<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Citigroup hacked: data for 200,000 or more US Citibank customers&#160;breached</title>
	<atom:link href="http://boingboing.net/2011/06/09/citigroup-hacked-dat.html/feed" rel="self" type="application/rss+xml" />
	<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html</link>
	<description>Brain candy for Happy Mutants</description>
	<lastBuildDate>Thu, 23 May 2013 01:52:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: SamSam</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1134126</link>
		<dc:creator>SamSam</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1134126</guid>
		<description>And I tried a 16-character password and it seemed to stick.

So not only do they have the worst restrictions on picking passwords -- almost every one of which makes your password less secure -- but they don&#039;t bother to implement their own restrictions. Somehow that makes me feel worse.

Hmmm... what do you bet that the idea was &quot;wait! What if we need to tell people their passwords over the phone! We can&#039;t use zeros, what if we read them as O&#039;s? And how are you supposed to pronounce characters like ^ anyway -- we need to ban those. And no one wants to have to read out a 13-character password!&quot;</description>
		<content:encoded><![CDATA[<p>And I tried a 16-character password and it seemed to stick.</p>
<p>So not only do they have the worst restrictions on picking passwords &#8212; almost every one of which makes your password less secure &#8212; but they don&#8217;t bother to implement their own restrictions. Somehow that makes me feel worse.</p>
<p>Hmmm&#8230; what do you bet that the idea was &#8220;wait! What if we need to tell people their passwords over the phone! We can&#8217;t use zeros, what if we read them as O&#8217;s? And how are you supposed to pronounce characters like ^ anyway &#8212; we need to ban those. And no one wants to have to read out a 13-character password!&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1133902</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1133902</guid>
		<description>Citigroup bought the repeal of Glass-Steagal in order to retroactively legalize their purchase of Traveler&#039;s, and that&#039;s what led to TARP and the economic mess the whole world is in right now.

http://www.pbs.org/wgbh/pages/frontline/shows/wallstreet/weill/demise.html

Citigroup is greedy and corrupt, and spreads corruption and evil in its wake.</description>
		<content:encoded><![CDATA[<p>Citigroup bought the repeal of Glass-Steagal in order to retroactively legalize their purchase of Traveler&#8217;s, and that&#8217;s what led to TARP and the economic mess the whole world is in right now.</p>
<p><a href="http://www.pbs.org/wgbh/pages/frontline/shows/wallstreet/weill/demise.html" rel="nofollow">http://www.pbs.org/wgbh/pages/frontline/shows/wallstreet/weill/demise.html</a></p>
<p>Citigroup is greedy and corrupt, and spreads corruption and evil in its wake.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chong</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1133903</link>
		<dc:creator>Chong</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1133903</guid>
		<description>Any news on who was behind it? Only had a quick skim of the linked articles so I apologise if I missed it.</description>
		<content:encoded><![CDATA[<p>Any news on who was behind it? Only had a quick skim of the linked articles so I apologise if I missed it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MrJM</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1133904</link>
		<dc:creator>MrJM</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1133904</guid>
		<description>My local credit union has never been hacked for the secure data of its customers.

Just saying.
</description>
		<content:encoded><![CDATA[<p>My local credit union has never been hacked for the secure data of its customers.</p>
<p>Just saying.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1134426</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1134426</guid>
		<description>I, too, like my credit union, but come on folks- do you think their online security is any better?  The size of the corporation doesn&#039;t matter as much as you think it does when it comes to online security.</description>
		<content:encoded><![CDATA[<p>I, too, like my credit union, but come on folks- do you think their online security is any better?  The size of the corporation doesn&#8217;t matter as much as you think it does when it comes to online security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SamSam</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1133935</link>
		<dc:creator>SamSam</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1133935</guid>
		<description>Is there any way on earth now that we can avoid losing our information to stupid websites with stupid bad internet security? If we want to live in the modern world and bank and stuff, of course.

I just rushed over to change my password, don&#039;t know how much it will help.

FWIW, here are the inane password requirements Citibank forces you to follow:

&lt;blockquote&gt;
To create a secure password for your account, follow these quick and simple Password Guidelines:
* Must include a combination of letters and numbers only  // &lt;i&gt;ok, so explicitly disallowing other characters -- which are no harder to store or hash!!! -- makes us less safe&lt;/i&gt;
* Must be 6 to 12 characters // &lt;i&gt;setting a top limit of 12 characters -- what, 13 characters is too big to store on your server??? -- makes us less safe&lt;/i&gt;
* Cannot begin with a zero // &lt;i&gt;adding arbitrary rules limits the number of passwords, making us less safe&lt;/i&gt;
* Cannot include spaces // &lt;i&gt;a space is just a character -- it&#039;s no harder to store or hash -- excluding it makes us less safe&lt;/i&gt;
* Cannot have more than 2 consecutive characters (for example, 222 or MMM, etc) // &lt;i&gt;adding arbitrary rules limits the number of passwords, making us less safe&lt;/i&gt;
&lt;/blockquote&gt;

