<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Huge Security Hole in John Ratcliffe-Lee&#8217;s Browser</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=326" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=326</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=326&#038;cpage=1#comment-474</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Sun, 25 Mar 2007 23:50:31 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=326#comment-474</guid>
		<description><![CDATA[This post is on the first results page for the query &quot;(Citi OR CitiBank) AND (Love OR Like OR Best OR Good OR Great OR Adore OR Wonderful OR Convenient)&quot; in BlogPulse, as I noted when I looked at some recent stats.

Kind of an interesting query in and of itself, huh?
]]></description>
		<content:encoded><![CDATA[<p>This post is on the first results page for the query &#8220;(Citi OR CitiBank) AND (Love OR Like OR Best OR Good OR Great OR Adore OR Wonderful OR Convenient)&#8221; in BlogPulse, as I noted when I looked at some recent stats.</p>
<p>Kind of an interesting query in and of itself, huh?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Ratcliffe-Lee</title>
		<link>http://spiresecurity.com/?p=326&#038;cpage=1#comment-473</link>
		<dc:creator>John Ratcliffe-Lee</dc:creator>
		<pubDate>Sat, 24 Mar 2007 03:31:05 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=326#comment-473</guid>
		<description><![CDATA[On the contrary, no point has been missed.  From my perspective, you&#039;re still trying to hammer home an opinion that has been discussed already and fleshed out.  Of course the way I used coComment created this situation (and at no point have I denied that), why the need to keep addressing it?

As a paying customer of Citibank, my perspective is slightly different than yours, a security pundit.  Regardless of what I&#039;m doing on my computer and how I&#039;m doing it, isn&#039;t constructing a secure environment somewhat about anticipation and preparation?  Are you telling me if you were a developer for Citibank, and you knew about coComment, the way it functioned, and that the possibility exists some of Citibank&#039;s customers might use it (not just me by the way, this happened to 3 other people that I know about), wouldn&#039;t you consider that scenario in your design decisions?  If your answer is no, then I&#039;d be quite surprised.

I&#039;m not asking Citibank to detect anything.  Frankly, I don&#039;t want them to detect anything.  I find it hard to believe that you don&#039;t think this is something that should be preventing from the outset.  If Wachovia and ING Direct can do it, why not Citibank?

I&#039;ve thought more than twice about all the software running on my client and coComment has weighed in on how I can use such software (theirs) properly as well.  As a Citibank customer, what&#039;s disturbing to me is why their message forms even allowed a coComment extension to initialize when the page was loaded and they have failed to address this in any means other than an open-ended response from someone on their security team.
]]></description>
		<content:encoded><![CDATA[<p>On the contrary, no point has been missed.  From my perspective, you&#8217;re still trying to hammer home an opinion that has been discussed already and fleshed out.  Of course the way I used coComment created this situation (and at no point have I denied that), why the need to keep addressing it?</p>
<p>As a paying customer of Citibank, my perspective is slightly different than yours, a security pundit.  Regardless of what I&#8217;m doing on my computer and how I&#8217;m doing it, isn&#8217;t constructing a secure environment somewhat about anticipation and preparation?  Are you telling me if you were a developer for Citibank, and you knew about coComment, the way it functioned, and that the possibility exists some of Citibank&#8217;s customers might use it (not just me by the way, this happened to 3 other people that I know about), wouldn&#8217;t you consider that scenario in your design decisions?  If your answer is no, then I&#8217;d be quite surprised.</p>
<p>I&#8217;m not asking Citibank to detect anything.  Frankly, I don&#8217;t want them to detect anything.  I find it hard to believe that you don&#8217;t think this is something that should be preventing from the outset.  If Wachovia and ING Direct can do it, why not Citibank?</p>
<p>I&#8217;ve thought more than twice about all the software running on my client and coComment has weighed in on how I can use such software (theirs) properly as well.  As a Citibank customer, what&#8217;s disturbing to me is why their message forms even allowed a coComment extension to initialize when the page was loaded and they have failed to address this in any means other than an open-ended response from someone on their security team.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete</title>
		<link>http://spiresecurity.com/?p=326&#038;cpage=1#comment-472</link>
		<dc:creator>Pete</dc:creator>
		<pubDate>Sat, 24 Mar 2007 01:26:17 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=326#comment-472</guid>
		<description><![CDATA[@John -

Sorry, but you appear to still be missing the point. Citibank&#039;s design decisions impact how you/your software operate, but the control still remains on your end. There is no way Citibank can detect software on your desktop barring some sort of agent donwload themselves.

It is still not quite clear to me that the problem here was that Citibank wasn&#039;t using SSL (which, btw, is really smoke and mirrors to begin with).

Huge hole in John Ratcliffe-Lee&#039;s browser. It&#039;s your fault, not theirs. Think twice about all the software you have running on your client.

]]></description>
		<content:encoded><![CDATA[<p>@John -</p>
<p>Sorry, but you appear to still be missing the point. Citibank&#8217;s design decisions impact how you/your software operate, but the control still remains on your end. There is no way Citibank can detect software on your desktop barring some sort of agent donwload themselves.</p>
<p>It is still not quite clear to me that the problem here was that Citibank wasn&#8217;t using SSL (which, btw, is really smoke and mirrors to begin with).</p>
<p>Huge hole in John Ratcliffe-Lee&#8217;s browser. It&#8217;s your fault, not theirs. Think twice about all the software you have running on your client.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Ratcliffe-Lee</title>
		<link>http://spiresecurity.com/?p=326&#038;cpage=1#comment-471</link>
		<dc:creator>John Ratcliffe-Lee</dc:creator>
		<pubDate>Sat, 24 Mar 2007 00:21:15 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=326#comment-471</guid>
		<description><![CDATA[Pete,

Thanks for your thoughts on this.  I think I&#039;ve fully acknowledged, and anyone else reading the back and forth about this issue realizes, that none of this would of happened without my involvement.  I have no plans to retract any statements I&#039;ve made about this issue and will not make any calls to anyone else to do so either.  Everyone is allowed their opinion.

