<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Texas Bank Sues Customer Hit by $800,000 Cyber Heist</title>
	<atom:link href="http://krebsonsecurity.com/2010/01/texas-bank-sues-customer-hit-by-800000-cyber-heist/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/01/texas-bank-sues-customer-hit-by-800000-cyber-heist/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 23 May 2012 01:40:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: James R. ("Jim") Woodhill</title>
		<link>http://krebsonsecurity.com/2010/01/texas-bank-sues-customer-hit-by-800000-cyber-heist/comment-page-2/#comment-12555</link>
		<dc:creator>James R. ("Jim") Woodhill</dc:creator>
		<pubDate>Tue, 16 Nov 2010 21:25:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=756#comment-12555</guid>
		<description>&gt; That’s all we need. More laws restating what 
     &gt; security pro’s see as obvious

Check out Brian&#039;s reporting on S.3898.  There is not a word on *how* the banks should stop this new and fast-growing crime.  (Note that this is not the bill I would write.  But it&#039;s a great example of what happens on the Hill when an industry fails to get out in front of an important problem with a sensible proposal.)

     &gt; Holding the customer accountable for their 
     &gt; in-house security is as valid a point as holding 
     &gt; the bank accountable for their’s 

My view is whom to hold accountable can only legitimately be decided by the elected representatives of the people.  The banks *say* they disagree.  Note, however, that at the FDIC Symposium on Combating Commercial Payments Fraud on May 11, 2010 in Washington, D.C., the banking industry representative who was most vocal about the righteousness of the banks&#039; imposing commercial-account online banking funds transfer fraud losses on randomly-unlucky small- and medium-sized enterprises admitted that if the name of the organization that was hit by ZeuS happened to be &quot;Barney Frank for Congress Campaign Fund&quot;, he would make good on *that* loss regardless of its size or who was &quot;really&quot; responsible.

     &gt; The real issue I am concerned about is the 
     &gt; increased pressure by banks to go completely 
     &gt; on-line or face fee increases while at the same 
     &gt; time watching these types of crimes proliferate.

Be Very, Very Afraid, then.  Check out:

http://www.bankerstuff.com/BankerstuffWebinars/November16WebinarJavelinOnlineBanking/tabid/579/Default.aspx

Javelin Strategy &amp; Research predicts that there are still almost $7 *billion* in banking costs that can be wrung out of the system via moving transactions into cyberspace.  Given the revenue losses Sen. Durbin has inflicted on the financial services industry in the Dodd-Frank Act, expect redoubled efforts of the kind you fear.  I would just like to see the banks disclose the risks their commercial customers are accepting by moving their banking online.</description>
		<content:encoded><![CDATA[<p>&gt; That’s all we need. More laws restating what<br />
     &gt; security pro’s see as obvious</p>
<p>Check out Brian&#8217;s reporting on S.3898.  There is not a word on *how* the banks should stop this new and fast-growing crime.  (Note that this is not the bill I would write.  But it&#8217;s a great example of what happens on the Hill when an industry fails to get out in front of an important problem with a sensible proposal.)</p>
<p>     &gt; Holding the customer accountable for their<br />
     &gt; in-house security is as valid a point as holding<br />
     &gt; the bank accountable for their’s </p>
<p>My view is whom to hold accountable can only legitimately be decided by the elected representatives of the people.  The banks *say* they disagree.  Note, however, that at the FDIC Symposium on Combating Commercial Payments Fraud on May 11, 2010 in Washington, D.C., the banking industry representative who was most vocal about the righteousness of the banks&#8217; imposing commercial-account online banking funds transfer fraud losses on randomly-unlucky small- and medium-sized enterprises admitted that if the name of the organization that was hit by ZeuS happened to be &#8220;Barney Frank for Congress Campaign Fund&#8221;, he would make good on *that* loss regardless of its size or who was &#8220;really&#8221; responsible.</p>
<p>     &gt; The real issue I am concerned about is the<br />
     &gt; increased pressure by banks to go completely<br />
     &gt; on-line or face fee increases while at the same<br />
     &gt; time watching these types of crimes proliferate.</p>
<p>Be Very, Very Afraid, then.  Check out:</p>
<p><a href="http://www.bankerstuff.com/BankerstuffWebinars/November16WebinarJavelinOnlineBanking/tabid/579/Default.aspx" rel="nofollow">http://www.bankerstuff.com/BankerstuffWebinars/November16WebinarJavelinOnlineBanking/tabid/579/Default.aspx</a></p>
<p>Javelin Strategy &amp; Research predicts that there are still almost $7 *billion* in banking costs that can be wrung out of the system via moving transactions into cyberspace.  Given the revenue losses Sen. Durbin has inflicted on the financial services industry in the Dodd-Frank Act, expect redoubled efforts of the kind you fear.  I would just like to see the banks disclose the risks their commercial customers are accepting by moving their banking online.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-12555" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('12555', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-12555-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-12555" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('12555', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-12555-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Bufford</title>
		<link>http://krebsonsecurity.com/2010/01/texas-bank-sues-customer-hit-by-800000-cyber-heist/comment-page-2/#comment-12511</link>
		<dc:creator>Bufford</dc:creator>
		<pubDate>Mon, 15 Nov 2010 18:34:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=756#comment-12511</guid>
		<description>Re: Authentify&#039;s Recommendation for More Legislation

