<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Geek Professor &#187; Banks</title>
	<atom:link href="http://www.thegeekprofessor.com/tag/banks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thegeekprofessor.com</link>
	<description>Making tech easy for everyone</description>
	<lastBuildDate>Thu, 02 Feb 2012 01:11:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Citibank Unable to Afford Secure Web Design</title>
		<link>http://www.thegeekprofessor.com/citibank-unable-to-afford-secure-web-design/</link>
		<comments>http://www.thegeekprofessor.com/citibank-unable-to-afford-secure-web-design/#comments</comments>
		<pubDate>Wed, 15 Jun 2011 11:35:02 +0000</pubDate>
		<dc:creator>Jeremy</dc:creator>
				<category><![CDATA[Big Business]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Account Security]]></category>
		<category><![CDATA[Banks]]></category>
		<category><![CDATA[Continual Stupidity]]></category>
		<category><![CDATA[Negligence]]></category>
		<category><![CDATA[Utter Failure]]></category>

		<guid isPermaLink="false">http://www.thegeekprofessor.com/?p=3791</guid>
		<description><![CDATA[If you're with Citibank, then YOU'RE WITH STUPID! When I teach, I explain how most of the breaches and problems you hear in the world aren't about clever hackers or sophisticated attackers, but instead about weak and pathetic security. This has just become my new go-to example. Basically after you logged into your account as [...]]]></description>
			<content:encoded><![CDATA[<div class='figure' style='float:left;margin-right:7px; width:208px;height:;text-align:right'><img id='img292' class=figure_img src='http://www.thegeekprofessor.com//graphics/logos/citibank.jpg' alt="If you're with Citibank, then YOU'RE WITH STUPID!"  width='200px'  height='134px' /><div class=figure_text>If you're with Citibank, then YOU'RE WITH STUPID!</div></div>

<p>When I teach, I explain how most of the breaches and problems you hear in the world aren't about clever hackers or sophisticated attackers, but instead about weak and pathetic security. This has just become my new go-to example.</p>

<blockquote>Basically after you logged into your account as a Citi customer, the URL contained a code identifying your account. All you had to do was change around the numbers and boom, you were in someone else's account.</blockquote>

<p>What that means is that if you were to look at the address in your bar at the top of the browser, it contains the name of the website you're on and (as is typical) a whole lot of other junk like this:

<p class=example>http://www.citibank.com/account.asp?were=dumbascrap&#038;we=shouldhaveknownbetter</p>

<p>One of the values in the "lots of other junk" area told Citibank who's account to show. If you just entered any random number, the website would think you were the user with that ID and show you <i>their</i> page. Even when this kind of problem was new over a decade ago, it seemed pretty dumb for major websites to be this sloppy. To think that a site run by such a large (and rich) company would make this kind of mistake would be laughable if it weren't so contemptible.</p>

 
<p>Citi, TJX wants to thank you from the bottom of their hearts for finally doing something so stupid that we can forget about <a href="tjx-data-breach-up-to-94-million-victims">their horrible mistake</a> (at least just a little).</p>

<p><a href="http://consumerist.com/2011/06/how-hackers-stole-200000-citi-accounts-by-exploiting-basic-browser-vulnerability.html">Source</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.thegeekprofessor.com/citibank-unable-to-afford-secure-web-design/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wikileaks Prepares; Bank of America Panics</title>
		<link>http://www.thegeekprofessor.com/wikileaks-prepares-bank-of-america-panics/</link>
		<comments>http://www.thegeekprofessor.com/wikileaks-prepares-bank-of-america-panics/#comments</comments>
		<pubDate>Thu, 20 Jan 2011 14:26:29 +0000</pubDate>
		<dc:creator>Jeremy</dc:creator>
				<category><![CDATA[Businesses and Government]]></category>
		<category><![CDATA[Bank of America]]></category>
		<category><![CDATA[Banks]]></category>
		<category><![CDATA[Money]]></category>
		<category><![CDATA[Wikileaks]]></category>

		<guid isPermaLink="false">http://www.thegeekprofessor.com/?p=2084</guid>
		<description><![CDATA[<p>Bank of America is getting ready for the storm if and when Wikileaks exposes... something.</p>]]></description>
			<content:encoded><![CDATA[<div class='figure' style='float:left;margin-right:7px; width:296px;height:;text-align:right'><img id='img293' class=figure_img src='http://www.thegeekprofessor.com//graphics/posts/2009.10/bad_bank.jpg' alt=""  width='288px'  height='192px' /><div class=figure_text></div></div>

<p>I'm fairly ambivalent about the whole Wikileaks issue. I've long been a supporter of whistleblowing in general as companies and the governement should be held accountable for abuses and wrong-doing and often it's only fully public scandals that allow that to happen (though sometimes not even then).</p>

<p>Anyway, as to whether Wikileaks has done anything wrong, one must first ask if there was anything posted that caused significantly more harm than good (<a href="http://www.salon.com/news/opinion/glenn_greenwald/2011/01/19/wikileaks/index.html">which so far has been a "no" it seems</a>).</p>