DUM DUM DUM</description>
		<content:encoded><![CDATA[<p>Is there any way on earth now that we can avoid losing our information to stupid websites with stupid bad internet security? If we want to live in the modern world and bank and stuff, of course.</p>
<p>I just rushed over to change my password, don&#8217;t know how much it will help.</p>
<p>FWIW, here are the inane password requirements Citibank forces you to follow:</p>
<blockquote><p>
To create a secure password for your account, follow these quick and simple Password Guidelines:<br />
* Must include a combination of letters and numbers only  // <i>ok, so explicitly disallowing other characters &#8212; which are no harder to store or hash!!! &#8212; makes us less safe</i><br />
* Must be 6 to 12 characters // <i>setting a top limit of 12 characters &#8212; what, 13 characters is too big to store on your server??? &#8212; makes us less safe</i><br />
* Cannot begin with a zero // <i>adding arbitrary rules limits the number of passwords, making us less safe</i><br />
* Cannot include spaces // <i>a space is just a character &#8212; it&#8217;s no harder to store or hash &#8212; excluding it makes us less safe</i><br />
* Cannot have more than 2 consecutive characters (for example, 222 or MMM, etc) // <i>adding arbitrary rules limits the number of passwords, making us less safe</i>
</p></blockquote>
<p>DUM DUM DUM</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1133941</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1133941</guid>
		<description>I stopped doing business with Citibank three years ago, after my card data was stolen for the third time. On that third occasion, fraudulent transactions began appearing on a newly-issued debit card DAYS BEFORE THE CARD WAS ACTIVATED. I concluded that (a) Citi&#039;s security was fucked; or (b) Citi itself was engaging in broad-scale intentional fucking of its customers; or (c) both. 

Switched entirely to my credit union. Zero problems since then. </description>
		<content:encoded><![CDATA[<p>I stopped doing business with Citibank three years ago, after my card data was stolen for the third time. On that third occasion, fraudulent transactions began appearing on a newly-issued debit card DAYS BEFORE THE CARD WAS ACTIVATED. I concluded that (a) Citi&#8217;s security was fucked; or (b) Citi itself was engaging in broad-scale intentional fucking of its customers; or (c) both. </p>
<p>Switched entirely to my credit union. Zero problems since then. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SamSam</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1133943</link>
		<dc:creator>SamSam</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1133943</guid>
		<description>Damnit, there were supposed to be line breaks in that bulleted list. I meant to click preview, I swear!

Anyway, I see now it&#039;s supposed to just be credit card information. Since I would never willingly be a Citi customer for anything (my mortgage was transferred to them, out of my control), I feel a little safer.</description>
		<content:encoded><![CDATA[<p>Damnit, there were supposed to be line breaks in that bulleted list. I meant to click preview, I swear!</p>
<p>Anyway, I see now it&#8217;s supposed to just be credit card information. Since I would never willingly be a Citi customer for anything (my mortgage was transferred to them, out of my control), I feel a little safer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1133955</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1133955</guid>
		<description>If you think Citibank&#039;s password rules are inane, look up the ones for American Express. For some stupid reason you canâ€™t have a password over 8 characters long with them.</description>
		<content:encoded><![CDATA[<p>If you think Citibank&#8217;s password rules are inane, look up the ones for American Express. For some stupid reason you canâ€™t have a password over 8 characters long with them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cowicide</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1133964</link>
		<dc:creator>Cowicide</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1133964</guid>
		<description>&lt;blockquote&gt;My local credit union has never been hacked for the secure data of its customers.&lt;/blockquote&gt;

Good for you!

Not to mention using a local credit union is what every other patriotic American should be doing if they &lt;i&gt;really&lt;/i&gt; want to stop these &quot;too big to fail&quot; bullshit operations from having so much power in Washington, D.C. and keep screwing the rest of us.