That&#039;s all we need. More laws restating what security pro&#039;s see as obvious. In the end you get a detailed list (limited) of methods that will no longer be used by attackers and a plethora of unlisted techiques that won&#039;t be prosecutable.

Holding the customer accountable for their in-house security is as valid a point as holding the bank accountable for their&#039;s.

The real issue I am concerned about is the increased pressure by banks to go completely on-line or face fee increases while at the same time watching these types of crimes proliferate.</description>
		<content:encoded><![CDATA[<p>Re: Authentify&#8217;s Recommendation for More Legislation</p>
<p>That&#8217;s all we need. More laws restating what security pro&#8217;s see as obvious. In the end you get a detailed list (limited) of methods that will no longer be used by attackers and a plethora of unlisted techiques that won&#8217;t be prosecutable.</p>
<p>Holding the customer accountable for their in-house security is as valid a point as holding the bank accountable for their&#8217;s.</p>
<p>The real issue I am concerned about is the increased pressure by banks to go completely on-line or face fee increases while at the same time watching these types of crimes proliferate.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-12511" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('12511', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-12511-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-12511" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('12511', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-12511-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: nat</title>
		<link>http://krebsonsecurity.com/2010/01/texas-bank-sues-customer-hit-by-800000-cyber-heist/comment-page-1/#comment-7382</link>
		<dc:creator>nat</dc:creator>
		<pubDate>Thu, 08 Jul 2010 04:51:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=756#comment-7382</guid>
		<description>1st line of defense:  Don&#039;t bank online.  But if you HAVE TO bank online, then.....

2nd line of defense:  Use a dedicated machine with a Linux O.S. (see also http://www.distrowatch.com &amp;/or http://www.linux.org/dist/list.html for comprehensive listings).  Can&#039;t use a dedicated machine?  Then.....

3rd line of defense:  Boot the machine off of a Linux disk and save your data to a USB flash drive.  And DO NOT store your login IDs and passwords electronically; but DO store them in a physically secure place (e.g., a safe).</description>
		<content:encoded><![CDATA[<p>1st line of defense:  Don&#8217;t bank online.  But if you HAVE TO bank online, then&#8230;..</p>
<p>2nd line of defense:  Use a dedicated machine with a Linux O.S. (see also <a href="http://www.distrowatch.com" rel="nofollow">http://www.distrowatch.com</a> &amp;/or <a href="http://www.linux.org/dist/list.html" rel="nofollow">http://www.linux.org/dist/list.html</a> for comprehensive listings).  Can&#8217;t use a dedicated machine?  Then&#8230;..</p>
<p>3rd line of defense:  Boot the machine off of a Linux disk and save your data to a USB flash drive.  And DO NOT store your login IDs and passwords electronically; but DO store them in a physically secure place (e.g., a safe).</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7382" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7382', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7382-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7382" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7382', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7382-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2010/01/texas-bank-sues-customer-hit-by-800000-cyber-heist/comment-page-2/#comment-7300</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Thu, 01 Jul 2010 19:17:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=756#comment-7300</guid>
		<description>Excellent link Benjamin! Seems like a settlement is already in place. 

