<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New Log-In Process Coming to EmigrantDirect</title>
	<atom:link href="http://www.consumerismcommentary.com/2007/11/30/new-log-in-process-coming-to-emigrantdirect/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.consumerismcommentary.com/2007/11/30/new-log-in-process-coming-to-emigrantdirect/</link>
	<description>A premiere personal finance blog, established 2003. Within, Flexo discusses his own experiences with money, and he and other authors comment on a wide range of personal finance topics.</description>
	<lastBuildDate>Sat, 21 Nov 2009 16:42:00 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Toby</title>
		<link>http://www.consumerismcommentary.com/2007/11/30/new-log-in-process-coming-to-emigrantdirect/#comment-127748</link>
		<dc:creator>Toby</dc:creator>
		<pubDate>Thu, 13 Dec 2007 06:22:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.consumerismcommentary.com/2007/11/30/new-log-in-process-coming-to-emigrantdirect/#comment-127748</guid>
		<description>@ general:  I agree that thieves tend to go for low-hanging fruit before tackling something more sophisticated.  However, I think you are over-estimated the amount of sophistication and complexity inherent in these new &quot;security measures.&quot;

In our industry we call it &quot;security theater&quot;.  Looks great.  Looks secure.  Makes for great press-releases.  Doesn&#039;t do a lick of good as far as increasing security.

My job is not to make things completely secure.  It is to balance the risk versus the cost of security measures.  So when I say that these new measures don&#039;t do any good, I mean that the total cost (monetary, user experience, etc.) is not worth the &quot;increased security&quot; (trivial).  The money these companies spend is not to increase security, rather it is to increase the *appearance* of security to their customers.  Given that this increases customer trust it is still probably money well-spent but don&#039;t, for a second, think that they&#039;ve improved security in any meaningful way.

Also, I don&#039;t think you realize the threat that is out there.  It&#039;s not little Johnny hacking your computer from his mommy&#039;s basement anymore.  Organized crime is out there.  They are well-funded.  They have professional programmers writing their software and it is really well planned and well implemented.  

Virus signature databases doubled in size over the past year and anti-virus vendors  are struggling to keep up.  An estimated 25% of the 600  million computers on the Internet today are thought to be parts of  botnets.  150 million zombie machines out there that might do anything from attack a site, to resend spam, to collect your personal information.  It is considered by many to be a virtual pandemic.

So pardon me if I don&#039;t jump up and give a standing ovation to an under-arm-fart-noise rendition of Beethoven&#039;s 5th.  I think I&#039;ll hold my applause for a real performance.</description>
		<content:encoded><![CDATA[<p>@ general:  I agree that thieves tend to go for low-hanging fruit before tackling something more sophisticated.  However, I think you are over-estimated the amount of sophistication and complexity inherent in these new &#8220;security measures.&#8221;</p>
<p>In our industry we call it &#8220;security theater&#8221;.  Looks great.  Looks secure.  Makes for great press-releases.  Doesn&#8217;t do a lick of good as far as increasing security.</p>
<p>My job is not to make things completely secure.  It is to balance the risk versus the cost of security measures.  So when I say that these new measures don&#8217;t do any good, I mean that the total cost (monetary, user experience, etc.) is not worth the &#8220;increased security&#8221; (trivial).  The money these companies spend is not to increase security, rather it is to increase the *appearance* of security to their customers.  Given that this increases customer trust it is still probably money well-spent but don&#8217;t, for a second, think that they&#8217;ve improved security in any meaningful way.</p>
<p>Also, I don&#8217;t think you realize the threat that is out there.  It&#8217;s not little Johnny hacking your computer from his mommy&#8217;s basement anymore.  Organized crime is out there.  They are well-funded.  They have professional programmers writing their software and it is really well planned and well implemented.  </p>
<p>Virus signature databases doubled in size over the past year and anti-virus vendors  are struggling to keep up.  An estimated 25% of the 600  million computers on the Internet today are thought to be parts of  botnets.  150 million zombie machines out there that might do anything from attack a site, to resend spam, to collect your personal information.  It is considered by many to be a virtual pandemic.</p>
<p>So pardon me if I don&#8217;t jump up and give a standing ovation to an under-arm-fart-noise rendition of Beethoven&#8217;s 5th.  I think I&#8217;ll hold my applause for a real performance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: general</title>
		<link>http://www.consumerismcommentary.com/2007/11/30/new-log-in-process-coming-to-emigrantdirect/#comment-127285</link>
		<dc:creator>general</dc:creator>
		<pubDate>Tue, 11 Dec 2007 15:44:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.consumerismcommentary.com/2007/11/30/new-log-in-process-coming-to-emigrantdirect/#comment-127285</guid>
		<description>@ Toby: As an information security professional, you then know that most thieves and unsavory characters tend to go for low hanging fruit before tackling something more sophisticated.  

The point behind the modifications isn&#039;t that the system is absolutely secure, it&#039;s simply that they&#039;ve added extra layers of security to make it just a little more difficult for the majority of script kiddies.  

The reality is that if someone wants your information bad enough, they&#039;re going to get it.   It doesn&#039;t matter what you do, or how you do it.  The key here is that it now takes more effort and more technical know-how to get to what they&#039;re after.  

As you&#039;re aware, the process of creating security measures to defend against security breaches is very cyclic by nature.  Sooner or later the thieves ramp up on the new security measures, and then the business has to adapt and create a new hurdle.    Then we start over again.

