<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Victim Asks Capital One, &#8216;Who&#8217;s in Your Wallet?&#8217;</title> <atom:link href="http://krebsonsecurity.com/2010/03/another-la-e-banking-victim-suing-capital-one/feed/" rel="self" type="application/rss+xml" /><link>http://krebsonsecurity.com/2010/03/another-la-e-banking-victim-suing-capital-one/</link> <description>In-depth security news and investigation</description> <lastBuildDate>Mon, 06 Sep 2010 11:50:41 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.0.1</generator> <item><title>By: GL Greene</title><link>http://krebsonsecurity.com/2010/03/another-la-e-banking-victim-suing-capital-one/#comment-3696</link> <dc:creator>GL Greene</dc:creator> <pubDate>Fri, 12 Mar 2010 04:52:02 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=700#comment-3696</guid> <description>This seems to be true... My bank, BB&amp;T told me that they cannot prevent unauthorized ACH debits on my business account. I have had it happen. They told me to go back to the initiator and fight them for refund. They told me the best defense was to close the account and open a new one.  Bottom line... guard your account number and don&#039;t send checks unless absolutely necessary.</description> <content:encoded><![CDATA[<p>This seems to be true&#8230; My bank, BB&amp;T told me that they cannot prevent unauthorized ACH debits on my business account. I have had it happen. They told me to go back to the initiator and fight them for refund. They told me the best defense was to close the account and open a new one.  Bottom line&#8230; guard your account number and don&#8217;t send checks unless absolutely necessary.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3696" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3696', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-3696-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3696" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3696', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-3696-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Badtux</title><link>http://krebsonsecurity.com/2010/03/another-la-e-banking-victim-suing-capital-one/#comment-3622</link> <dc:creator>Badtux</dc:creator> <pubDate>Thu, 11 Mar 2010 04:56:10 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=700#comment-3622</guid> <description>Thing is, these transactions originated from the ACH (automated check clearinghouse) system -- which has nothing to do with Zeus on his own systems, nothing originated on his own systems. The authorization tokens for the ACH system are the bank account number and the bank routing number. In other words, EVERY SINGLE PERSON HE HAS EVER MAILED A CHECK TO could be the culprit here. That&#039;s just how weak the ACH system&#039;s &quot;authentication&quot; really is.The banks set it up that way on purpose, for their own convenience, back when the original ACH system was set up by the Federal Reserve because they didn&#039;t want to have to authenticate that each transaction was authorized by the person who&#039;d issued the check. But that was back when only Federal Reserve banks had ACH terminals and you could at least validate that an actual physical check was involved. Nowadays, a friggin&#039; *health club* can make an unauthorized withdrawal from your account just using the routing number and account number off a check you once mailed them. Yes, I know this for a fact -- it happened to me.In short: the ACH system has clear authorization issues that the banks are *not* in any hurry to fix since they&#039;re not on the hook. Any talk of &quot;Zeus&quot; or whatnot is ridiculous here -- no amount of Zeus  on his own system would create a transaction that originated from the ACH system. Zeus could have stole his account number, but the same is true of anybody else that this guy has ever mailed a check to since the day he opened the account. The banks chose convenience over security when they created the ACH system, and now they&#039;re making the small businesses pay once scammers exploit the very security hole that the banks themselves put into their system? Yeah, that sounds about right...</description> <content:encoded><![CDATA[<div
style="background-color:#FFFFCC !important"><p>Thing is, these transactions originated from the ACH (automated check clearinghouse) system &#8212; which has nothing to do with Zeus on his own systems, nothing originated on his own systems. The authorization tokens for the ACH system are the bank account number and the bank routing number. In other words, EVERY SINGLE PERSON HE HAS EVER MAILED A CHECK TO could be the culprit here. That&#8217;s just how weak the ACH system&#8217;s &#8220;authentication&#8221; really is.</p><p> The banks set it up that way on purpose, for their own convenience, back when the original ACH system was set up by the Federal Reserve because they didn&#8217;t want to have to authenticate that each transaction was authorized by the person who&#8217;d issued the check. But that was back when only Federal Reserve banks had ACH terminals and you could at least validate that an actual physical check was involved. Nowadays, a friggin&#8217; *health club* can make an unauthorized withdrawal from your account just using the routing number and account number off a check you once mailed them. Yes, I know this for a fact &#8212; it happened to me.