<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Big Bank Mules Target Small Bank Businesses</title>
	<atom:link href="http://krebsonsecurity.com/2013/01/big-bank-mules-target-small-bank-businesses/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2013/01/big-bank-mules-target-small-bank-businesses/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Sun, 19 May 2013 06:15:27 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: TJ</title>
		<link>http://krebsonsecurity.com/2013/01/big-bank-mules-target-small-bank-businesses/comment-page-1/#comment-148808</link>
		<dc:creator>TJ</dc:creator>
		<pubDate>Fri, 01 Feb 2013 07:05:49 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18091#comment-148808</guid>
		<description><![CDATA[Instead of trying to freeload off of Brian&#039;s blog, why don&#039;t you do the ethical thing and buy some ad space.]]></description>
		<content:encoded><![CDATA[<p>Instead of trying to freeload off of Brian&#8217;s blog, why don&#8217;t you do the ethical thing and buy some ad space.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike A.</title>
		<link>http://krebsonsecurity.com/2013/01/big-bank-mules-target-small-bank-businesses/comment-page-1/#comment-148653</link>
		<dc:creator>Mike A.</dc:creator>
		<pubDate>Thu, 31 Jan 2013 21:37:44 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18091#comment-148653</guid>
		<description><![CDATA[SoundPass removes the human element from the total Login, therefore preventing any Trojan real-time Keyloggers from stealing the virtual SoundPass credential dynamic token. This solution is better than any existing solution available at any major Bank protecting massive volumes of users. Besides being more secure, it is also more user friendly and more affordable.
Yes it uses a Java applet to generate a new virtual token for every Login because Java is the stronges program language online. Today&#039;s Java vulnerbilities would not allow a Hacker into a SoundPass protected account. The Hacker would have never gotten into the online bank account in the first place if it were protected by SoundPass. For a major online banking provider to make the comment that user&#039;s must watch their own backs will not hold up in court of law, as we have already seen. Banks are responsible for providing best possible security per the FFIEC.
Banks could implement Smartcards to properly protect their online banking members but Smartcards are more expensive, difficult to deploy to massive volumes of users and they are cumbersome for the users. By the way, SoundPass was designed from a Smartcard. So their are strong solutions available and these types of breaches DO NOT have to keep happening over and over again!]]></description>
		<content:encoded><![CDATA[<p>SoundPass removes the human element from the total Login, therefore preventing any Trojan real-time Keyloggers from stealing the virtual SoundPass credential dynamic token. This solution is better than any existing solution available at any major Bank protecting massive volumes of users. Besides being more secure, it is also more user friendly and more affordable.<br />
Yes it uses a Java applet to generate a new virtual token for every Login because Java is the stronges program language online. Today&#8217;s Java vulnerbilities would not allow a Hacker into a SoundPass protected account. The Hacker would have never gotten into the online bank account in the first place if it were protected by SoundPass. For a major online banking provider to make the comment that user&#8217;s must watch their own backs will not hold up in court of law, as we have already seen. Banks are responsible for providing best possible security per the FFIEC.<br />
Banks could implement Smartcards to properly protect their online banking members but Smartcards are more expensive, difficult to deploy to massive volumes of users and they are cumbersome for the users. By the way, SoundPass was designed from a Smartcard. So their are strong solutions available and these types of breaches DO NOT have to keep happening over and over again!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George</title>
		<link>http://krebsonsecurity.com/2013/01/big-bank-mules-target-small-bank-businesses/comment-page-1/#comment-148529</link>
		<dc:creator>George</dc:creator>
		<pubDate>Thu, 31 Jan 2013 15:54:51 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18091#comment-148529</guid>
		<description><![CDATA[Why isn&#039;t more attention paid to the mules? Perhaps the banking industry should sponsor TV ads that advise the public about what a mule does and why it is part of an illegal enterprise.