It&#039;s an improvement, and as an information security professional, I would expect you to applaud the effort to at least improve security based upon what you know of the business involved, and the nature of security in a digital world.

Thanks.</description>
		<content:encoded><![CDATA[<p>@ Toby: As an information security professional, you then know that most thieves and unsavory characters tend to go for low hanging fruit before tackling something more sophisticated.  </p>
<p>The point behind the modifications isn&#8217;t that the system is absolutely secure, it&#8217;s simply that they&#8217;ve added extra layers of security to make it just a little more difficult for the majority of script kiddies.  </p>
<p>The reality is that if someone wants your information bad enough, they&#8217;re going to get it.   It doesn&#8217;t matter what you do, or how you do it.  The key here is that it now takes more effort and more technical know-how to get to what they&#8217;re after.  </p>
<p>As you&#8217;re aware, the process of creating security measures to defend against security breaches is very cyclic by nature.  Sooner or later the thieves ramp up on the new security measures, and then the business has to adapt and create a new hurdle.    Then we start over again.</p>
<p>It&#8217;s an improvement, and as an information security professional, I would expect you to applaud the effort to at least improve security based upon what you know of the business involved, and the nature of security in a digital world.</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Toby</title>
		<link>http://www.consumerismcommentary.com/2007/11/30/new-log-in-process-coming-to-emigrantdirect/#comment-125840</link>
		<dc:creator>Toby</dc:creator>
		<pubDate>Tue, 04 Dec 2007 21:19:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.consumerismcommentary.com/2007/11/30/new-log-in-process-coming-to-emigrantdirect/#comment-125840</guid>
		<description>@ Madison:  The point is not just to have a picture associated with your account.  It is supposed to be the combination of your picture and word or phrase that is supposed to ensure that you are communicating your your bank and not a phishing site.

When you are setting up the pictures, I always use meaningful phrases that will jog my memory when I am logging in.  For instance, if you have a picture of an orange.  Don&#039;t use the phrase &quot;An orange&quot; associated with it.  Instead use something meaningful like a song lyric, &quot;I&#039;ve got my spine, I&#039;ve got my orange crush.&quot;  Now, even though you may not remember which picture is which, the phrase should hopefully jog your memory.</description>
		<content:encoded><![CDATA[<p>@ Madison:  The point is not just to have a picture associated with your account.  It is supposed to be the combination of your picture and word or phrase that is supposed to ensure that you are communicating your your bank and not a phishing site.</p>
<p>When you are setting up the pictures, I always use meaningful phrases that will jog my memory when I am logging in.  For instance, if you have a picture of an orange.  Don&#8217;t use the phrase &#8220;An orange&#8221; associated with it.  Instead use something meaningful like a song lyric, &#8220;I&#8217;ve got my spine, I&#8217;ve got my orange crush.&#8221;  Now, even though you may not remember which picture is which, the phrase should hopefully jog your memory.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Madison</title>
		<link>http://www.consumerismcommentary.com/2007/11/30/new-log-in-process-coming-to-emigrantdirect/#comment-125820</link>
		<dc:creator>Madison</dc:creator>
		<pubDate>Tue, 04 Dec 2007 15:57:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.consumerismcommentary.com/2007/11/30/new-log-in-process-coming-to-emigrantdirect/#comment-125820</guid>
		<description>Isn&#039;t the idea of the pictures that I am supposed to recognize them? We have so many bank accounts, I can&#039;t even remember which pictures go to which accounts.</description>
		<content:encoded><![CDATA[<p>Isn&#8217;t the idea of the pictures that I am supposed to recognize them? We have so many bank accounts, I can&#8217;t even remember which pictures go to which accounts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Toby</title>
		<link>http://www.consumerismcommentary.com/2007/11/30/new-log-in-process-coming-to-emigrantdirect/#comment-125472</link>
		<dc:creator>Toby</dc:creator>
		<pubDate>Mon, 03 Dec 2007 04:10:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.consumerismcommentary.com/2007/11/30/new-log-in-process-coming-to-emigrantdirect/#comment-125472</guid>
		<description>I hate to be a killjoy but, as an information security professional, I can tell you that the type of login you are talking about does little to actually protect your information from determined criminals.  Within hours of ING deploying their new login scheme there were keyloggers with a new &quot;feature&quot; that would capture small sections of your screen around your mouse pointer when you clicked it which allowed the criminals to capture your PIN even if you use the on-screen number pad.

In addition, once the malicious software is on your system they can steal the cookies from your browser that store info about those pictures that everyone is using or stick in the middle and conduct their own electronic transfers.  It&#039;s a lot of sizzle and very little steak, if you know what I mean.</description>
		<content:encoded><![CDATA[<p>I hate to be a killjoy but, as an information security professional, I can tell you that the type of login you are talking about does little to actually protect your information from determined criminals.  Within hours of ING deploying their new login scheme there were keyloggers with a new &#8220;feature&#8221; that would capture small sections of your screen around your mouse pointer when you clicked it which allowed the criminals to capture your PIN even if you use the on-screen number pad.</p>
<p>In addition, once the malicious software is on your system they can steal the cookies from your browser that store info about those pictures that everyone is using or stick in the middle and conduct their own electronic transfers.  It&#8217;s a lot of sizzle and very little steak, if you know what I mean.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
