<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Announcing Burner Profiles</title>
	<atom:link href="http://blog.burningman.com/2013/01/news/announcing-burner-profiles/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.burningman.com/2013/01/news/announcing-burner-profiles/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=announcing-burner-profiles</link>
	<description></description>
	<lastBuildDate>Mon, 17 Jun 2013 18:57:02 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Sheri Davenport</title>
		<link>http://blog.burningman.com/2013/01/news/announcing-burner-profiles/comment-page-1/#comment-93456</link>
		<dc:creator>Sheri Davenport</dc:creator>
		<pubDate>Sun, 10 Feb 2013 16:52:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.burningman.com/?p=23965#comment-93456</guid>
		<description><![CDATA[I filled out my profile on Feb 7 to register but never got a confirming email. So last night I filled out another profile and used another email address...I didn&#039;t get a confirmation email for the profile either. Now I&#039;m panicked because I&#039;m afraid I&#039;m not pre-registered at all and won&#039;t be able to buy a ticket on Wednesday. Help! 
Sheri]]></description>
		<content:encoded><![CDATA[<p>I filled out my profile on Feb 7 to register but never got a confirming email. So last night I filled out another profile and used another email address&#8230;I didn&#8217;t get a confirmation email for the profile either. Now I&#8217;m panicked because I&#8217;m afraid I&#8217;m not pre-registered at all and won&#8217;t be able to buy a ticket on Wednesday. Help!<br />
Sheri
<p>
				<span id="reportcomment_results_div_93456"><a href="javascript:void(0);" onclick="reportComment_AddTextArea( 93456 );" title="Report this comment" rel="nofollow">Report this comment</a></span><br />
				<span id="reportcomment_comment_div_93456"></span>
			</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Diana</title>
		<link>http://blog.burningman.com/2013/01/news/announcing-burner-profiles/comment-page-1/#comment-93216</link>
		<dc:creator>Diana</dc:creator>
		<pubDate>Thu, 07 Feb 2013 21:35:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.burningman.com/?p=23965#comment-93216</guid>
		<description><![CDATA[Hey, just a quick question. I applied for a Low Income Ticket and was flipping crazy happy when I saw that I was accepted. Thank you guys for the opportunity. I just wanted to know if it is required of me to create a Burner Profile. I see that it&#039;s like registering for the next ticket sale, but I&#039;m not going to buy any more tickets! And I don&#039;t want to mess this up either! So, should I? Thanks.]]></description>
		<content:encoded><![CDATA[<p>Hey, just a quick question. I applied for a Low Income Ticket and was flipping crazy happy when I saw that I was accepted. Thank you guys for the opportunity. I just wanted to know if it is required of me to create a Burner Profile. I see that it&#8217;s like registering for the next ticket sale, but I&#8217;m not going to buy any more tickets! And I don&#8217;t want to mess this up either! So, should I? Thanks.
<p>
				<span id="reportcomment_results_div_93216"><a href="javascript:void(0);" onclick="reportComment_AddTextArea( 93216 );" title="Report this comment" rel="nofollow">Report this comment</a></span><br />
				<span id="reportcomment_comment_div_93216"></span>
			</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Celia</title>
		<link>http://blog.burningman.com/2013/01/news/announcing-burner-profiles/comment-page-1/#comment-92759</link>
		<dc:creator>Celia</dc:creator>
		<pubDate>Sat, 02 Feb 2013 20:58:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.burningman.com/?p=23965#comment-92759</guid>
		<description><![CDATA[Trying to register my profile, but received message thru Firefox after trying to log back in from email I received that site not secure.. ??  Okay to continue or not.  Don&#039;t want to mess this up.]]></description>
		<content:encoded><![CDATA[<p>Trying to register my profile, but received message thru Firefox after trying to log back in from email I received that site not secure.. ??  Okay to continue or not.  Don&#8217;t want to mess this up.
<p>
				<span id="reportcomment_results_div_92759"><a href="javascript:void(0);" onclick="reportComment_AddTextArea( 92759 );" title="Report this comment" rel="nofollow">Report this comment</a></span><br />
				<span id="reportcomment_comment_div_92759"></span>
			</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven</title>
		<link>http://blog.burningman.com/2013/01/news/announcing-burner-profiles/comment-page-1/#comment-92506</link>
		<dc:creator>Steven</dc:creator>
		<pubDate>Thu, 31 Jan 2013 22:33:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.burningman.com/?p=23965#comment-92506</guid>
		<description><![CDATA[Nevermind! I found it. It&#039;s at profiles.burningman.com in case anyone else needs it.]]></description>
		<content:encoded><![CDATA[<p>Nevermind! I found it. It&#8217;s at profiles.burningman.com in case anyone else needs it.
<p>
				<span id="reportcomment_results_div_92506"><a href="javascript:void(0);" onclick="reportComment_AddTextArea( 92506 );" title="Report this comment" rel="nofollow">Report this comment</a></span><br />
				<span id="reportcomment_comment_div_92506"></span>
			</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven</title>
		<link>http://blog.burningman.com/2013/01/news/announcing-burner-profiles/comment-page-1/#comment-92452</link>
		<dc:creator>Steven</dc:creator>
		<pubDate>Thu, 31 Jan 2013 16:07:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.burningman.com/?p=23965#comment-92452</guid>
		<description><![CDATA[Soooo, where&#039;s the link to the page that lets me create a profile? I can&#039;t seem to find it in this article, nor is it on tickets.burningman.com (I did a search on that page and the word &quot;profile&quot; appears nowhere.)