Our congressmen need to look at this, and not only change the liability laws, but help the banks with their security concerns. After all we are supposedly in a &quot;cyber-war&quot; with enemies already. It only makes sense for the government to help the little banks out on the infrastructure and costs on this new security,. if they mandate the requirements.

Consumer&#039;s Union has more or less joined the fray, with political action to improve credit card practices and fraud protection. CU is a BIG lobby, I didn&#039;t hesitate to join, and we now stand together to put pressure on congress and the banking industry as a whole!</description>
		<content:encoded><![CDATA[<p>Excellent link Benjamin! Seems like a settlement is already in place. </p>
<p>Our congressmen need to look at this, and not only change the liability laws, but help the banks with their security concerns. After all we are supposedly in a &#8220;cyber-war&#8221; with enemies already. It only makes sense for the government to help the little banks out on the infrastructure and costs on this new security,. if they mandate the requirements.</p>
<p>Consumer&#8217;s Union has more or less joined the fray, with political action to improve credit card practices and fraud protection. CU is a BIG lobby, I didn&#8217;t hesitate to join, and we now stand together to put pressure on congress and the banking industry as a whole!</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7300" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7300', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7300-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7300" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7300', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7300-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2010/01/texas-bank-sues-customer-hit-by-800000-cyber-heist/comment-page-2/#comment-7299</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Thu, 01 Jul 2010 18:56:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=756#comment-7299</guid>
		<description>@Dave:

You list is part of the picture - I might add that few seem to be aware that Microsoft has a free utility called &quot;steady state&quot; that locks the hard drive to ANY changes in files. Ordinary files would have to be stored on another drive or partition. I&#039;m not sure which versions of Windows that it is available. If not available for your version, maybe a look at Faronics would be in order.

You would still want AV and AS solutions in place, in case the present session were somehow compromised. This would entail unlocking the drive at least two times a day, to update the operating system and/or AV/AS utilities. You would not want to do any unnecessary surfing during these updates; and immediately relock the drive afterward.

Some say a Puppy Linux Live CD would be better; your mileage may vary.</description>
		<content:encoded><![CDATA[<p>@Dave:</p>
<p>You list is part of the picture &#8211; I might add that few seem to be aware that Microsoft has a free utility called &#8220;steady state&#8221; that locks the hard drive to ANY changes in files. Ordinary files would have to be stored on another drive or partition. I&#8217;m not sure which versions of Windows that it is available. If not available for your version, maybe a look at Faronics would be in order.</p>
<p>You would still want AV and AS solutions in place, in case the present session were somehow compromised. This would entail unlocking the drive at least two times a day, to update the operating system and/or AV/AS utilities. You would not want to do any unnecessary surfing during these updates; and immediately relock the drive afterward.</p>
<p>Some say a Puppy Linux Live CD would be better; your mileage may vary.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7299" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7299', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7299-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7299" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7299', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7299-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2010/01/texas-bank-sues-customer-hit-by-800000-cyber-heist/comment-page-2/#comment-7298</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Thu, 01 Jul 2010 18:42:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=756#comment-7298</guid>
		<description>That&#039;s funny! I had always read SMS is one of the easiest forms of communication to intercept and manipulate. Maybe you country has a different SMS form of service than the rest of the world?

