<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Verified by Visa is training people to get phished</title>
	<atom:link href="http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/feed/" rel="self" type="application/rss+xml" />
	<link>http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/</link>
	<description>jim reardon (from joliet / shorewood, illinois, and former microsoft intern guy)</description>
	<lastBuildDate>Fri, 30 Jul 2010 21:36:24 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Henry Hertz Hobbit</title>
		<link>http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/comment-page-1/#comment-15273</link>
		<dc:creator>Henry Hertz Hobbit</dc:creator>
		<pubDate>Fri, 30 Jul 2010 21:36:24 +0000</pubDate>
		<guid isPermaLink="false">http://eviljim.com/?p=427#comment-15273</guid>
		<description>Addendum:
I should have said you will have no password if you don&#039;t record or store it some place.  I did, but how many people will fail to save their password which is created in an ad-hoc situation?  I still contend it is something that the name used (they use your first name + last name + number) shows about as much creativity as mud. The entire process needs to be controlled from your banking institution.  The online retailer should just say that you need to do that and THEN come back and finish the transaction. Every browser has tabs so you can easily do this or if not can start another window.  Auto created user names lead to all kinds of problems.  That is an addition to the way this is done (at the retailer) which is wrong.  There are many web sites that are now compromised by pretenders doing this so beware that you get the real one.  My PAC filter will have the updated rules on 2010-08-02 and I was able to move the &quot;visa.com&quot; rule back to &quot;.visa.com&quot; for more security.  That will prevent thousands of unknown Visa look-alikes.  VISA, ARE YOU LISTENING?  Make all of your &quot;visa.com&quot; in your own web pages &quot;www.visa.com&quot; instead.  Thanks.</description>
		<content:encoded><![CDATA[<p>Addendum:<br />
I should have said you will have no password if you don&#8217;t record or store it some place.  I did, but how many people will fail to save their password which is created in an ad-hoc situation?  I still contend it is something that the name used (they use your first name + last name + number) shows about as much creativity as mud. The entire process needs to be controlled from your banking institution.  The online retailer should just say that you need to do that and THEN come back and finish the transaction. Every browser has tabs so you can easily do this or if not can start another window.  Auto created user names lead to all kinds of problems.  That is an addition to the way this is done (at the retailer) which is wrong.  There are many web sites that are now compromised by pretenders doing this so beware that you get the real one.  My PAC filter will have the updated rules on 2010-08-02 and I was able to move the &#8220;visa.com&#8221; rule back to &#8220;.visa.com&#8221; for more security.  That will prevent thousands of unknown Visa look-alikes.  VISA, ARE YOU LISTENING?  Make all of your &#8220;visa.com&#8221; in your own web pages &#8220;www.visa.com&#8221; instead.  Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Henry Hertz Hobbit</title>
		<link>http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/comment-page-1/#comment-15265</link>
		<dc:creator>Henry Hertz Hobbit</dc:creator>
		<pubDate>Fri, 30 Jul 2010 07:36:50 +0000</pubDate>
		<guid isPermaLink="false">http://eviljim.com/?p=427#comment-15265</guid>
		<description>I have to modify my filters to accomodate this.  The filters are available here:

http://www.HostsFile.org/pac.html
http://www.SecureMecca.com/pac.html

What gets me is that it gave me a user name I didn&#039;t want and a phone number for my bank (I called - it is them so at least it is legitimate) but now I have an ad-hoc user name they created with no password, no way to change that, and no way to make a purchase!  It says you need to login to your bank to set the stuff up.  I did and there is nothing there. Either they need to have you set it up with your bank with a user name of your choice and a way to enter a password or they should scrap the whole fiasco.

Does anybody know what it is for MasterCard?  I heard they had something similar.  But I had to modify my PAC filter rule from this which prevented access to bogusvisa.com:

GoodDomains[i++] = &quot;.visa.com&quot;;

to this which allows it:

GoodDomains[i++] = &quot;visa.com&quot;

just because of this thing that is supposed to make you safer (they actually use just plain old &quot;visa.com&quot;).  This rule used to prevent the bogusvisa.com:

BadHostParts[i++] = &quot;visa\.com&quot;;

It still prevents unknown phishers like visa.com.gobbledygook.co.uk, but the fact that Visa doesn&#039;t always call subdomain.visa.com or www.visa.com but instead uses just plain visa.com opens up a pattern for abuse.