Am I going crazy?]]></description>
		<content:encoded><![CDATA[<p>Soooo, where&#8217;s the link to the page that lets me create a profile? I can&#8217;t seem to find it in this article, nor is it on tickets.burningman.com (I did a search on that page and the word &#8220;profile&#8221; appears nowhere.)</p>
<p>Am I going crazy?
<p>
				<span id="reportcomment_results_div_92452"><a href="javascript:void(0);" onclick="reportComment_AddTextArea( 92452 );" title="Report this comment" rel="nofollow">Report this comment</a></span><br />
				<span id="reportcomment_comment_div_92452"></span>
			</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ghost</title>
		<link>http://blog.burningman.com/2013/01/news/announcing-burner-profiles/comment-page-1/#comment-92058</link>
		<dc:creator>Ghost</dc:creator>
		<pubDate>Sun, 27 Jan 2013 20:22:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.burningman.com/?p=23965#comment-92058</guid>
		<description><![CDATA[Well, I got registered, even got the confirmation letter. HOWEVER, everytime I use Exporer 9 I get a certificate warning, if I use Chrome no problem goes straight through. So if the Borg is monitoring, you might consider fixing it as I have a bad feeling that your security may have been screwed with, especially if you are going to require Explorer as the browser du jour on ticket day.
So, what are we to expect from the Borg, continued sloppiness which is an upgrade from last year, maybe we should be happy offer up some ding dongs in sacrafice to the &#039;gods&#039; and kick back.]]></description>
		<content:encoded><![CDATA[<p>Well, I got registered, even got the confirmation letter. HOWEVER, everytime I use Exporer 9 I get a certificate warning, if I use Chrome no problem goes straight through. So if the Borg is monitoring, you might consider fixing it as I have a bad feeling that your security may have been screwed with, especially if you are going to require Explorer as the browser du jour on ticket day.<br />
So, what are we to expect from the Borg, continued sloppiness which is an upgrade from last year, maybe we should be happy offer up some ding dongs in sacrafice to the &#8216;gods&#8217; and kick back.
<p>
				<span id="reportcomment_results_div_92058"><a href="javascript:void(0);" onclick="reportComment_AddTextArea( 92058 );" title="Report this comment" rel="nofollow">Report this comment</a></span><br />
				<span id="reportcomment_comment_div_92058"></span>
			</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marcus</title>
		<link>http://blog.burningman.com/2013/01/news/announcing-burner-profiles/comment-page-1/#comment-91775</link>
		<dc:creator>Marcus</dc:creator>
		<pubDate>Thu, 24 Jan 2013 21:19:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.burningman.com/?p=23965#comment-91775</guid>
		<description><![CDATA[I&#039;m very confused on how to make a profile for the registrations.. I see some others comments about that their profiles have been created, can someone help me or give me some info on creating a profile.. Thank you. My email is marcusmonstur@gmail.com if anyone is willing to send me info...]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m very confused on how to make a profile for the registrations.. I see some others comments about that their profiles have been created, can someone help me or give me some info on creating a profile.. Thank you. My email is <span class="emailShroud_protectedAddress" id="sto_emailShroud0" >marcusmonstur<span class="emailShroud_transformedAddress"> here: marcusmonstur (at) gmail.com</span></span> if anyone is willing to send me info&#8230;
<p>
				<span id="reportcomment_results_div_91775"><a href="javascript:void(0);" onclick="reportComment_AddTextArea( 91775 );" title="Report this comment" rel="nofollow">Report this comment</a></span><br />
				<span id="reportcomment_comment_div_91775"></span>
			</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spock the Cow</title>
		<link>http://blog.burningman.com/2013/01/news/announcing-burner-profiles/comment-page-1/#comment-91531</link>
		<dc:creator>Spock the Cow</dc:creator>
		<pubDate>Tue, 22 Jan 2013 21:17:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.burningman.com/?p=23965#comment-91531</guid>
		<description><![CDATA[I agree with Tripod about the security issue here.  