<p>But to the point, Wikileaks is expected to release a lot of data about Bank of America very soon. There's a lot of speculation, but more interestingly, there are reports that <a href="http://www.alternet.org/economy/149555/what_does_wikileaks_have_on_bank_of_america/">Bank of America is preparing focused teams to respond to whatever drops when it drops</a>.</p>

<p>I look forward to seeing how slime covered that rock is when it's lifted.</p>]]></content:encoded>
			<wfw:commentRss>http://www.thegeekprofessor.com/wikileaks-prepares-bank-of-america-panics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Have Fun With Secret Questions</title>
		<link>http://www.thegeekprofessor.com/have-fun-with-secret-questions/</link>
		<comments>http://www.thegeekprofessor.com/have-fun-with-secret-questions/#comments</comments>
		<pubDate>Mon, 03 May 2010 13:39:12 +0000</pubDate>
		<dc:creator>Jeremy</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Banks]]></category>
		<category><![CDATA[Telephone Challenge Questions]]></category>

		<guid isPermaLink="false">http://www.thegeekprofessor.com/?p=1446</guid>
		<description><![CDATA[<p>You can have a lot of fun with the system if you think outside the box.</p>]]></description>
			<content:encoded><![CDATA[<div class='figure' style='float:right;margin-left:7px; width:296px;height:;text-align:right'><img id='img294' class=figure_img src='http://www.thegeekprofessor.com//graphics/money/bad_bank.jpg' alt=""  width='288px'  height='192px' /><div class=figure_text></div></div><p>Sometimes when you set up an account with a company, they'll let you set a question and the answer. Then when you call in, the operator will read the question YOU WROTE and you get to provide the response. This has the potential to be highly amusing if done right:</p>

<p>
<strong>Q:</strong> What the hell is your f***ing problem, sir?<br/>
<strong>A:</strong> This is completely inappropriate and I'd like to speak to your supervisor.
</p>

<p>
<strong>Q:</strong> I've been embezzling hundreds of thousands of dollars from my employer, and I don't care who knows it.<br/>
<strong>A:</strong> It's a good thing they're recording this call, because I'm going to have to report you.
</p>

<p>
<strong>Q:</strong> Are you really who you say you are?<br/>
<strong>A:</strong> No, I am a Russian identity thief.
</p>

<p><a href="http://www.schneier.com/blog/archives/2010/04/fun_with_secret.html#comments">Check out a ton more here</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.thegeekprofessor.com/have-fun-with-secret-questions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Control Your Online Banking With Twitter. Seriously!?</title>
		<link>http://www.thegeekprofessor.com/control-your-online-banking-with-twitter-seriously/</link>
		<comments>http://www.thegeekprofessor.com/control-your-online-banking-with-twitter-seriously/#comments</comments>
		<pubDate>Tue, 29 Sep 2009 12:21:31 +0000</pubDate>
		<dc:creator>Jeremy</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Banks]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://www.thegeekprofessor.com/?p=361</guid>
		<description><![CDATA[<p>Coming soon: Twitter your bank account into oblivion</p>]]></description>
			<content:encoded><![CDATA[<blockquote>With tweetMyMoney, you can monitor your account balance, deposits, withdrawals, holds and cleared checks with simple commands. <strong>And, you can even transfer funds within your account</strong>. It’s all available on Twitter, 24/7! And, the best part is, our tweetMyMoney service is free!</blockquote>

<p>(Emphasis mine)</p>

<div class='figure' style='float:right;margin-left:7px; width:229px;height:;text-align:right'><img id='img295' class=figure_img src='http://www.thegeekprofessor.com//graphics/posts/2009.09/vantage_twitter_banking.jpg' alt="Hello Twitter banking, goodbye money."  width='221px'  height='115px' /><div class=figure_text>Hello Twitter banking, goodbye money.</div></div><p><a href="http://www.vcu.com/content/20090925/myvantage-goes-mobile-first-its-kind-solution">Why anyone thought this was a good idea, I don't know</a>. Granted, you can't transfer money to OTHER accounts, only "within you account", but someone who breaks into your twitter account can still get a lot of information about you and move your money around causing you serious overdraft fees.</p>

<p>The issue at heart here is that getting information about your account and moving money around only requires the security of your Twitter account (which isn't to say much). How many people put strong passwords on their Twitter like they do the bank? How much effort does Twitter put into their security?</p>

<p>I think the idea of alerts to your phone is kind of cool, but maybe the bank should have set up its own Twitter-like messaging service instead of using a public one that's a big fat target of <a href="http://news.cnet.com/twitter-phishing-scam-may-be-spreading/">bad</a> <a href="http://www.scambusters.org/twitterscam.html">guys</a> <a href="http://www.readwriteweb.com/archives/stalkdaily_a_new_twitter_virus_on_the_loose.php">already</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.thegeekprofessor.com/control-your-online-banking-with-twitter-seriously/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