&lt;a href=&quot;http://cowicide.blogspot.com/2010/04/william-black-should-be-household-name.html&quot;&gt;I think if more people watched this, they&#039;d understand why choosing a large bank is basically an act against America.&lt;/a&gt;

Want to stop financial terrorism against America?  Pull your money OUT of them, America.</description>
		<content:encoded><![CDATA[<blockquote><p>My local credit union has never been hacked for the secure data of its customers.</p></blockquote>
<p>Good for you!</p>
<p>Not to mention using a local credit union is what every other patriotic American should be doing if they <i>really</i> want to stop these &#8220;too big to fail&#8221; bullshit operations from having so much power in Washington, D.C. and keep screwing the rest of us.</p>
<p><a href="http://cowicide.blogspot.com/2010/04/william-black-should-be-household-name.html">I think if more people watched this, they&#8217;d understand why choosing a large bank is basically an act against America.</a></p>
<p>Want to stop financial terrorism against America?  Pull your money OUT of them, America.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TEKNA2007</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1134003</link>
		<dc:creator>TEKNA2007</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1134003</guid>
		<description>Credit union member here.  You couldn&#039;t wish for better customer service, especially if you need to call up and talk to a human.  I usually get people I&#039;ve talked to before.</description>
		<content:encoded><![CDATA[<p>Credit union member here.  You couldn&#8217;t wish for better customer service, especially if you need to call up and talk to a human.  I usually get people I&#8217;ve talked to before.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1134276</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1134276</guid>
		<description>I see they&#039;re trying to sneak this in when people are paying attention to sony&#039;s fail, seeing as it happened in may and we&#039;re 1/3 of the way through June.  So, this company had 20,000 accounts compromised and didn&#039;t tell anyone until at least a week or more likely several had passed.

Yep, confirmed for sony-tier security and service.</description>
		<content:encoded><![CDATA[<p>I see they&#8217;re trying to sneak this in when people are paying attention to sony&#8217;s fail, seeing as it happened in may and we&#8217;re 1/3 of the way through June.  So, this company had 20,000 accounts compromised and didn&#8217;t tell anyone until at least a week or more likely several had passed.</p>
<p>Yep, confirmed for sony-tier security and service.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Courtney</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1134284</link>
		<dc:creator>Courtney</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1134284</guid>
		<description>Actually, I have a friend who works in customer service (not at citibank) and you would not believe the things she&#039;s heard people call the @ character. Like &quot;epsilon,&quot; &quot;the letter kitten,&quot; and &quot;strudel sign.&quot;</description>
		<content:encoded><![CDATA[<p>Actually, I have a friend who works in customer service (not at citibank) and you would not believe the things she&#8217;s heard people call the @ character. Like &#8220;epsilon,&#8221; &#8220;the letter kitten,&#8221; and &#8220;strudel sign.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1134039</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1134039</guid>
		<description>Is it me or have there been more hackings of these big institutions? I wouldn&#039;t be surprised to see it was Lulzsec.</description>
		<content:encoded><![CDATA[<p>Is it me or have there been more hackings of these big institutions? I wouldn&#8217;t be surprised to see it was Lulzsec.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nosehat</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1134298</link>
		<dc:creator>nosehat</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1134298</guid>
		<description>Yes, such a system would prioritize reading-out-account-passwords-over-the-phone-to-whomever-is-calling over account security.

Which would be consistent anyway.

There is no reason why a bank should ever read out your password over the phone.  In fact, there&#039;s no reason a bank should ever have your plain text password in the first place.  Is the one-way hash dead these days?</description>
		<content:encoded><![CDATA[<p>Yes, such a system would prioritize reading-out-account-passwords-over-the-phone-to-whomever-is-calling over account security.</p>
<p>Which would be consistent anyway.</p>
<p>There is no reason why a bank should ever read out your password over the phone.  In fact, there&#8217;s no reason a bank should ever have your plain text password in the first place.  Is the one-way hash dead these days?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Courtney</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1134059</link>
		<dc:creator>Courtney</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1134059</guid>
		<description>I have non-letter/number characters in my citibank pw.</description>
		<content:encoded><![CDATA[<p>I have non-letter/number characters in my citibank pw.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1134315</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1134315</guid>
		<description>No, i think forums still use it :D.  Basically, the least important, least formal places on the internet are more secure than the most important.</description>
		<content:encoded><![CDATA[<p>No, i think forums still use it :D.  Basically, the least important, least formal places on the internet are more secure than the most important.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: superzorgon</title>
		<link>http://boingboing.net/2011/06/09/citigroup-hacked-dat.html#comment-1134060</link>
		<dc:creator>superzorgon</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-1134060</guid>
		<description>WARNING: My co-worker has a Citibank account, and she just discovered that their remedy is to switch customers to a new account... and then charge them $100 for doing so. 

Any of you out there w/ Citibank accounts, take heed. 

I bet the Citibank employee who came up with that policy got a raise.</description>
		<content:encoded><![CDATA[<p>WARNING: My co-worker has a Citibank account, and she just discovered that their remedy is to switch customers to a new account&#8230; and then charge them $100 for doing so. </p>
<p>Any of you out there w/ Citibank accounts, take heed. </p>
<p>I bet the Citibank employee who came up with that policy got a raise.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