</p><p>In short: the ACH system has clear authorization issues that the banks are *not* in any hurry to fix since they&#8217;re not on the hook. Any talk of &#8220;Zeus&#8221; or whatnot is ridiculous here &#8212; no amount of Zeus  on his own system would create a transaction that originated from the ACH system. Zeus could have stole his account number, but the same is true of anybody else that this guy has ever mailed a check to since the day he opened the account. The banks chose convenience over security when they created the ACH system, and now they&#8217;re making the small businesses pay once scammers exploit the very security hole that the banks themselves put into their system? Yeah, that sounds about right&#8230;</p></div><p>Well-loved. Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3622" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3622', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-3622-up" style="font-size:12px; color:#009933;">4</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3622" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3622', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-3622-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Rick</title><link>http://krebsonsecurity.com/2010/03/another-la-e-banking-victim-suing-capital-one/#comment-3458</link> <dc:creator>Rick</dc:creator> <pubDate>Tue, 09 Mar 2010 13:08:51 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=700#comment-3458</guid> <description>On the one hand: most of these businesses are hopelessly locked into Windows and hopelessly infected with a cocktail of malware, most often Zeus, even if they say otherwise and even if they have supposed &#039;experts&#039; supporting the claim. We all know they are/were infected at one point or another.On the other hand: the banks lose nothing. The contracts state the businesses must absorb the losses.There are two solutions. Either legislation makes the banks liable - and that&#039;s never going to happen because the banks know how bad security is out there in the field - or the businesses have to stop using Windows. There&#039;s either the one or the other. There&#039;s no &#039;in between&#039;.</description> <content:encoded><![CDATA[<p>On the one hand: most of these businesses are hopelessly locked into Windows and hopelessly infected with a cocktail of malware, most often Zeus, even if they say otherwise and even if they have supposed &#8216;experts&#8217; supporting the claim. We all know they are/were infected at one point or another.</p><p>On the other hand: the banks lose nothing. The contracts state the businesses must absorb the losses.</p><p>There are two solutions. Either legislation makes the banks liable &#8211; and that&#8217;s never going to happen because the banks know how bad security is out there in the field &#8211; or the businesses have to stop using Windows. There&#8217;s either the one or the other. There&#8217;s no &#8216;in between&#8217;.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3458" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3458', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-3458-up" style="font-size:12px; color:#009933;">1</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3458" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3458', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-3458-down" style="font-size:12px; color:#990033;">6</span></p>]]></content:encoded> </item> <item><title>By: Rick</title><link>http://krebsonsecurity.com/2010/03/another-la-e-banking-victim-suing-capital-one/#comment-3456</link> <dc:creator>Rick</dc:creator> <pubDate>Tue, 09 Mar 2010 12:59:59 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=700#comment-3456</guid> <description>CC companies employ extraordinary measures to prophylactically prevent crime and yet people get ripped off all the time. It might be interesting to compare stats for CCs with online banking.</description> <content:encoded><![CDATA[<p>CC companies employ extraordinary measures to prophylactically prevent crime and yet people get ripped off all the time. It might be interesting to compare stats for CCs with online banking.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3456" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3456', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-3456-up" style="font-size:12px; color:#009933;">2</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3456" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3456', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-3456-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Rick</title><link>http://krebsonsecurity.com/2010/03/another-la-e-banking-victim-suing-capital-one/#comment-3454</link> <dc:creator>Rick</dc:creator> <pubDate>Tue, 09 Mar 2010 12:54:26 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=700#comment-3454</guid> <description>Not finding Zeus doesn&#039;t mean anything when forensic tests show Zeus can only be detected 23% of the time.</description> <content:encoded><![CDATA[<div
