<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: N.Y. Firm Faces Bankruptcy from $164,000 E-Banking Loss</title>
	<atom:link href="http://krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Sat, 11 Feb 2012 19:29:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: cheeseman</title>
		<link>http://krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/comment-page-2/#comment-7332</link>
		<dc:creator>cheeseman</dc:creator>
		<pubDate>Fri, 02 Jul 2010 18:13:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1311#comment-7332</guid>
		<description>Sounds like the bank is aiding and abetting criminals with grand larceny. I would find a good lawyer.</description>
		<content:encoded><![CDATA[<p>Sounds like the bank is aiding and abetting criminals with grand larceny. I would find a good lawyer.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7332" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7332', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7332-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7332" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7332', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7332-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Eli Talmor</title>
		<link>http://krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/comment-page-2/#comment-7162</link>
		<dc:creator>Eli Talmor</dc:creator>
		<pubDate>Mon, 28 Jun 2010 13:11:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1311#comment-7162</guid>
		<description>Gartner analysts published in December 2009 that all existing means of strong authentication are inadequate to protect transaction integrity for simple reason that Trojan horse malware resident on our infected PCs circumvent these means. Nearly 50% of PCs worldwide are infected with some sort of malware. The vulnerability exploited is called Man in the Browser. Man-in-the-Browser, is a trojan that infects a web browser and has the ability to modify transaction content or insert additional transactions, all in a completely covert fashion invisible to both the user and host application. A MitB attack will be successful irrespective of whether security mechanisms such as SSL/PKI and/or Two or Three Factor Authentication solutions are in place. The MitB Trojan works by utilising common facilities provided to enhance Browser capabilities is virtually undetectable to virus scanning software.In an example exchange between user and host, the customer will always be shown, via confirmation screens, the exact payment information as keyed into the browser. The bank, however, will receive a transaction with materially altered instructions. The use of strong authentication tools simply creates an increased level of misplaced confidence on the part of both customer and bank that the transaction is secure. Therefore US regulators and FBI recommend that all financial activities will be performed only from dedicated computers. Obviously this is a short-term solution. It has been demonstrated that Out-of-band transaction confirmation , such SMS sent over mobile phone , merely adds complexity to the process and is still vulnerable to targeted attack .The need exists for malware-resilient solution to the problem.
Our solution is a 2-stage process including signing of web form by user and signed form authorization by the service provider. No transaction will be authorized without both stages fully completed. In order to use our Software-as-a-Service end-user must download our client software, register his PC and enroll his Biometrics VoicePrint, the whole process takes less then a minute. Signing software includes data verification module that ensures that What you See is What you Sign, Strong Authentication module that ensures the identity of the person signing transaction and Advanced Electronic Signature module that ensures transaction integrity in transit and at rest.
The following flow highlights the signing process for medium-sensitivity transaction. End-user signs web-form for third-party money transfer. Our software prompts end-user to confirm transaction integrity and verify the data. Finally end-user is prompted to enter his 4 digit PIN. It takes about 15 sec of end-user time to sign filled web-form. Meduim-sensitivity transaction is signed using 2-factor strong authentication, including proprietary PC ID (something you have) and PIN (something you know). Higher-sensitivity transactions may be signed using 3-factor strong authentication by adding Live Voice Biometrics (something you are)..
Signed web-form includes 2 parts: end-user attributes and transaction details. It complies with the definition of Advanced Electronic Signature. Both end-user and service provider will keep the same signed web-form for future audit. Service provider may access this signed web-form through our API. This solution is malware-resilient, does not require any dedicated hardware and does not add complexity to the business flow. This solution is generic and is applicable to Banking transfers, E-commerce purchases, Insurance claims, Healthcare prescriptions, E-Gov voting.</description>
		<content:encoded><![CDATA[<p>Gartner analysts published in December 2009 that all existing means of strong authentication are inadequate to protect transaction integrity for simple reason that Trojan horse malware resident on our infected PCs circumvent these means. Nearly 50% of PCs worldwide are infected with some sort of malware. The vulnerability exploited is called Man in the Browser. Man-in-the-Browser, is a trojan that infects a web browser and has the ability to modify transaction content or insert additional transactions, all in a completely covert fashion invisible to both the user and host application. A MitB attack will be successful irrespective of whether security mechanisms such as SSL/PKI and/or Two or Three Factor Authentication solutions are in place. The MitB Trojan works by utilising common facilities provided to enhance Browser capabilities is virtually undetectable to virus scanning software.In an example exchange between user and host, the customer will always be shown, via confirmation screens, the exact payment information as keyed into the browser. The bank, however, will receive a transaction with materially altered instructions. The use of strong authentication tools simply creates an increased level of misplaced confidence on the part of both customer and bank that the transaction is secure. Therefore US regulators and FBI recommend that all financial activities will be performed only from dedicated computers. Obviously this is a short-term solution. It has been demonstrated that Out-of-band transaction confirmation , such SMS sent over mobile phone , merely adds complexity to the process and is still vulnerable to targeted attack .The need exists for malware-resilient solution to the problem.<br />
Our solution is a 2-stage process including signing of web form by user and signed form authorization by the service provider. No transaction will be authorized without both stages fully completed. In order to use our Software-as-a-Service end-user must download our client software, register his PC and enroll his Biometrics VoicePrint, the whole process takes less then a minute. Signing software includes data verification module that ensures that What you See is What you Sign, Strong Authentication module that ensures the identity of the person signing transaction and Advanced Electronic Signature module that ensures transaction integrity in transit and at rest.<br />
The following flow highlights the signing process for medium-sensitivity transaction. End-user signs web-form for third-party money transfer. Our software prompts end-user to confirm transaction integrity and verify the data. Finally end-user is prompted to enter his 4 digit PIN. It takes about 15 sec of end-user time to sign filled web-form. Meduim-sensitivity transaction is signed using 2-factor strong authentication, including proprietary PC ID (something you have) and PIN (something you know). Higher-sensitivity transactions may be signed using 3-factor strong authentication by adding Live Voice Biometrics (something you are)..<br />
Signed web-form includes 2 parts: end-user attributes and transaction details. It complies with the definition of Advanced Electronic Signature. Both end-user and service provider will keep the same signed web-form for future audit. Service provider may access this signed web-form through our API. This solution is malware-resilient, does not require any dedicated hardware and does not add complexity to the business flow. This solution is generic and is applicable to Banking transfers, E-commerce purchases, Insurance claims, Healthcare prescriptions, E-Gov voting.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7162" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7162', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7162-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7162" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7162', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7162-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Clarification</title>
		<link>http://krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/comment-page-1/#comment-5887</link>
		<dc:creator>Clarification</dc:creator>
		<pubDate>Mon, 17 May 2010 01:21:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1311#comment-5887</guid>
		<description>I hear it often, that banks are responsible for credit card fraud. They are not. The vendor loses money on fraudulent transactions, not banks. I wish banks were responsible; we would have less fraud then.</description>
		<content:encoded><![CDATA[<p>I hear it often, that banks are responsible for credit card fraud. They are not. The vendor loses money on fraudulent transactions, not banks. I wish banks were responsible; we would have less fraud then.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-5887" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('5887', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-5887-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-5887" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('5887', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-5887-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Jay</title>
		<link>http://krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/comment-page-2/#comment-5093</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Fri, 16 Apr 2010 14:13:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1311#comment-5093</guid>
		<description>Interesting &#039;concept&#039;: http://www.srware.net/en/software_banking_browser_2008.php

