<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Once your PC is hacked, your ecommerce passwords go on sale at $2 a&#160;pop</title>
	<atom:link href="http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html/feed" rel="self" type="application/rss+xml" />
	<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html</link>
	<description>Brain candy for Happy Mutants</description>
	<lastBuildDate>Wed, 22 May 2013 13:46:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Halloween_Jack</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1617035</link>
		<dc:creator>Halloween_Jack</dc:creator>
		<pubDate>Sat, 29 Dec 2012 05:05:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1617035</guid>
		<description> It could be linked to an alternative payment system such as PayPal, or possibly the complete credit card info is stored in plaintext. Which sounds kind of crazy, I know, but who knows?</description>
		<content:encoded><![CDATA[<p> It could be linked to an alternative payment system such as PayPal, or possibly the complete credit card info is stored in plaintext. Which sounds kind of crazy, I know, but who knows?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tracy_Flick</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1616494</link>
		<dc:creator>Tracy_Flick</dc:creator>
		<pubDate>Fri, 28 Dec 2012 17:20:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1616494</guid>
		<description> But it says that accounts with credit card info attached go for a higher price. So doesn&#039;t that imply that the ones they&#039;re selling for the lower price don&#039;t have credit card info attached?</description>
		<content:encoded><![CDATA[<p> But it says that accounts with credit card info attached go for a higher price. So doesn&#8217;t that imply that the ones they&#8217;re selling for the lower price don&#8217;t have credit card info attached?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charlie B</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1616416</link>
		<dc:creator>Charlie B</dc:creator>
		<pubDate>Fri, 28 Dec 2012 16:17:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1616416</guid>
		<description>Seems like lately it&#039;s trojans - usually java trojans.  Yet another reason to avoid Java on ythe endpoint, if Oracle&#039;s ownership wasn&#039;t enough.</description>
		<content:encoded><![CDATA[<p>Seems like lately it&#8217;s trojans &#8211; usually java trojans.  Yet another reason to avoid Java on ythe endpoint, if Oracle&#8217;s ownership wasn&#8217;t enough.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Harvey</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1616025</link>
		<dc:creator>Bob Harvey</dc:creator>
		<pubDate>Thu, 27 Dec 2012 18:36:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1616025</guid>
		<description>How do I sell them. I could make a living making emails and selling the passwords.</description>
		<content:encoded><![CDATA[<p>How do I sell them. I could make a living making emails and selling the passwords.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bolamig</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1615746</link>
		<dc:creator>bolamig</dc:creator>
		<pubDate>Thu, 27 Dec 2012 06:19:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1615746</guid>
		<description>So what&#039;s the most common way of stealing passwords from an infected PC these days? Are they still using keyloggers or can they now crack the browser password cache?</description>
		<content:encoded><![CDATA[<p>So what&#8217;s the most common way of stealing passwords from an infected PC these days? Are they still using keyloggers or can they now crack the browser password cache?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Halloween_Jack</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1615659</link>
		<dc:creator>Halloween_Jack</dc:creator>
		<pubDate>Thu, 27 Dec 2012 02:37:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1615659</guid>
		<description>Because lots of people have their credit card information stored online with Amazon (and other e-tailers), to facilitate things like one-click shopping. </description>
		<content:encoded><![CDATA[<p>Because lots of people have their credit card information stored online with Amazon (and other e-tailers), to facilitate things like one-click shopping. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tracy_Flick</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1615634</link>
		<dc:creator>Tracy_Flick</dc:creator>
		<pubDate>Thu, 27 Dec 2012 01:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1615634</guid>
		<description>I have a stupid question. Why is a username and password without credit card info attached valuable? Why would anyone care that I&#039;m catlady123 at Amazon, and my password is 1stinkyhouse!, if they can&#039;t use that to order anything? </description>
		<content:encoded><![CDATA[<p>I have a stupid question. Why is a username and password without credit card info attached valuable? Why would anyone care that I&#8217;m catlady123 at Amazon, and my password is 1stinkyhouse!, if they can&#8217;t use that to order anything? </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: angusm</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1615602</link>
		<dc:creator>angusm</dc:creator>
		<pubDate>Wed, 26 Dec 2012 23:10:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1615602</guid>
		<description>It does say &lt;strong&gt;working&lt;/strong&gt; accounts, so presumably they have some way to verify that the username/password combination works before they list it for sale.

If you did have some way to feed the bad guys fake user/pass combos, you might set things up so that the password gets set to a new random password every 2-3 days, increasing the chances of it going &#039;bad&#039; between the time it&#039;s tested and the time of sale. The bad guys could work around that pretty easily, though (&quot;New passwords, guaranteed less than six hours old&quot;).

A possible approach might be for retailers to release &#039;tripwire&#039; accounts: a given username/password combo would appear to work, but any time that it was used, no goods would be shipped and the attacker&#039;s details would be captured. Any other transactions originating from the same IP (or with the same browser fingerprint) would be flagged for review. Again, the bad guys could get around this by using botnets or Tor routers.