The main registration page ( http://profiles.burningman.com/register/ ) is not encrypted.  So you send your email address, real name, and your chosen user name in plaintext.  The system then replies to that email address with a password,  but they recommend you change your password after you log on.  You then go to a login page that is SSL encrypted ( https://profiles.burningman.com/wp-login.php ).  After you log in, pages are no longer encrypted.  The &#039;change your password&#039; section is on an unencrypted page.  Those fields are sent as standard HTTP Post.  

So if someone is intercepting my traffic (on any public wifi, for example), they will first get my email address, user name and real name in unencrypted packets.  Then if I&#039;m using an email client that doesn&#039;t continue SSL after the login page, they&#039;ll get my password in the response email.  But even if I am using secure email, if I change my password as directed in the email then the new password will be intercepted.  

I verified by capturing my own packets with a sniffer that the email address, user name, real name and new password are all sent plaintext.  

Given that the Burner Profile system is intended to aggregate personal information and also somehow interface with the ticketing system, this is at least a privacy concern and possibly also a vector for ticket or credit card theft.]]></description>
		<content:encoded><![CDATA[<p>I agree with Tripod about the security issue here.  </p>
<p>The main registration page ( <a href="http://profiles.burningman.com/register/" rel="nofollow">http://profiles.burningman.com/register/</a> ) is not encrypted.  So you send your email address, real name, and your chosen user name in plaintext.  The system then replies to that email address with a password,  but they recommend you change your password after you log on.  You then go to a login page that is SSL encrypted ( <a href="https://profiles.burningman.com/wp-login.php" rel="nofollow">https://profiles.burningman.com/wp-login.php</a> ).  After you log in, pages are no longer encrypted.  The &#8216;change your password&#8217; section is on an unencrypted page.  Those fields are sent as standard HTTP Post.  </p>
<p>So if someone is intercepting my traffic (on any public wifi, for example), they will first get my email address, user name and real name in unencrypted packets.  Then if I&#8217;m using an email client that doesn&#8217;t continue SSL after the login page, they&#8217;ll get my password in the response email.  But even if I am using secure email, if I change my password as directed in the email then the new password will be intercepted.  </p>
<p>I verified by capturing my own packets with a sniffer that the email address, user name, real name and new password are all sent plaintext.  </p>
<p>Given that the Burner Profile system is intended to aggregate personal information and also somehow interface with the ticketing system, this is at least a privacy concern and possibly also a vector for ticket or credit card theft.
<p>
				<span id="reportcomment_results_div_91531"><a href="javascript:void(0);" onclick="reportComment_AddTextArea( 91531 );" title="Report this comment" rel="nofollow">Report this comment</a></span><br />
				<span id="reportcomment_comment_div_91531"></span>
			</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: simon of the playa</title>
		<link>http://blog.burningman.com/2013/01/news/announcing-burner-profiles/comment-page-1/#comment-91297</link>
		<dc:creator>simon of the playa</dc:creator>
		<pubDate>Mon, 21 Jan 2013 00:12:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.burningman.com/?p=23965#comment-91297</guid>
		<description><![CDATA[i&#039;d like to report that early beta testing with the embedded neural probe is going great.