http://www.zdnet.com.au/sms-two-factor-authentication-dead-in-3-years-nab-339284387.htm</description>
		<content:encoded><![CDATA[<p>That&#8217;s funny! I had always read SMS is one of the easiest forms of communication to intercept and manipulate. Maybe you country has a different SMS form of service than the rest of the world?</p>
<p><a href="http://www.zdnet.com.au/sms-two-factor-authentication-dead-in-3-years-nab-339284387.htm" rel="nofollow">http://www.zdnet.com.au/sms-two-factor-authentication-dead-in-3-years-nab-339284387.htm</a></p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7298" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7298', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7298-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7298" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7298', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7298-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2010/01/texas-bank-sues-customer-hit-by-800000-cyber-heist/comment-page-1/#comment-7297</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Thu, 01 Jul 2010 18:02:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=756#comment-7297</guid>
		<description>Although I agree with what you are pointing out here; it does seem ridiculous to pay lawyers $200,000 to initiate and follow through to a lawsuit, when simply paying the victim the same money would have been settled out of court instantly!

I realize the bank probably doesn&#039;t want precedent set  here also, but it is still ridiculous.</description>
		<content:encoded><![CDATA[<p>Although I agree with what you are pointing out here; it does seem ridiculous to pay lawyers $200,000 to initiate and follow through to a lawsuit, when simply paying the victim the same money would have been settled out of court instantly!</p>
<p>I realize the bank probably doesn&#8217;t want precedent set  here also, but it is still ridiculous.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7297" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7297', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7297-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7297" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7297', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7297-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Les</title>
		<link>http://krebsonsecurity.com/2010/01/texas-bank-sues-customer-hit-by-800000-cyber-heist/comment-page-2/#comment-6583</link>
		<dc:creator>Les</dc:creator>
		<pubDate>Mon, 07 Jun 2010 18:54:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=756#comment-6583</guid>
		<description>Most bank staff cannot comprehend network security. Attempts at enlightening them often proves unfruitful. It often takes auditors to compel banks into action. I still know of banks that won&#039;t use Multi-factor authentication. I know that&#039;s not comprehensive but it&#039;s better than nothing at all. (Why position yourself to be low hanging fruit?)

The problem with Debit cards is that once you provide  a PIN to a merchant, you are entrusting the key to unlock your bank account with the merchant&#039;s security. And most merchants are clueless when it comes to anything close to Payment Card Industry security.  As an example: in 2007 in Southern California, it was speculated that Office Depot Databases were compromised. Hackers harvested Debit card numbers and corresponding PINs. Wamu, BofA, and Wells Fargo reissued 250,000 debit cards in response. The actual breach was never positively identified. 

Everytime you use a Debit card and provide your PIN for a retail transaction, you&#039;ve just entrusted it to the merchant&#039;s network security.  

I would suspect that using Debit cards with various retailers also increases your chances of encountering Card Skimmer too. Yet banks issue Debit cards to customers by default. Bank staff doesn&#039;t even know how to issue a simple ATM Card anymore. 

Since electronic deposit is quickly becoming the industry standard practice, the business model needs to change because the bad guys are adopting more quickly than the financial institutions and merchants. The &quot;It&#039;s too complex&quot; or &quot;It&#039;s too expensive&quot; is no longer an acceptable excuse.</description>
		<content:encoded><![CDATA[<p>Most bank staff cannot comprehend network security. Attempts at enlightening them often proves unfruitful. It often takes auditors to compel banks into action. I still know of banks that won&#8217;t use Multi-factor authentication. I know that&#8217;s not comprehensive but it&#8217;s better than nothing at all. (Why position yourself to be low hanging fruit?)</p>
<p>The problem with Debit cards is that once you provide  a PIN to a merchant, you are entrusting the key to unlock your bank account with the merchant&#8217;s security. And most merchants are clueless when it comes to anything close to Payment Card Industry security.  As an example: in 2007 in Southern California, it was speculated that Office Depot Databases were compromised. Hackers harvested Debit card numbers and corresponding PINs. Wamu, BofA, and Wells Fargo reissued 250,000 debit cards in response. The actual breach was never positively identified. </p>
<p>Everytime you use a Debit card and provide your PIN for a retail transaction, you&#8217;ve just entrusted it to the merchant&#8217;s network security.  </p>
<p>I would suspect that using Debit cards with various retailers also increases your chances of encountering Card Skimmer too. Yet banks issue Debit cards to customers by default. Bank staff doesn&#8217;t even know how to issue a simple ATM Card anymore. </p>
<p>Since electronic deposit is quickly becoming the industry standard practice, the business model needs to change because the bad guys are adopting more quickly than the financial institutions and merchants. The &#8220;It&#8217;s too complex&#8221; or &#8220;It&#8217;s too expensive&#8221; is no longer an acceptable excuse.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6583" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6583', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6583-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6583" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6583', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6583-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: anonymoose</title>
		<link>http://krebsonsecurity.com/2010/01/texas-bank-sues-customer-hit-by-800000-cyber-heist/comment-page-2/#comment-6580</link>
		<dc:creator>anonymoose</dc:creator>
		<pubDate>Mon, 07 Jun 2010 15:45:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=756#comment-6580</guid>
		<description>I had a debit card with a major bank that had my picture on it. It fell out of my pocket, and someone picked it up and immediately charged almost $1000 at a convenience store, where the clerk didn&#039;t bother to compare the picture on the card (or the signature) to the person using the card.