A stripped browser, for banking only: no Java, Flash. Also, shielded against other installed browsers.

Seems more practical than a separate box for banking only.

In German - and, unfortunately, not updated since 2008, so I can&#039;t tell how secure it is :(</description>
		<content:encoded><![CDATA[<p>Interesting &#8216;concept&#8217;: <a href="http://www.srware.net/en/software_banking_browser_2008.php" rel="nofollow">http://www.srware.net/en/software_banking_browser_2008.php</a></p>
<p>A stripped browser, for banking only: no Java, Flash. Also, shielded against other installed browsers.</p>
<p>Seems more practical than a separate box for banking only.</p>
<p>In German &#8211; and, unfortunately, not updated since 2008, so I can&#8217;t tell how secure it is <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-5093" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('5093', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-5093-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-5093" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('5093', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-5093-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Sean</title>
		<link>http://krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/comment-page-2/#comment-4883</link>
		<dc:creator>Sean</dc:creator>
		<pubDate>Thu, 08 Apr 2010 19:59:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1311#comment-4883</guid>
		<description>&quot;Adobe should be fined for their poor security&quot;

Every user that downloads Adobe software enters into a binding legal contract stating that Adobe is not responsible for any consequential damages, direct or indirect, and there is no warranty. Nearly every software package in existence has this language in their license agreement.

Does Adobe security suck?  Yes, probably.

Have they done something illegal?  No, absolutely not.  They warned you upfront and you choose to  ignore the warning and take the risk.

You can&#039;t &quot;fine&quot; people for doing something that is not illegal.</description>
		<content:encoded><![CDATA[<p>&#8220;Adobe should be fined for their poor security&#8221;</p>
<p>Every user that downloads Adobe software enters into a binding legal contract stating that Adobe is not responsible for any consequential damages, direct or indirect, and there is no warranty. Nearly every software package in existence has this language in their license agreement.</p>
<p>Does Adobe security suck?  Yes, probably.</p>
<p>Have they done something illegal?  No, absolutely not.  They warned you upfront and you choose to  ignore the warning and take the risk.</p>
<p>You can&#8217;t &#8220;fine&#8221; people for doing something that is not illegal.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4883" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4883', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4883-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4883" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4883', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4883-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Sean</title>
		<link>http://krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/comment-page-1/#comment-4787</link>
		<dc:creator>Sean</dc:creator>
		<pubDate>Mon, 05 Apr 2010 22:49:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1311#comment-4787</guid>
		<description>I also feel really bad for this business owner.

