<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: DDoS Attack on Bank Hid $900,000 Cyberheist</title>
	<atom:link href="http://krebsonsecurity.com/2013/02/ddos-attack-on-bank-hid-900000-cyberheist/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2013/02/ddos-attack-on-bank-hid-900000-cyberheist/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Sun, 19 May 2013 06:15:27 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Kent</title>
		<link>http://krebsonsecurity.com/2013/02/ddos-attack-on-bank-hid-900000-cyberheist/comment-page-1/#comment-163250</link>
		<dc:creator>Kent</dc:creator>
		<pubDate>Mon, 18 Mar 2013 20:41:02 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18159#comment-163250</guid>
		<description><![CDATA[&gt;&gt;I love how my bank – BB&amp;T – only allows alpha/num characters for passwords.

Yeh, mine was doing that too - and a brokerage house I think.
I haven&#039;t checked lately, but it totally surprised me - of all the institutions you&#039;d think the money vaults would be the ones to be totally on top of it.

&gt;&gt;stupid security questions that are used for resetting your password

I&#039;ve been thinking of just making up gibberish answers to those and storing them in my password manager program when I have the time.]]></description>
		<content:encoded><![CDATA[<p>&gt;&gt;I love how my bank – BB&amp;T – only allows alpha/num characters for passwords.</p>
<p>Yeh, mine was doing that too &#8211; and a brokerage house I think.<br />
I haven&#8217;t checked lately, but it totally surprised me &#8211; of all the institutions you&#8217;d think the money vaults would be the ones to be totally on top of it.</p>
<p>&gt;&gt;stupid security questions that are used for resetting your password</p>
<p>I&#8217;ve been thinking of just making up gibberish answers to those and storing them in my password manager program when I have the time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MadMonkey</title>
		<link>http://krebsonsecurity.com/2013/02/ddos-attack-on-bank-hid-900000-cyberheist/comment-page-1/#comment-162723</link>
		<dc:creator>MadMonkey</dc:creator>
		<pubDate>Sun, 17 Mar 2013 07:09:13 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18159#comment-162723</guid>
		<description><![CDATA[What about those stupid security questions that are used for resetting your password? 

Questions like &#039;When were you born&#039; or &#039;What is your mothers maiden name&#039; don&#039;t increase security in my mind and could easily be compromised. Even if you did answer with something other than the truth we often forget what we wrote making them even less effective.]]></description>
		<content:encoded><![CDATA[<p>What about those stupid security questions that are used for resetting your password? </p>
<p>Questions like &#8216;When were you born&#8217; or &#8216;What is your mothers maiden name&#8217; don&#8217;t increase security in my mind and could easily be compromised. Even if you did answer with something other than the truth we often forget what we wrote making them even less effective.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sudon't</title>
		<link>http://krebsonsecurity.com/2013/02/ddos-attack-on-bank-hid-900000-cyberheist/comment-page-1/#comment-162623</link>
		<dc:creator>sudon't</dc:creator>
		<pubDate>Sat, 16 Mar 2013 21:21:58 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18159#comment-162623</guid>
		<description><![CDATA[I love how my bank - BB&amp;T - only allows alpha/num characters for passwords. Nothing like forcing the few customers who&#039;ll use strong passwords to dumb it down.]]></description>
		<content:encoded><![CDATA[<p>I love how my bank &#8211; BB&amp;T &#8211; only allows alpha/num characters for passwords. Nothing like forcing the few customers who&#8217;ll use strong passwords to dumb it down.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MadMonkey</title>
		<link>http://krebsonsecurity.com/2013/02/ddos-attack-on-bank-hid-900000-cyberheist/comment-page-1/#comment-160740</link>
		<dc:creator>MadMonkey</dc:creator>
		<pubDate>Mon, 11 Mar 2013 12:46:11 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18159#comment-160740</guid>
		<description><![CDATA[The very fact that you&#039;re doubting Mr Krebs probably means you have little idea who he really is! Lets just say that he can get his stories straight from the horses (mules) mouth.  

@Mr Krebs: Great idea about using a Live CD for doing your banking online!

But what about KeyScrambler, I use it in my browser to scramble my keyboard input? 