style="background-color:#FFFFCC !important"><p>Not finding Zeus doesn&#8217;t mean anything when forensic tests show Zeus can only be detected 23% of the time.</p></div><p>Well-loved. Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3454" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3454', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-3454-up" style="font-size:12px; color:#009933;">4</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3454" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3454', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-3454-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Gerrys Blog &#187; Blog Archive &#187; Chanel &#124; expo bags » Blog Archive » Discount chanel handbags and chanel</title><link>http://krebsonsecurity.com/2010/03/another-la-e-banking-victim-suing-capital-one/#comment-3447</link> <dc:creator>Gerrys Blog &#187; Blog Archive &#187; Chanel &#124; expo bags » Blog Archive » Discount chanel handbags and chanel</dc:creator> <pubDate>Tue, 09 Mar 2010 10:31:34 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=700#comment-3447</guid> <description>[...] Victim Asks Capital One, &#039;Who&#039;s in Your Wallet?&#039; — Krebs on Security [...]</description> <content:encoded><![CDATA[<p>[...] Victim Asks Capital One, &#39;Who&#39;s in Your Wallet?&#39; — Krebs on Security [...]</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3447" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3447', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-3447-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3447" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3447', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-3447-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: what is the effect of a personal injury payment of £2800 on means tested benefits and housing benefit?</title><link>http://krebsonsecurity.com/2010/03/another-la-e-banking-victim-suing-capital-one/#comment-3446</link> <dc:creator>what is the effect of a personal injury payment of £2800 on means tested benefits and housing benefit?</dc:creator> <pubDate>Tue, 09 Mar 2010 10:02:09 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=700#comment-3446</guid> <description>[...] Victim Asks Capital One, &#039;Who&#039;s in Your Wallet?&#039; — Krebs on Security [...]</description> <content:encoded><![CDATA[<p>[...] Victim Asks Capital One, &#39;Who&#39;s in Your Wallet?&#39; — Krebs on Security [...]</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3446" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3446', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-3446-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3446" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3446', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-3446-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Darrell Haynes</title><link>http://krebsonsecurity.com/2010/03/another-la-e-banking-victim-suing-capital-one/#comment-3422</link> <dc:creator>Darrell Haynes</dc:creator> <pubDate>Tue, 09 Mar 2010 03:54:40 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=700#comment-3422</guid> <description>FYI From CERT:Energizer DUO USB Battery Charger Software Allows Remote System Access
added March 8, 2010 at 10:26 amUS-CERT is aware of a backdoor in the software for the Energizer DUO USB battery charger. This backdoor may allow a remote attacker to list directories, send and receive files, and execute programs on an affected system. The software, which has been discontinued, was available for both Windows and Apple Mac OS X versions. Only the Windows version is affected by this vulnerability.US-CERT encourages users and administrators to review Vulnerability Note VU#154421 and apply the recommended solutions.</description> <content:encoded><![CDATA[<p>FYI From CERT:</p><p>Energizer DUO USB Battery Charger Software Allows Remote System Access<br
/> added March 8, 2010 at 10:26 am</p><p>US-CERT is aware of a backdoor in the software for the Energizer DUO USB battery charger. This backdoor may allow a remote attacker to list directories, send and receive files, and execute programs on an affected system. The software, which has been discontinued, was available for both Windows and Apple Mac OS X versions. Only the Windows version is affected by this vulnerability.</p><p>US-CERT encourages users and administrators to review Vulnerability Note VU#154421 and apply the recommended solutions.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3422" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3422', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-3422-up" style="font-size:12px; color:#009933;">1</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3422" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3422', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-3422-down" style="font-size:12px; color:#990033;">5</span></p>]]></content:encoded> </item> <item><title>By: MGD</title><link>http://krebsonsecurity.com/2010/03/another-la-e-banking-victim-suing-capital-one/#comment-3418</link> <dc:creator>MGD</dc:creator> <pubDate>Tue, 09 Mar 2010 01:44:47 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=700#comment-3418</guid> <description>Quote:  &quot; ....  lost more than $27,000 last year when five unauthorized automated clearing house withdrawals were made from its accounts and sent to individuals around the United States ....&quot;Page 1 of the court filing states four (4) withdrawals for $27,620. However the attached exhibits show that originally there were four withdrawals totaling $36,495.  However,  it appears according to an exhibit dated 03/10/2009 that the fourth withdrawal for $8,875 was subsequently reversed, leaving the actual loss at three withdrawals totaling $27,620, as follows:ELAINE LEE SHELBY     WELLS FARGO MN. 02/25/2009  $9,200