But, in a vein similar to your comment, the business owner admitted that she opted to take the risk and not purchase insurance for her business.  I did that too during the first few years of my business.  Then I &quot;grew up&quot; as a business owner, and started paying out $200/month to insure my business against lots of different calamities.</description>
		<content:encoded><![CDATA[<p>I also feel really bad for this business owner.</p>
<p>But, in a vein similar to your comment, the business owner admitted that she opted to take the risk and not purchase insurance for her business.  I did that too during the first few years of my business.  Then I &#8220;grew up&#8221; as a business owner, and started paying out $200/month to insure my business against lots of different calamities.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4787" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4787', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4787-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4787" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4787', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4787-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Sean</title>
		<link>http://krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/comment-page-1/#comment-4786</link>
		<dc:creator>Sean</dc:creator>
		<pubDate>Mon, 05 Apr 2010 22:45:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1311#comment-4786</guid>
		<description>You are absolutely right.  I was wondering why some of the mules had apparently been instructed to set up LLC&#039;s.  Bingo.  You just answered the question.

If the &quot;mule&quot; is an LLC, banks don&#039;t care.</description>
		<content:encoded><![CDATA[<p>You are absolutely right.  I was wondering why some of the mules had apparently been instructed to set up LLC&#8217;s.  Bingo.  You just answered the question.</p>
<p>If the &#8220;mule&#8221; is an LLC, banks don&#8217;t care.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4786" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4786', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4786-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4786" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4786', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4786-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: si-borg</title>
		<link>http://krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/comment-page-1/#comment-4667</link>
		<dc:creator>si-borg</dc:creator>
		<pubDate>Thu, 01 Apr 2010 02:07:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1311#comment-4667</guid>
		<description>An SMS sent after every transaction as confirmation would help ensure that business owners would be able to get onto any problems within 24 hours. Some banks already do this in Australia.  

Simple. Cheap. Effective?</description>
		<content:encoded><![CDATA[<p>An SMS sent after every transaction as confirmation would help ensure that business owners would be able to get onto any problems within 24 hours. Some banks already do this in Australia.  </p>
<p>Simple. Cheap. Effective?</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4667" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4667', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4667-up" style="font-size:14px; color:#009933;">3</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4667" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4667', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4667-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Businger</title>
		<link>http://krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/comment-page-1/#comment-4637</link>
		<dc:creator>Michael Businger</dc:creator>
		<pubDate>Wed, 31 Mar 2010 16:35:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1311#comment-4637</guid>
		<description>This is another good reason for anyone using online banking to have a dedicated computer that is only used to online banking, no web browsing, no email, no storage of sensitive or critical business data, etc. Yes, this is an additional cost, but I think any reasonable person can see it is much cheaper than the alternative!</description>
		<content:encoded><![CDATA[<div style="background-color:#FFFFCC !important"><p>This is another good reason for anyone using online banking to have a dedicated computer that is only used to online banking, no web browsing, no email, no storage of sensitive or critical business data, etc. Yes, this is an additional cost, but I think any reasonable person can see it is much cheaper than the alternative!</p>
</div><div class="CommentRating">Well-loved. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4637" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4637', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4637-up" style="font-size:14px; color:#009933;">10</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4637" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4637', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4637-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Henry Hertz Hobbit</title>
		<link>http://krebsonsecurity.com/2010/02/n-y-firm-faces-bankruptcy-from-164000-e-banking-loss/comment-page-2/#comment-4140</link>
		<dc:creator>Henry Hertz Hobbit</dc:creator>
		<pubDate>Wed, 17 Mar 2010 22:25:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1311#comment-4140</guid>
		<description>Brian:

Good article.  Now you know why I spend so much of my time trying to foil ZBot at SecureMecca dot com.  There are several points I feel need to be made.

