<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Geek Professor &#187; Negligence</title>
	<atom:link href="http://www.thegeekprofessor.com/tag/negligence/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thegeekprofessor.com</link>
	<description>Making tech easy for everyone</description>
	<lastBuildDate>Thu, 02 Feb 2012 01:11:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Citibank Unable to Afford Secure Web Design</title>
		<link>http://www.thegeekprofessor.com/citibank-unable-to-afford-secure-web-design/</link>
		<comments>http://www.thegeekprofessor.com/citibank-unable-to-afford-secure-web-design/#comments</comments>
		<pubDate>Wed, 15 Jun 2011 11:35:02 +0000</pubDate>
		<dc:creator>Jeremy</dc:creator>
				<category><![CDATA[Big Business]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Account Security]]></category>
		<category><![CDATA[Banks]]></category>
		<category><![CDATA[Continual Stupidity]]></category>
		<category><![CDATA[Negligence]]></category>
		<category><![CDATA[Utter Failure]]></category>

		<guid isPermaLink="false">http://www.thegeekprofessor.com/?p=3791</guid>
		<description><![CDATA[If you're with Citibank, then YOU'RE WITH STUPID! When I teach, I explain how most of the breaches and problems you hear in the world aren't about clever hackers or sophisticated attackers, but instead about weak and pathetic security. This has just become my new go-to example. Basically after you logged into your account as [...]]]></description>
			<content:encoded><![CDATA[<div class='figure' style='float:left;margin-right:7px; width:208px;height:;text-align:right'><img id='img414' class=figure_img src='http://www.thegeekprofessor.com//graphics/logos/citibank.jpg' alt="If you're with Citibank, then YOU'RE WITH STUPID!"  width='200px'  height='134px' /><div class=figure_text>If you're with Citibank, then YOU'RE WITH STUPID!</div></div>

<p>When I teach, I explain how most of the breaches and problems you hear in the world aren't about clever hackers or sophisticated attackers, but instead about weak and pathetic security. This has just become my new go-to example.</p>

<blockquote>Basically after you logged into your account as a Citi customer, the URL contained a code identifying your account. All you had to do was change around the numbers and boom, you were in someone else's account.</blockquote>

<p>What that means is that if you were to look at the address in your bar at the top of the browser, it contains the name of the website you're on and (as is typical) a whole lot of other junk like this:

<p class=example>http://www.citibank.com/account.asp?were=dumbascrap&#038;we=shouldhaveknownbetter</p>

<p>One of the values in the "lots of other junk" area told Citibank who's account to show. If you just entered any random number, the website would think you were the user with that ID and show you <i>their</i> page. Even when this kind of problem was new over a decade ago, it seemed pretty dumb for major websites to be this sloppy. To think that a site run by such a large (and rich) company would make this kind of mistake would be laughable if it weren't so contemptible.</p>

 
<p>Citi, TJX wants to thank you from the bottom of their hearts for finally doing something so stupid that we can forget about <a href="tjx-data-breach-up-to-94-million-victims">their horrible mistake</a> (at least just a little).</p>

<p><a href="http://consumerist.com/2011/06/how-hackers-stole-200000-citi-accounts-by-exploiting-basic-browser-vulnerability.html">Source</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.thegeekprofessor.com/citibank-unable-to-afford-secure-web-design/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TJX Data Breach Up to 94 Million Victims</title>
		<link>http://www.thegeekprofessor.com/tjx-data-breach-up-to-94-million-victims/</link>
		<comments>http://www.thegeekprofessor.com/tjx-data-breach-up-to-94-million-victims/#comments</comments>
		<pubDate>Mon, 29 Oct 2007 11:23:48 +0000</pubDate>
		<dc:creator>Jeremy</dc:creator>
				<category><![CDATA[Big Business]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Data Abuse]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Negligence]]></category>
		<category><![CDATA[TJ Maxx]]></category>
		<category><![CDATA[TJX]]></category>
		<category><![CDATA[WEP]]></category>
		<category><![CDATA[Wireless Security]]></category>

		<guid isPermaLink="false">http://www.thegeekprofessor.com/?p=157</guid>
		<description><![CDATA[<p>TJX/TJ Maxx was one of the most spectacular examples of mass data breach in history (at the time). Read more to find out why this happened.</p>]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;ve been <a href="http://www.consumeraffairs.com/news04/2007/10/tjx_data.html">following this breach</a>, the key problem here is two part:</p>

<p>
1) TJX is the parent company of several other companies including TJ Maxx. Each of those companies shared data with TJX creating a massive database (and a single target for the hackers).
</p>

<p>
2) TJX (and others) shouldn&#8217;t have stored the credit card data in the first place and when they did, they should have used <a href="http://www.bestsecuritytips.com/news+article.storyid+226.htm">better security</a>.
</p>

<p>Though they&#8217;ll blame &#8220;clever hackers&#8221; for the breach, the fault instead lies squarely with TJX who&#8217;s business practice of storing credit cards against people&#8217;s will along with negligent use of outdated wireless encryption (WEP) first created a giant target and then then left a gaping hole for the bad guys to be able to go and get it.</p>]]></content:encoded>
			<wfw:commentRss>http://www.thegeekprofessor.com/tjx-data-breach-up-to-94-million-victims/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

