link>
		<dc:creator>pepe</dc:creator>
		<pubDate>Thu, 20 Mar 2008 21:39:17 +0000</pubDate>
		<guid>http://blog.alfbox.net/index.php/2008/02/21/secure-authentication-without-ssl-part2/#comment-99</guid>
		<description>State of the art pw authentication should provide *mutual* authentication. iIeally, it will also protect against offline bruteforce attacks, as passwords tend to be rather short. An example for such a protocol is SRP.

See srp.stanford.edu. The SRP authentication also produces a strong common secret that you can use to encrypt your session or at least authenticate it, to prevent hijacking/replay

There are some efforts to integrate SRP into SSL, see RFC5054. This should also help implementing SRP somewhere else.


Your last sentence on the other hand seems to imply that you want users to authenticate via browser. use htaccess in digest mode(not basic). Its also ch-resp. but much more standardized.

have fun</description>
		<content:encoded><![CDATA[<p>State of the art pw authentication should provide *mutual* authentication. iIeally, it will also protect against offline bruteforce attacks, as passwords tend to be rather short. An example for such a protocol is SRP.</p>
<p>See srp.stanford.edu. The SRP authentication also produces a strong common secret that you can use to encrypt your session or at least authenticate it, to prevent hijacking/replay</p>
<p>There are some efforts to integrate SRP into SSL, see RFC5054. This should also help implementing SRP somewhere else.</p>
<p>Your last sentence on the other hand seems to imply that you want users to authenticate via browser. use htaccess in digest mode(not basic). Its also ch-resp. but much more standardized.</p>
<p>have fun</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Secure authentication without SSL by Alf</title>
		<link>http://blog.alfbox.net/index.php/2008/02/18/secure-authentication-without-ssl/#comment-96</link>
		<dc:creator>Alf</dc:creator>
		<pubDate>Thu, 21 Feb 2008 09:07:22 +0000</pubDate>
		<guid>http://blog.alfbox.net/index.php/2008/02/18/secure-authentication-without-ssl/#comment-96</guid>
		<description>Be careful, I'm writing a second post since we discovered a miss in this approach. Your proposition to let the javascript set up the type of authentication (plain text or hash) is a good point, I will add it later.</description>
		<content:encoded><![CDATA[<p>Be careful, I&#8217;m writing a second post since we discovered a miss in this approach. Your proposition to let the javascript set up the type of authentication (plain text or hash) is a good point, I will add it later.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Secure authentication without SSL by Bram</title>
		<link>http://blog.alfbox.net/index.php/2008/02/18/secure-authentication-without-ssl/#comment-95</link>
		<dc:creator>Bram</dc:creator>
		<pubDate>Wed, 20 Feb 2008 20:35:33 +0000</pubDate>
		<guid>http://blog.alfbox.net/index.php/2008/02/18/secure-authentication-without-ssl/#comment-95</guid>
		<description>I've been considering doing something similar for a project I'm working on. Only, if I were you, I'd include something like a hidden profile field to indicate whether you're POSTing the password in cleartext or in the hashed format. That way, users without javascript can still log in, albeit less secure. Simply use a simple javascript to change the value of the hidden field for users who do have JS enabled.

Otherwise, I like it, and I'll definitely borrow an idea or two from your setup for my project. Thanks!</description>
		<content:encoded><![CDATA[<p>I&#8217;ve been considering doing something similar for a project I&#8217;m working on. Only, if I were you, I&#8217;d include something like a hidden profile field to indicate whether you&#8217;re POSTing the password in cleartext or in the hashed format. That way, users without javascript can still log in, albeit less secure. Simply use a simple javascript to change the value of the hidden field for users who do have JS enabled.</p>
<p>Otherwise, I like it, and I&#8217;ll definitely borrow an idea or two from your setup for my project. Thanks!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