With that said, I&#039;d like to make clear that I fully understand how and why coComment (as well as their Mozilla Firefox extension) function as they do and this situation would not have come to light if I had initially un-checked the tracking box.  As I mentioned over on Stowe&#039;s post, this was a simple user error caused by haste and something that can happen to anyone.

You&#039;re exactly right about Citibank not being in the &quot;communication stream.&quot;  There should be no involvement whatsoever by a third party in the &quot;communication stream&quot; when I&#039;m on my bank&#039;s web site.  My issue is why Citibank even allowed coComment to function in the first place (which has been disseminated by the fact that they don&#039;t use SSL).

Since I&#039;m sure you&#039;ve read my colleague Tom&#039;s post(s) and comments over on OTD, I won&#039;t go much further.  My thoughts on this are essentially in-line with his and he&#039;s addressed any questions you&#039;ve had with the same perspective I would&#039;ve.

Thanks again for your time and attention to this, and for helping spread the word about being proactive with your security online.

Very best,

John
]]></description>
		<content:encoded><![CDATA[<p>Pete,</p>
<p>Thanks for your thoughts on this.  I think I&#8217;ve fully acknowledged, and anyone else reading the back and forth about this issue realizes, that none of this would of happened without my involvement.  I have no plans to retract any statements I&#8217;ve made about this issue and will not make any calls to anyone else to do so either.  Everyone is allowed their opinion.</p>
<p>With that said, I&#8217;d like to make clear that I fully understand how and why coComment (as well as their Mozilla Firefox extension) function as they do and this situation would not have come to light if I had initially un-checked the tracking box.  As I mentioned over on Stowe&#8217;s post, this was a simple user error caused by haste and something that can happen to anyone.</p>
<p>You&#8217;re exactly right about Citibank not being in the &#8220;communication stream.&#8221;  There should be no involvement whatsoever by a third party in the &#8220;communication stream&#8221; when I&#8217;m on my bank&#8217;s web site.  My issue is why Citibank even allowed coComment to function in the first place (which has been disseminated by the fact that they don&#8217;t use SSL).</p>
<p>Since I&#8217;m sure you&#8217;ve read my colleague Tom&#8217;s post(s) and comments over on OTD, I won&#8217;t go much further.  My thoughts on this are essentially in-line with his and he&#8217;s addressed any questions you&#8217;ve had with the same perspective I would&#8217;ve.</p>
<p>Thanks again for your time and attention to this, and for helping spread the word about being proactive with your security online.</p>
<p>Very best,</p>
<p>John</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Biro</title>
		<link>http://spiresecurity.com/?p=326&#038;cpage=1#comment-470</link>
		<dc:creator>Tom Biro</dc:creator>
		<pubDate>Thu, 22 Mar 2007 17:22:59 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=326#comment-470</guid>
		<description><![CDATA[Pete -

As to your update 2 - that&#039;s a very good point to make sure is clear. You&#039;re right - user is always (at least theoretically, unless some third party ends up being in control) in control of what s/he is doing, browser-wise.

I asked Citi&#039;s tech folks about this on the phone over the weekend, and didn&#039;t get any answers, and hadn&#039;t heard back about this specifically.

Again, while I think it can be testy at times from my POV and yours, we appreciate your candid comments, makes for great discussion.

Appreciate your time.

Best,

Tom
]]></description>
		<content:encoded><![CDATA[<p>Pete -</p>
<p>As to your update 2 &#8211; that&#8217;s a very good point to make sure is clear. You&#8217;re right &#8211; user is always (at least theoretically, unless some third party ends up being in control) in control of what s/he is doing, browser-wise.</p>
<p>I asked Citi&#8217;s tech folks about this on the phone over the weekend, and didn&#8217;t get any answers, and hadn&#8217;t heard back about this specifically.</p>
<p>Again, while I think it can be testy at times from my POV and yours, we appreciate your candid comments, makes for great discussion.</p>
<p>Appreciate your time.</p>
<p>Best,</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Open The Dialogue</title>
		<link>http://spiresecurity.com/?p=326&#038;cpage=1#comment-475</link>
		<dc:creator>Open The Dialogue</dc:creator>
		<pubDate>Thu, 22 Mar 2007 13:55:15 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=326#comment-475</guid>
		<description><![CDATA[&lt;strong&gt;Followup on coComment / Citibank issue&lt;/strong&gt;

I&#039;ve been trying to keep up with what has been going on with regard to John&#039;s issue late last week with coComment and Citibank, and I wanted to post an update today after reading this post by Pete Spire of...
]]></description>
		<content:encoded><![CDATA[<p><strong>Followup on coComment / Citibank issue</strong></p>
<p>I&#8217;ve been trying to keep up with what has been going on with regard to John&#8217;s issue late last week with coComment and Citibank, and I wanted to post an update today after reading this post by Pete Spire of&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