The bank said &quot;tough luck&quot; and would not even investigate the fraud. 

Now, at least, to use the card I have to enter in my zip code (and since I have an unusual zip code, this offers me a modicum of security).

As a result, I now insist on choosing a bank that requires PIN numbers for credit cards, just as debit cards work.

Debit cards do not have the legal loss protections of credit cards (although if Obama&#039;s banking reforms pass this may change), and credit cards traditionally don&#039;t have PIN security. So it was hard to find to find a secure credit card.

The only company that supports the consumer is American Express, but since they have high bank fees, many retailers won&#039;t accept them. The hunt for an honest, secure, universally-accepted bank is unending.</description>
		<content:encoded><![CDATA[<p>I had a debit card with a major bank that had my picture on it. It fell out of my pocket, and someone picked it up and immediately charged almost $1000 at a convenience store, where the clerk didn&#8217;t bother to compare the picture on the card (or the signature) to the person using the card.</p>
<p>The bank said &#8220;tough luck&#8221; and would not even investigate the fraud. </p>
<p>Now, at least, to use the card I have to enter in my zip code (and since I have an unusual zip code, this offers me a modicum of security).</p>
<p>As a result, I now insist on choosing a bank that requires PIN numbers for credit cards, just as debit cards work.</p>
<p>Debit cards do not have the legal loss protections of credit cards (although if Obama&#8217;s banking reforms pass this may change), and credit cards traditionally don&#8217;t have PIN security. So it was hard to find to find a secure credit card.</p>
<p>The only company that supports the consumer is American Express, but since they have high bank fees, many retailers won&#8217;t accept them. The hunt for an honest, secure, universally-accepted bank is unending.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6580" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6580', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6580-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6580" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6580', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6580-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Karen</title>
		<link>http://krebsonsecurity.com/2010/01/texas-bank-sues-customer-hit-by-800000-cyber-heist/comment-page-1/#comment-6334</link>
		<dc:creator>Karen</dc:creator>
		<pubDate>Wed, 02 Jun 2010 04:59:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=756#comment-6334</guid>
		<description>That&#039;s just great but more consumers use windows than macs because they don&#039;t know otherwise; it&#039;s the way it is. If they did, they wouldnt use windows, obviously. Unless they want to be robbed. Hmm....</description>
		<content:encoded><![CDATA[<p>That&#8217;s just great but more consumers use windows than macs because they don&#8217;t know otherwise; it&#8217;s the way it is. If they did, they wouldnt use windows, obviously. Unless they want to be robbed. Hmm&#8230;.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6334" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6334', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6334-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6334" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6334', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6334-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 2/29 queries in 0.009 seconds using memcached
Object Caching 952/981 objects using memcached

Served from: krebsonsecurity.com @ 2012-05-23 00:23:13 -->