Negative publicity about the mule profession could make it more difficult to find people to do that job.]]></description>
		<content:encoded><![CDATA[<p>Why isn&#8217;t more attention paid to the mules? Perhaps the banking industry should sponsor TV ads that advise the public about what a mule does and why it is part of an illegal enterprise.</p>
<p>Negative publicity about the mule profession could make it more difficult to find people to do that job.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wonderer</title>
		<link>http://krebsonsecurity.com/2013/01/big-bank-mules-target-small-bank-businesses/comment-page-1/#comment-148510</link>
		<dc:creator>Wonderer</dc:creator>
		<pubDate>Thu, 31 Jan 2013 14:20:33 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18091#comment-148510</guid>
		<description><![CDATA[Sorry for offtopic,

Here is some relatively fresh information about Chronopay case in Russian court. 

http://www.compromat.ru/page_32949.htm 

This site has many articles on &quot;controvercial&quot; stories and cases.]]></description>
		<content:encoded><![CDATA[<p>Sorry for offtopic,</p>
<p>Here is some relatively fresh information about Chronopay case in Russian court. </p>
<p><a href="http://www.compromat.ru/page_32949.htm" rel="nofollow">http://www.compromat.ru/page_32949.htm</a> </p>
<p>This site has many articles on &#8220;controvercial&#8221; stories and cases.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon</title>
		<link>http://krebsonsecurity.com/2013/01/big-bank-mules-target-small-bank-businesses/comment-page-1/#comment-148070</link>
		<dc:creator>Jon</dc:creator>
		<pubDate>Wed, 30 Jan 2013 13:11:15 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18091#comment-148070</guid>
		<description><![CDATA[Isn&#039;t a separate verification really just a form of &quot;out of band&quot; authentication?

The issue is MITB manipulating sensitive data elements (like routing # and account #) on the wire while displaying what was entered on the screen.

Only some form of out of band is an effective control against this, something that prevents MITB, or an insurance type solution.]]></description>
		<content:encoded><![CDATA[<p>Isn&#8217;t a separate verification really just a form of &#8220;out of band&#8221; authentication?</p>
<p>The issue is MITB manipulating sensitive data elements (like routing # and account #) on the wire while displaying what was entered on the screen.</p>
<p>Only some form of out of band is an effective control against this, something that prevents MITB, or an insurance type solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon</title>
		<link>http://krebsonsecurity.com/2013/01/big-bank-mules-target-small-bank-businesses/comment-page-1/#comment-148067</link>
		<dc:creator>Jon</dc:creator>
		<pubDate>Wed, 30 Jan 2013 13:08:34 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18091#comment-148067</guid>
		<description><![CDATA[How would you make payments to employees and vendors without a Bank?  Cash?  Seems like using a Bank is pretty much required if you are going to be more than a sole proprietor.  Even if your Bank fails, you&#039;ll hardly notice it (while the taxpayer, certainly does).  The failed bank gets a new name and off you go on Monday morning.]]></description>
		<content:encoded><![CDATA[<p>How would you make payments to employees and vendors without a Bank?  Cash?  Seems like using a Bank is pretty much required if you are going to be more than a sole proprietor.  Even if your Bank fails, you&#8217;ll hardly notice it (while the taxpayer, certainly does).  The failed bank gets a new name and off you go on Monday morning.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2013/01/big-bank-mules-target-small-bank-businesses/comment-page-1/#comment-147824</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Wed, 30 Jan 2013 01:14:47 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18091#comment-147824</guid>
		<description><![CDATA[Very true Neej;

But once a client gets onboard with me, the only things they catch are usually something a boot scan with a rescue disk can take care of. My Hiren&#039;s USB stick ain&#039;t bad either - usually a small job if they do what I tell them. I only have one stick in the mud, and I continually threaten to end support if she doesn&#039;t wake up. She knows going elsewhere will cost her dearly!