1. These people really need to consider getting off of Microsoft Windows.  I had a Windows newbie that was using my PAC filter basically accuse me that I had made it so that he was going to have to format his drive to get rid of the PAC filter. I don&#039;t know if the instructions I gave him in a personal email placated him, but if he had just read the Uninstall.txt file he would have been good to go.  In fact, he could turn the PAC filter on and off at will. The registry changes are just to make it possible for it to function at all. He could also have deleted the rule in the PAC filter that caused problems for him.  Even a little bit of extra protection is better than none.  I just installed Thunderbird on Sauron running OpenSUSE 11.2 Linux .  I had to deduce that renaming the unbzipped folder (thunderbird ---&gt; thunderbird-3.03.) was in order along with creating a symlink (thunderbird ---&gt; /usr/local/lib/thunderbird-3.0.3). Altering the thunderbird startup script was also necessary to handle the future update changes, which I hope slow down from a torrent to a trickle.  What am I saying?  These people need to take some of the responsibility on themselves so that this doesn&#039;t happen.  Ergo, if you want the easy route off of Windows pick Macintosh.  The hard route via Linux takes more work but these people need to ask themselves just one question.  What if this attack had been made on me and I was using a Macintosh or Linux?  Attack foiled.  I was talking to a relative that had suspicious charges on their credit card.  Their machine is pwned.  How many are like this?  A lot more than people think.  Hackers have already found ways around the UAC.
I must hasten to add that I don&#039;t use them, so the UAC gets in the way of auto updating the PAC filter.  It is only useful with XP or Windows 7 Professional or Ultimate.  I would suggest using the Web Of Trust, but that doesn&#039;t help in a spear phishing attack.

2. Banking regulations need to change.  The financial institutions need to assume at least some of the responsibility for this.  The complete draining of a company&#039;s assets should never have happened.  Legislative bodies primarily in the U.S. but all over the earth need to provide the protection that is being used to protect idiots that are using Windows whether they are just personal or small business.  They are already doing it for the individual.  The regulations were written with a large corporation in mind and it just isn&#039;t enough.  Small businesses do not have the resources and in many cases the personal acumen to make themselves safer.

3. Security comes in layers.  One of these layers is step 2.  The other is step 1.  Another layer is to use some common sense - do NOT click on the links in emails, especially if it is saying it goes to NACHA, FDIC, or some other place like that.  Invariably, that is NOT where they go.</description>
		<content:encoded><![CDATA[<p>Brian:</p>
<p>Good article.  Now you know why I spend so much of my time trying to foil ZBot at SecureMecca dot com.  There are several points I feel need to be made.</p>
<p>1. These people really need to consider getting off of Microsoft Windows.  I had a Windows newbie that was using my PAC filter basically accuse me that I had made it so that he was going to have to format his drive to get rid of the PAC filter. I don&#8217;t know if the instructions I gave him in a personal email placated him, but if he had just read the Uninstall.txt file he would have been good to go.  In fact, he could turn the PAC filter on and off at will. The registry changes are just to make it possible for it to function at all. He could also have deleted the rule in the PAC filter that caused problems for him.  Even a little bit of extra protection is better than none.  I just installed Thunderbird on Sauron running OpenSUSE 11.2 Linux .  I had to deduce that renaming the unbzipped folder (thunderbird &#8212;&gt; thunderbird-3.03.) was in order along with creating a symlink (thunderbird &#8212;&gt; /usr/local/lib/thunderbird-3.0.3). Altering the thunderbird startup script was also necessary to handle the future update changes, which I hope slow down from a torrent to a trickle.  What am I saying?  These people need to take some of the responsibility on themselves so that this doesn&#8217;t happen.  Ergo, if you want the easy route off of Windows pick Macintosh.  The hard route via Linux takes more work but these people need to ask themselves just one question.  What if this attack had been made on me and I was using a Macintosh or Linux?  Attack foiled.  I was talking to a relative that had suspicious charges on their credit card.  Their machine is pwned.  How many are like this?  A lot more than people think.  Hackers have already found ways around the UAC.<br />
I must hasten to add that I don&#8217;t use them, so the UAC gets in the way of auto updating the PAC filter.  It is only useful with XP or Windows 7 Professional or Ultimate.  I would suggest using the Web Of Trust, but that doesn&#8217;t help in a spear phishing attack.</p>
<p>2. Banking regulations need to change.  The financial institutions need to assume at least some of the responsibility for this.  The complete draining of a company&#8217;s assets should never have happened.  Legislative bodies primarily in the U.S. but all over the earth need to provide the protection that is being used to protect idiots that are using Windows whether they are just personal or small business.  They are already doing it for the individual.  The regulations were written with a large corporation in mind and it just isn&#8217;t enough.  Small businesses do not have the resources and in many cases the personal acumen to make themselves safer.</p>
<p>3. Security comes in layers.  One of these layers is step 2.  The other is step 1.  Another layer is to use some common sense &#8211; do NOT click on the links in emails, especially if it is saying it goes to NACHA, FDIC, or some other place like that.  Invariably, that is NOT where they go.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4140" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4140', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4140-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4140" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4140', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4140-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 2/23 queries in 0.023 seconds using memcached
Object Caching 952/970 objects using memcached

Served from: krebsonsecurity.com @ 2012-02-12 06:36:48 -->