This particular arms race is very hard to win.</description>
		<content:encoded><![CDATA[<p>It does say <strong>working</strong> accounts, so presumably they have some way to verify that the username/password combination works before they list it for sale.</p>
<p>If you did have some way to feed the bad guys fake user/pass combos, you might set things up so that the password gets set to a new random password every 2-3 days, increasing the chances of it going &#8216;bad&#8217; between the time it&#8217;s tested and the time of sale. The bad guys could work around that pretty easily, though (&#8220;New passwords, guaranteed less than six hours old&#8221;).</p>
<p>A possible approach might be for retailers to release &#8216;tripwire&#8217; accounts: a given username/password combo would appear to work, but any time that it was used, no goods would be shipped and the attacker&#8217;s details would be captured. Any other transactions originating from the same IP (or with the same browser fingerprint) would be flagged for review. Again, the bad guys could get around this by using botnets or Tor routers.</p>
<p>This particular arms race is very hard to win.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eark_the_Bunny</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1615598</link>
		<dc:creator>Eark_the_Bunny</dc:creator>
		<pubDate>Wed, 26 Dec 2012 22:35:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1615598</guid>
		<description>I am wondering if it would be possible to &quot;hack&quot; these SOB&#039;s back by spewing out thousands of false usernames and passwords.  Thus diluting the value of the information.  Maybe even get those turkeys in trouble with their customers for selling bad product.  Sort of like releasing sterilized male mosquitoes who mate with fertile females but their eggs never hatch. </description>
		<content:encoded><![CDATA[<p>I am wondering if it would be possible to &#8220;hack&#8221; these SOB&#8217;s back by spewing out thousands of false usernames and passwords.  Thus diluting the value of the information.  Maybe even get those turkeys in trouble with their customers for selling bad product.  Sort of like releasing sterilized male mosquitoes who mate with fertile females but their eggs never hatch. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: oasisob1</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1615578</link>
		<dc:creator>oasisob1</dc:creator>
		<pubDate>Wed, 26 Dec 2012 21:37:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1615578</guid>
		<description>I do, but since I don&#039;t have a credit card processor, you just have to send it to me, and trust that I will only spend $5 with it.</description>
		<content:encoded><![CDATA[<p>I do, but since I don&#8217;t have a credit card processor, you just have to send it to me, and trust that I will only spend $5 with it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Finnagain</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1615577</link>
		<dc:creator>Finnagain</dc:creator>
		<pubDate>Wed, 26 Dec 2012 21:35:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1615577</guid>
		<description> Do you take visa?</description>
		<content:encoded><![CDATA[<p> Do you take visa?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Kelly</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1615573</link>
		<dc:creator>Patrick Kelly</dc:creator>
		<pubDate>Wed, 26 Dec 2012 21:31:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1615573</guid>
		<description>I do not have the capacity to do this, but if someone would create it I would buy if. There should be a program were a person could enter all of their potential usernames and passwords and it does a search of the internet and tells you every e-commerce accounts (or any account for that matter) opened up by you at any time. That way you could go through and close accounts you forgot about and make sure you passwords are being updated to account for new advances  in password cracking software. Internet it is yours. Go forth, be fruitful and create.</description>
		<content:encoded><![CDATA[<p>I do not have the capacity to do this, but if someone would create it I would buy if. There should be a program were a person could enter all of their potential usernames and passwords and it does a search of the internet and tells you every e-commerce accounts (or any account for that matter) opened up by you at any time. That way you could go through and close accounts you forgot about and make sure you passwords are being updated to account for new advances  in password cracking software. Internet it is yours. Go forth, be fruitful and create.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: oasisob1</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1615574</link>
		<dc:creator>oasisob1</dc:creator>
		<pubDate>Wed, 26 Dec 2012 21:31:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1615574</guid>
		<description>Sure, for $5 I can tell you how to get ALL your passwords back in one shot.</description>
		<content:encoded><![CDATA[<p>Sure, for $5 I can tell you how to get ALL your passwords back in one shot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Finnagain</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1615571</link>
		<dc:creator>Finnagain</dc:creator>
		<pubDate>Wed, 26 Dec 2012 21:28:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1615571</guid>
		<description>Can I buy my passwords back? </description>
		<content:encoded><![CDATA[<p>Can I buy my passwords back? </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tyger11</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1615566</link>
		<dc:creator>tyger11</dc:creator>
		<pubDate>Wed, 26 Dec 2012 21:17:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1615566</guid>
		<description>It&#039;s capitalism, baby!</description>
		<content:encoded><![CDATA[<p>It&#8217;s capitalism, baby!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Funk Daddy</title>
		<link>http://boingboing.net/2012/12/26/once-your-pc-is-hacked-your-e.html#comment-1615558</link>
		<dc:creator>Funk Daddy</dc:creator>
		<pubDate>Wed, 26 Dec 2012 20:38:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=202853#comment-1615558</guid>
		<description>$2 !...

I feel as a victim I am being under-valued by my assailant </description>
		<content:encoded><![CDATA[<p>$2 !&#8230;</p>
<p>I feel as a victim I am being under-valued by my assailant </p>
]]></content:encoded>
	</item>
</channel>
</rss>
