<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Guarding online banking</title>
	<atom:link href="http://philwilson.org/blog/2007/11/guarding-online-banking/feed" rel="self" type="application/rss+xml" />
	<link>http://philwilson.org/blog/2007/11/guarding-online-banking</link>
	<description>a geek commodity</description>
	<lastBuildDate>Mon, 06 Sep 2010 00:21:29 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Phil Wilson</title>
		<link>http://philwilson.org/blog/2007/11/guarding-online-banking/comment-page-1#comment-1161</link>
		<dc:creator>Phil Wilson</dc:creator>
		<pubDate>Tue, 05 Feb 2008 15:21:00 +0000</pubDate>
		<guid isPermaLink="false">http://philwilson.org/blog/2007/11/guarding-online-banking#comment-1161</guid>
		<description>Just testing</description>
		<content:encoded><![CDATA[<p>Just testing</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phil Wilson</title>
		<link>http://philwilson.org/blog/2007/11/guarding-online-banking/comment-page-1#comment-1160</link>
		<dc:creator>Phil Wilson</dc:creator>
		<pubDate>Sat, 10 Nov 2007 00:05:00 +0000</pubDate>
		<guid isPermaLink="false">http://philwilson.org/blog/2007/11/guarding-online-banking#comment-1160</guid>
		<description>You get one free, and then it&#039;s £6 for each one after that. The size is a problem - if it was on my keychain I&#039;d probably be less bothered.&lt;br/&gt;&lt;br/&gt;The Barclay&#039;s Q&amp;A on this is just a disaster - on the front page there&#039;s a list of questions but they&#039;re not clickable to their answers, just a link for &quot;see the answers to these questions!&quot; and then those questions aren&#039;t the first thing on the page. And then it&#039;s in Flash. Rubbish.</description>
		<content:encoded><![CDATA[<p>You get one free, and then it&#8217;s £6 for each one after that. The size is a problem &#8211; if it was on my keychain I&#8217;d probably be less bothered.</p>
<p>The Barclay&#8217;s Q&#038;A on this is just a disaster &#8211; on the front page there&#8217;s a list of questions but they&#8217;re not clickable to their answers, just a link for &#8220;see the answers to these questions!&#8221; and then those questions aren&#8217;t the first thing on the page. And then it&#8217;s in Flash. Rubbish.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scribe</title>
		<link>http://philwilson.org/blog/2007/11/guarding-online-banking/comment-page-1#comment-1159</link>
		<dc:creator>Scribe</dc:creator>
		<pubDate>Fri, 09 Nov 2007 09:35:00 +0000</pubDate>
		<guid isPermaLink="false">http://philwilson.org/blog/2007/11/guarding-online-banking#comment-1159</guid>
		<description>The Flash-based &quot;page&quot; - presumably so they can fade text in and out like a pro - just proves to me how much Barclays don&#039;t get it at all when it comes to customers/users.&lt;br/&gt;&lt;br/&gt;Presumably the warnings that it gives you right at the bottom of the &quot;common questions&quot; page (I&#039;d cut and paste, but... hnnng) are to prevent social engineering attacks? If that&#039;s the case, isn&#039;t this just another level of &lt;i&gt;perception&lt;/i&gt; of security? I can see it would help prevent ongoing or delayed fraud, but does it prevent live man-in-the-middle relay attacks?&lt;br/&gt;&lt;br/&gt;Kind of hoping they send me one now, just to see what it&#039;s like...</description>
		<content:encoded><![CDATA[<p>The Flash-based &#8220;page&#8221; &#8211; presumably so they can fade text in and out like a pro &#8211; just proves to me how much Barclays don&#8217;t get it at all when it comes to customers/users.</p>
<p>Presumably the warnings that it gives you right at the bottom of the &#8220;common questions&#8221; page (I&#8217;d cut and paste, but&#8230; hnnng) are to prevent social engineering attacks? If that&#8217;s the case, isn&#8217;t this just another level of <i>perception</i> of security? I can see it would help prevent ongoing or delayed fraud, but does it prevent live man-in-the-middle relay attacks?</p>
<p>Kind of hoping they send me one now, just to see what it&#8217;s like&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rod Begbie</title>
		<link>http://philwilson.org/blog/2007/11/guarding-online-banking/comment-page-1#comment-1158</link>
		<dc:creator>Rod Begbie</dc:creator>
		<pubDate>Fri, 09 Nov 2007 01:02:00 +0000</pubDate>
		<guid isPermaLink="false">http://philwilson.org/blog/2007/11/guarding-online-banking#comment-1158</guid>
		<description>How many of the Pinsentry gizmos can you get?  Can you just keep phoning up and claiming you haven&#039;t received it until you have one beside every computer you use?&lt;br/&gt;&lt;br/&gt;I&#039;m quite happy to have my PayPal/eBay keychain dongle (https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/cps/general/FAQPPSecurityKey-outside),  not least because it also works with my OpenID provider, but if I had more than one, it might get a bit on the annoying side.</description>
		<content:encoded><![CDATA[<p>How many of the Pinsentry gizmos can you get?  Can you just keep phoning up and claiming you haven&#8217;t received it until you have one beside every computer you use?</p>
<p>I&#8217;m quite happy to have my PayPal/eBay keychain dongle (<a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/cps/general/FAQPPSecurityKey-outside" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/www.paypal.com/us/cgi-bin/webscr?cmd=xpt/cps/general/FAQPPSecurityKey-outside&amp;referer=');">https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/cps/general/FAQPPSecurityKey-outside</a>),  not least because it also works with my OpenID provider, but if I had more than one, it might get a bit on the annoying side.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