http://www.qfxsoftware.com/]]></description>
		<content:encoded><![CDATA[<p>The very fact that you&#8217;re doubting Mr Krebs probably means you have little idea who he really is! Lets just say that he can get his stories straight from the horses (mules) mouth.  </p>
<p>@Mr Krebs: Great idea about using a Live CD for doing your banking online!</p>
<p>But what about KeyScrambler, I use it in my browser to scramble my keyboard input? </p>
<p><a href="http://www.qfxsoftware.com/" rel="nofollow">http://www.qfxsoftware.com/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kent</title>
		<link>http://krebsonsecurity.com/2013/02/ddos-attack-on-bank-hid-900000-cyberheist/comment-page-1/#comment-160139</link>
		<dc:creator>Kent</dc:creator>
		<pubDate>Fri, 08 Mar 2013 16:21:49 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18159#comment-160139</guid>
		<description><![CDATA[. . . because no one had ever found it before.]]></description>
		<content:encoded><![CDATA[<p>. . . because no one had ever found it before.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kent</title>
		<link>http://krebsonsecurity.com/2013/02/ddos-attack-on-bank-hid-900000-cyberheist/comment-page-1/#comment-160138</link>
		<dc:creator>Kent</dc:creator>
		<pubDate>Fri, 08 Mar 2013 16:20:51 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18159#comment-160138</guid>
		<description><![CDATA[Generally it&#039;s probably not a great practice to judge the veracity of investigative reporting by how often it&#039;s already been covered by other media. 
James Marshall who first found gold at Sutter&#039;s Mill in California in 1848 probably did not spend a lot of time wondering if it was really gold or not.]]></description>
		<content:encoded><![CDATA[<p>Generally it&#8217;s probably not a great practice to judge the veracity of investigative reporting by how often it&#8217;s already been covered by other media.<br />
James Marshall who first found gold at Sutter&#8217;s Mill in California in 1848 probably did not spend a lot of time wondering if it was really gold or not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BrianKrebs</title>
		<link>http://krebsonsecurity.com/2013/02/ddos-attack-on-bank-hid-900000-cyberheist/comment-page-1/#comment-160088</link>
		<dc:creator>BrianKrebs</dc:creator>
		<pubDate>Fri, 08 Mar 2013 12:47:06 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18159#comment-160088</guid>
		<description><![CDATA[The story is made up because the Sacramento Bee didn&#039;t cover it? That&#039;s rich. 

Maybe you should take the time to read the 80-some other stories on cyberheists that I&#039;ve broken over the last 4 years. You can see some of them here:

http://krebsonsecurity.com/category/smallbizvictims/]]></description>
		<content:encoded><![CDATA[<p>The story is made up because the Sacramento Bee didn&#8217;t cover it? That&#8217;s rich. </p>
<p>Maybe you should take the time to read the 80-some other stories on cyberheists that I&#8217;ve broken over the last 4 years. You can see some of them here:</p>
<p><a href="http://krebsonsecurity.com/category/smallbizvictims/" rel="nofollow">http://krebsonsecurity.com/category/smallbizvictims/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Doubting Thomas</title>
		<link>http://krebsonsecurity.com/2013/02/ddos-attack-on-bank-hid-900000-cyberheist/comment-page-1/#comment-159990</link>
		<dc:creator>Doubting Thomas</dc:creator>
		<pubDate>Fri, 08 Mar 2013 05:43:46 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18159#comment-159990</guid>
		<description><![CDATA[How come the Sacramento Bee never reported any of this?  Makes me wonder a bit if the whole thing is really true.  Not that the Bee is on top of everything, but if you search Ascent Builders there you only get 3 innocuous hits.  And if you google the name you only get this guy&#039;s blog.  Seems that a bunch of cyber guys would be commenting on this.]]></description>
		<content:encoded><![CDATA[<p>How come the Sacramento Bee never reported any of this?  Makes me wonder a bit if the whole thing is really true.  Not that the Bee is on top of everything, but if you search Ascent Builders there you only get 3 innocuous hits.  And if you google the name you only get this guy&#8217;s blog.  Seems that a bunch of cyber guys would be commenting on this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SteveCr48</title>
		<link>http://krebsonsecurity.com/2013/02/ddos-attack-on-bank-hid-900000-cyberheist/comment-page-1/#comment-157591</link>
		<dc:creator>SteveCr48</dc:creator>
		<pubDate>Wed, 27 Feb 2013 10:43:56 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18159#comment-157591</guid>
		<description><![CDATA[I heard you on Security Now, and now found your blog and website. Excellent!

You might consider recommending a Chromebook as a dedicated access machine. They&#039;re inexpensive, easy to use, and very secure. (Glad to answer questions/help if I can.)]]></description>
		<content:encoded><![CDATA[<p>I heard you on Security Now, and now found your blog and website. Excellent!</p>
<p>You might consider recommending a Chromebook as a dedicated access machine. They&#8217;re inexpensive, easy to use, and very secure. (Glad to answer questions/help if I can.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pmshah</title>
		<link>http://krebsonsecurity.com/2013/02/ddos-attack-on-bank-hid-900000-cyberheist/comment-page-1/#comment-157532</link>
		<dc:creator>pmshah</dc:creator>
		<pubDate>Wed, 27 Feb 2013 05:48:07 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=18159#comment-157532</guid>
		<description><![CDATA[I use a live boot CD of Puppy linux to make all my critical transactions. I don&#039;t do anything else with it !]]></description>
		<content:encoded><![CDATA[<p>I use a live boot CD of Puppy linux to make all my critical transactions. I don&#8217;t do anything else with it !</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 6/19 queries in 0.004 seconds using memcached
Object Caching 384/394 objects using memcached

 Served from: krebsonsecurity.com @ 2013-05-19 15:29:04 by W3 Total Cache -->