Some of the good tools like Combo Fix have been bypassed by the malware as well. This is why I like a good HIPS, where there are no signature updates or obsolete technology like that. Keeping most of the junk OFF the machine in the first place goes a LONG way! B-)]]></description>
		<content:encoded><![CDATA[<p>Very true Neej;</p>
<p>But once a client gets onboard with me, the only things they catch are usually something a boot scan with a rescue disk can take care of. My Hiren&#8217;s USB stick ain&#8217;t bad either &#8211; usually a small job if they do what I tell them. I only have one stick in the mud, and I continually threaten to end support if she doesn&#8217;t wake up. She knows going elsewhere will cost her dearly!</p>
<p>Some of the good tools like Combo Fix have been bypassed by the malware as well. This is why I like a good HIPS, where there are no signature updates or obsolete technology like that. Keeping most of the junk OFF the machine in the first place goes a LONG way! B-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Neej</title>
		<link>http://krebsonsecurity.com/2013/01/big-bank-mules-target-small-bank-businesses/comment-page-1/#comment-147821</link>
		<dc:creator>Neej</dc:creator>
		<pubDate>Wed, 30 Jan 2013 00:56:46 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18091#comment-147821</guid>
		<description><![CDATA[Heh ;) ... bad as MSSE is comparatively your probably still going to be cleaning up a lot of crap regardless of AV if your dealing with less savvy users.  Not that I&#039;d recommend using it.]]></description>
		<content:encoded><![CDATA[<p>Heh <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  &#8230; bad as MSSE is comparatively your probably still going to be cleaning up a lot of crap regardless of AV if your dealing with less savvy users.  Not that I&#8217;d recommend using it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: aknowldge</title>
		<link>http://krebsonsecurity.com/2013/01/big-bank-mules-target-small-bank-businesses/comment-page-1/#comment-147781</link>
		<dc:creator>aknowldge</dc:creator>
		<pubDate>Tue, 29 Jan 2013 22:14:33 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18091#comment-147781</guid>
		<description><![CDATA[goeastern europe go !!! well done]]></description>
		<content:encoded><![CDATA[<p>goeastern europe go !!! well done</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DD</title>
		<link>http://krebsonsecurity.com/2013/01/big-bank-mules-target-small-bank-businesses/comment-page-1/#comment-147737</link>
		<dc:creator>DD</dc:creator>
		<pubDate>Tue, 29 Jan 2013 19:24:38 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18091#comment-147737</guid>
		<description><![CDATA[JimV, I completely agree with you, but who does that?

I&#039;m sure these people will do that...now.  But prior to a major breach in security, what business spends the extra time and money to implement smart controls.  They don&#039;t, they won&#039;t.

What they will do is say &quot;What&#039;s the risk?&quot;  Translation: How can you pin that on me?  Even in that scenario I&#039;ll still collect my pension, 401k, drive a new SUV and make my house payments because I&#039;m a Payroll Manager, I&#039;m not in charge of security.   While if I add in two factor authentication or any other control that might inconvenience me (mainly by increasing my budget) that actually might impact my ability to put my kids in private school this year.

I think an interesting form of new legislation would be to require all companies, private and public to disclose how much of their overall budget goes towards information security.]]></description>
		<content:encoded><![CDATA[<p>JimV, I completely agree with you, but who does that?</p>
<p>I&#8217;m sure these people will do that&#8230;now.  But prior to a major breach in security, what business spends the extra time and money to implement smart controls.  They don&#8217;t, they won&#8217;t.</p>
<p>What they will do is say &#8220;What&#8217;s the risk?&#8221;  Translation: How can you pin that on me?  Even in that scenario I&#8217;ll still collect my pension, 401k, drive a new SUV and make my house payments because I&#8217;m a Payroll Manager, I&#8217;m not in charge of security.   While if I add in two factor authentication or any other control that might inconvenience me (mainly by increasing my budget) that actually might impact my ability to put my kids in private school this year.</p>
<p>I think an interesting form of new legislation would be to require all companies, private and public to disclose how much of their overall budget goes towards information security.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 4/23 queries in 0.005 seconds using memcached
Object Caching 388/406 objects using memcached

 Served from: krebsonsecurity.com @ 2013-05-19 14:19:11 by W3 Total Cache -->