KERRY ALYSSA DIXON    JPM CHASE  MO.  02/26/2009  $9,720
ZERRIN KARAGOZ         JPM CHASE FL.  02/26/2009  $8,700Brian,  since there is no record of  a ZEUS / zbot infection, have you attempted to contact any of the recipients and confirm that the funds were sent via Money Gram / Western Union to the usual eastern European places ?. At least one of them appears easy to locate.  One anomaly in the exhibits is that the last transfer for $8,700 lists an invalid account number, it is a duplicate of the bank id code.Also surprising from a security standpoint, the account is listed as a Payroll account,  is that these are large unusual amounts for a small business payroll account, and are being sent to accounts over a thousand miles away in other states. If one were to write fraud detection algorithms, those are two criteria flags for a SB payroll account.The Capitol One web page for matching to the small business account services on the exhibits has in its meta data:&quot;With TowerNET from Capital One, your small business is in control of its finances anytime from anywhere from a single point of access.&quot;In the current cyber environment that statement almost sounds like a security flaw !This case, and many of the other suits may hinge on whether statements made by banks regarding their security procedures, such as this from Capital, are really true:Quote:&quot;* We build information security right into our systems and networks using internationally recognized security standards, regulations, and industry-based best practices.* We employ strong authentication controls following guidance provided to us by the Federal Government&#039;s banking regulators&quot;MGD</description> <content:encoded><![CDATA[<div
style="background-color:#FFFFCC !important"><p>Quote:  &#8221; &#8230;.  lost more than $27,000 last year when five unauthorized automated clearing house withdrawals were made from its accounts and sent to individuals around the United States &#8230;.&#8221;</p><p>Page 1 of the court filing states four (4) withdrawals for $27,620. However the attached exhibits show that originally there were four withdrawals totaling $36,495.  However,  it appears according to an exhibit dated 03/10/2009 that the fourth withdrawal for $8,875 was subsequently reversed, leaving the actual loss at three withdrawals totaling $27,620, as follows:</p><p>ELAINE LEE SHELBY     WELLS FARGO MN. 02/25/2009  $9,200<br
/> KERRY ALYSSA DIXON    JPM CHASE  MO.  02/26/2009  $9,720<br
/> ZERRIN KARAGOZ         JPM CHASE FL.  02/26/2009  $8,700</p><p>Brian,  since there is no record of  a ZEUS / zbot infection, have you attempted to contact any of the recipients and confirm that the funds were sent via Money Gram / Western Union to the usual eastern European places ?. At least one of them appears easy to locate.  One anomaly in the exhibits is that the last transfer for $8,700 lists an invalid account number, it is a duplicate of the bank id code.</p><p>Also surprising from a security standpoint, the account is listed as a Payroll account,  is that these are large unusual amounts for a small business payroll account, and are being sent to accounts over a thousand miles away in other states. If one were to write fraud detection algorithms, those are two criteria flags for a SB payroll account.</p><p>The Capitol One web page for matching to the small business account services on the exhibits has in its meta data:</p><p>&#8220;With TowerNET from Capital One, your small business is in control of its finances anytime from anywhere from a single point of access.&#8221;</p><p>In the current cyber environment that statement almost sounds like a security flaw !</p><p>This case, and many of the other suits may hinge on whether statements made by banks regarding their security procedures, such as this from Capital, are really true:</p><p>Quote:</p><p>&#8220;* We build information security right into our systems and networks using internationally recognized security standards, regulations, and industry-based best practices.</p><p>* We employ strong authentication controls following guidance provided to us by the Federal Government&#8217;s banking regulators&#8221;</p><p>MGD</p></div><p>Well-loved. Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3418" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3418', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-3418-up" style="font-size:12px; color:#009933;">8</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3418" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3418', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-3418-down" style="font-size:12px; color:#990033;">1</span></p>]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using memcached
Page Caching using memcached (user agent is rejected)
Database Caching 3/10 queries in 0.004 seconds using memcached

Served from: krebsonsecurity.com @ 2010-09-06 12:12:01 -->