<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: On Banking Security</title>
	<atom:link href="http://emergentchaos.com/archives/2008/07/on-banking-security.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2008/07/on-banking-security.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Tamzen</title>
		<link>http://emergentchaos.com/archives/2008/07/on-banking-security.html/comment-page-1#comment-4843</link>
		<dc:creator>Tamzen</dc:creator>
		<pubDate>Thu, 03 Jul 2008 16:49:57 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2818#comment-4843</guid>
		<description>And Blizzard sold out of the Authenticator in 2 days. They are working to ramp production up but clearly they had no idea that this would sell out so fast. And they are making it available for what looks like less than it costs them. $6.50 is really  cheap for something like this.
For them to move to this model probably means they are really bleeding out mucho $$ on tech support for people being hacked and having all their stuff stole and sold.
It was VERY funny reading on the forums where the few clueful people were trying to explain 2-factor authentication and RSA Secure ID and how, no this can&#039;t be hacked in 3 days and yes it is secure.
</description>
		<content:encoded><![CDATA[<p>And Blizzard sold out of the Authenticator in 2 days. They are working to ramp production up but clearly they had no idea that this would sell out so fast. And they are making it available for what looks like less than it costs them. $6.50 is really  cheap for something like this.<br />
For them to move to this model probably means they are really bleeding out mucho $$ on tech support for people being hacked and having all their stuff stole and sold.<br />
It was VERY funny reading on the forums where the few clueful people were trying to explain 2-factor authentication and RSA Secure ID and how, no this can&#8217;t be hacked in 3 days and yes it is secure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nick owen</title>
		<link>http://emergentchaos.com/archives/2008/07/on-banking-security.html/comment-page-1#comment-4842</link>
		<dc:creator>nick owen</dc:creator>
		<pubDate>Thu, 03 Jul 2008 13:36:31 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2818#comment-4842</guid>
		<description>As I referenced in my blog, which I am too lazy to link to directly (half day at best today :),  I think that the banks must be waiting for better technology.  They need protection from MITM attacks and MITB attacks which means mutual authentication and some form of transcation auth or signing.  It probably makes economic sense to wait for a better solution.
</description>
		<content:encoded><![CDATA[<p>As I referenced in my blog, which I am too lazy to link to directly (half day at best today :),  I think that the banks must be waiting for better technology.  They need protection from MITM attacks and MITB attacks which means mutual authentication and some form of transcation auth or signing.  It probably makes economic sense to wait for a better solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Davi Ottenheimer</title>
		<link>http://emergentchaos.com/archives/2008/07/on-banking-security.html/comment-page-1#comment-4841</link>
		<dc:creator>Davi Ottenheimer</dc:creator>
		<pubDate>Thu, 03 Jul 2008 13:13:18 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2818#comment-4841</guid>
		<description>I do not see why this makes banks look any worse, or how it is &quot;funny&quot;.
Bank issues with two-factor (e.g. usability and cost) are very different from a gaming company.
Gamers love gadgets and rapid development/change -- if you really want to play THIS game, you need to use the cool new two-factor authentication, and you have to pay for it. You can easily see how the device can become another part of the status/group symbolism.
That is an entirely different world from banking.
</description>
		<content:encoded><![CDATA[<p>I do not see why this makes banks look any worse, or how it is &#8220;funny&#8221;.<br />
Bank issues with two-factor (e.g. usability and cost) are very different from a gaming company.<br />
Gamers love gadgets and rapid development/change &#8212; if you really want to play THIS game, you need to use the cool new two-factor authentication, and you have to pay for it. You can easily see how the device can become another part of the status/group symbolism.<br />
That is an entirely different world from banking.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathaniel H.</title>
		<link>http://emergentchaos.com/archives/2008/07/on-banking-security.html/comment-page-1#comment-4840</link>
		<dc:creator>Nathaniel H.</dc:creator>
		<pubDate>Thu, 03 Jul 2008 12:07:49 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2818#comment-4840</guid>
		<description>I&#039;ve noticed this enhanced security in games published by IGG. They&#039;re one of the big players in the MMO arena and leading the way in &#039;micropayment&#039; style revenue streams. Upon logging in you can either manually type in your username and password, or use a provided virtual keyboard/keypad. I also remember something about the ability to use a PIN for character deletion. This is a far cry from the old Everquest and Ultima days, that&#039;s for sure. I guess Blizzard cares about its customers unlike most banks.
This brings up a question I have, though. Has anyone seen any research relating the economies of developing countries to the number of &#039;hacking attempts&#039; (for lack of a better phrase at the moment) coming out of those countries? I wonder if that just has to do with computer crime such as this not being worth it in the developing world, where as developing nations have a reasonably good economic sector based around selling virtual currency? I can&#039;t even begin to bring up some of the fascinating sociological issues raised by third world gold sellers.
</description>
		<content:encoded><![CDATA[<p>I&#8217;ve noticed this enhanced security in games published by IGG. They&#8217;re one of the big players in the MMO arena and leading the way in &#8216;micropayment&#8217; style revenue streams. Upon logging in you can either manually type in your username and password, or use a provided virtual keyboard/keypad. I also remember something about the ability to use a PIN for character deletion. This is a far cry from the old Everquest and Ultima days, that&#8217;s for sure. I guess Blizzard cares about its customers unlike most banks.<br />
This brings up a question I have, though. Has anyone seen any research relating the economies of developing countries to the number of &#8216;hacking attempts&#8217; (for lack of a better phrase at the moment) coming out of those countries? I wonder if that just has to do with computer crime such as this not being worth it in the developing world, where as developing nations have a reasonably good economic sector based around selling virtual currency? I can&#8217;t even begin to bring up some of the fascinating sociological issues raised by third world gold sellers.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