one small glitch involving some impulsive face-painting ala Paul Addis (RIP) at the local Macy&#039;s cosmetic counter and subsequent arrest for lighting the hosiery department on fire, but besides that, i am very happy with the new tracking system, designed to protect us, and find us on the C-Grid, should we really freak out on mushrooms one night and spend 6 hours in the porta potty.

all in all, i like it.]]></description>
		<content:encoded><![CDATA[<p>i&#8217;d like to report that early beta testing with the embedded neural probe is going great.</p>
<p>one small glitch involving some impulsive face-painting ala Paul Addis (RIP) at the local Macy&#8217;s cosmetic counter and subsequent arrest for lighting the hosiery department on fire, but besides that, i am very happy with the new tracking system, designed to protect us, and find us on the C-Grid, should we really freak out on mushrooms one night and spend 6 hours in the porta potty.</p>
<p>all in all, i like it.
<p>
				<span id="reportcomment_results_div_91297"><a href="javascript:void(0);" onclick="reportComment_AddTextArea( 91297 );" title="Report this comment" rel="nofollow">Report this comment</a></span><br />
				<span id="reportcomment_comment_div_91297"></span>
			</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ralph Dosser</title>
		<link>http://blog.burningman.com/2013/01/news/announcing-burner-profiles/comment-page-1/#comment-91240</link>
		<dc:creator>Ralph Dosser</dc:creator>
		<pubDate>Sun, 20 Jan 2013 15:21:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.burningman.com/?p=23965#comment-91240</guid>
		<description><![CDATA[I signed up, was told that I would be sent a confirmation email....that was two days ago. Not in my spam filter, nothing. A friend who tried to register reported the process stalling out a little later in the process.

I used the &quot;contact us&quot; form to report the problem, and haven&#039;t heard back. So this thing that I&#039;m required to do to get my ticket doesn&#039;t appear to work, and there&#039;s apparently nothing I can do about it?]]></description>
		<content:encoded><![CDATA[<p>I signed up, was told that I would be sent a confirmation email&#8230;.that was two days ago. Not in my spam filter, nothing. A friend who tried to register reported the process stalling out a little later in the process.</p>
<p>I used the &#8220;contact us&#8221; form to report the problem, and haven&#8217;t heard back. So this thing that I&#8217;m required to do to get my ticket doesn&#8217;t appear to work, and there&#8217;s apparently nothing I can do about it?
<p>
				<span id="reportcomment_results_div_91240"><a href="javascript:void(0);" onclick="reportComment_AddTextArea( 91240 );" title="Report this comment" rel="nofollow">Report this comment</a></span><br />
				<span id="reportcomment_comment_div_91240"></span>
			</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using apc
Database Caching 1/35 queries in 0.010 seconds using apc
Object Caching 628/636 objects using apc

 Served from: blog.burningman.com @ 2013-06-18 00:32:04 by W3 Total Cache -->