<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>I Drivel &#187; security</title>
	<atom:link href="http://blog.justinlintz.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.justinlintz.com</link>
	<description>whatever comes to mind</description>
	<lastBuildDate>Wed, 12 Oct 2011 01:37:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Commerce Bank&#8217;s huge security failure</title>
		<link>http://blog.justinlintz.com/2009/09/commerce-banks-huge-security-failure/</link>
		<comments>http://blog.justinlintz.com/2009/09/commerce-banks-huge-security-failure/#comments</comments>
		<pubDate>Tue, 29 Sep 2009 02:31:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[observations]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.justinlintz.com/?p=43</guid>
		<description><![CDATA[<p>My checking account is part of Commerce Bank which about a year ago was bought out by TD Bank. Up until this summer their site http://www.commerceonline.com still worked for all my online banking. The theme had changed on the site but all the same login functionality was there. Then September 20th rolled around and <span style="color:#777"> . . . &#8594; Read More: <a href="http://blog.justinlintz.com/2009/09/commerce-banks-huge-security-failure/">Commerce Bank&#8217;s huge security failure</a></span>]]></description>
			<content:encoded><![CDATA[<p>My checking account is part of Commerce Bank which about a year ago was bought out by TD Bank.  Up until this summer their site <a href="http://www.commerceonline.com"> http://www.commerceonline.com</a> still worked for all my online banking.  The theme had changed on the site but all the same login functionality was there.  Then September 20th rolled around and I goto log into my account to check on some things only to find that <a href="http://www.commerceonline.com"> http://www.commerceonline.com</a> now is a search engine spam page?!  A whois lookup on commerceonline.com shows&#8230;</p>
<blockquote><p>% whois commerceonline.com</p>
<p>Whois Server Version 2.0</p>
<p>Domain names in the .com and .net domains can now be registered<br />
with many different competing registrars. Go to http://www.internic.net<br />
for detailed information.</p>
<p>   Domain Name: COMMERCEONLINE.COM<br />
   Registrar: CYDENTITY, INC. D/B/A CYPACK.COM<br />
   Whois Server: whois.cypack.com<br />
   Referral URL: http://www.cypack.com<br />
   Name Server: NS1.TRAFFICZ.COM<br />
   Name Server: NS2.TRAFFICZ.COM<br />
   Status: clientTransferProhibited<br />
   Updated Date: 20-sep-2009<br />
   Creation Date: 30-jul-1996<br />
   Expiration Date: 29-jul-2011</p></blockquote>
<p>For the non-technical person, they let their fucking domain name expire.  If they did this purposely they don&#8217;t deserve to be a bank, if this slipped passed someone&#8230; they don&#8217;t deserve to be a bank.  Why this is bad you ask?  Right now there is nothing preventing the owner of the site from going to <a href="http://web.archive.org/web/20080822104136/http://www.commerceonline.com/">web archive of commerceonline.com</a> and just copying the old look of the site and stealing X number of identities by faking a registration page or login page.  </p>
<p>Besides the whole fuckup of their old domain, apparently the login mechanism is different on <a href="http://www.tdbank.com">tdbank</a> now and my login information doesn&#8217;t work.  Yet I can&#8217;t sign up for a new account as it says I&#8217;m already registered.  I&#8217;m seriously considering switching off TD Bank because of this <a href="http://www.pisspoorplanning.com">pisspoorplanning</a> . </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.justinlintz.com/2009/09/commerce-banks-huge-security-failure/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