I think this needs to be sent to the scrap heap.  I don&#039;t mind a different user name and password from the bank and different ones for each card but the information should be creatable (sic) at each of your bank sites and not hid some place in their menus.  I never found the place to do it at my bank so I am going to have to go in and see them in person tomorrow. You should also have complete control of the process BEFORE you hit it at a purchase check-out.  That opens up so many chances for abuse that you cannot believe it.</description>
		<content:encoded><![CDATA[<p>I have to modify my filters to accomodate this.  The filters are available here:</p>
<p><a href="http://www.HostsFile.org/pac.html" rel="nofollow">http://www.HostsFile.org/pac.html</a><br />
<a href="http://www.SecureMecca.com/pac.html" rel="nofollow">http://www.SecureMecca.com/pac.html</a></p>
<p>What gets me is that it gave me a user name I didn&#8217;t want and a phone number for my bank (I called &#8211; it is them so at least it is legitimate) but now I have an ad-hoc user name they created with no password, no way to change that, and no way to make a purchase!  It says you need to login to your bank to set the stuff up.  I did and there is nothing there. Either they need to have you set it up with your bank with a user name of your choice and a way to enter a password or they should scrap the whole fiasco.</p>
<p>Does anybody know what it is for MasterCard?  I heard they had something similar.  But I had to modify my PAC filter rule from this which prevented access to bogusvisa.com:</p>
<p>GoodDomains[i++] = &#8220;.visa.com&#8221;;</p>
<p>to this which allows it:</p>
<p>GoodDomains[i++] = &#8220;visa.com&#8221;</p>
<p>just because of this thing that is supposed to make you safer (they actually use just plain old &#8220;visa.com&#8221;).  This rule used to prevent the bogusvisa.com:</p>
<p>BadHostParts[i++] = &#8220;visa\.com&#8221;;</p>
<p>It still prevents unknown phishers like visa.com.gobbledygook.co.uk, but the fact that Visa doesn&#8217;t always call subdomain.visa.com or <a href="http://www.visa.com" rel="nofollow">http://www.visa.com</a> but instead uses just plain visa.com opens up a pattern for abuse.</p>
<p>I think this needs to be sent to the scrap heap.  I don&#8217;t mind a different user name and password from the bank and different ones for each card but the information should be creatable (sic) at each of your bank sites and not hid some place in their menus.  I never found the place to do it at my bank so I am going to have to go in and see them in person tomorrow. You should also have complete control of the process BEFORE you hit it at a purchase check-out.  That opens up so many chances for abuse that you cannot believe it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rene</title>
		<link>http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/comment-page-1/#comment-12292</link>
		<dc:creator>Rene</dc:creator>
		<pubDate>Mon, 21 Dec 2009 09:26:31 +0000</pubDate>
		<guid isPermaLink="false">http://eviljim.com/?p=427#comment-12292</guid>
		<description>Use Visa allot. Today I came across Verified by Visa first time while buying tickets for a party. Tried twice with no success. All very fishy.
Switched over to another way of payment for this transaction.</description>
		<content:encoded><![CDATA[<p>Use Visa allot. Today I came across Verified by Visa first time while buying tickets for a party. Tried twice with no success. All very fishy.<br />
Switched over to another way of payment for this transaction.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: G</title>
		<link>http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/comment-page-1/#comment-12270</link>
		<dc:creator>G</dc:creator>
		<pubDate>Thu, 03 Dec 2009 00:40:52 +0000</pubDate>
		<guid isPermaLink="false">http://eviljim.com/?p=427#comment-12270</guid>
		<description>If you fill out the first box with false information you get a second box asking you to set a password. But this second box has a &quot;cancel&quot; button that allows you to cancel the whole &quot;Verified by Visa&quot; thing and then your order goes through. I hope.</description>
		<content:encoded><![CDATA[<p>If you fill out the first box with false information you get a second box asking you to set a password. But this second box has a &#8220;cancel&#8221; button that allows you to cancel the whole &#8220;Verified by Visa&#8221; thing and then your order goes through. I hope.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/comment-page-1/#comment-12238</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Mon, 16 Nov 2009 10:45:24 +0000</pubDate>
		<guid isPermaLink="false">http://eviljim.com/?p=427#comment-12238</guid>
		<description>Nice post. I too have blogged about this offensive dialog box:

http://www.richardskingdom.net/verified-by-visa-bad-for-security-worse-for-business

It beggars belief that Visa and Mastercard, the latter under their &quot;SecureCode&quot; brand, have adopted a technology that behaves just like the phishing attacks about which they constantly warn us.

Verified by Visa would have more credibility if credit card companies were required to post the passwords to account-holders. This wouldn&#039;t be difficult - it&#039;s what they do with PINs, after all.</description>
		<content:encoded><![CDATA[<p>Nice post. I too have blogged about this offensive dialog box:</p>
<p><a href="http://www.richardskingdom.net/verified-by-visa-bad-for-security-worse-for-business" rel="nofollow">http://www.richardskingdom.net/verified-by-visa-bad-for-security-worse-for-business</a></p>
<p>It beggars belief that Visa and Mastercard, the latter under their &#8220;SecureCode&#8221; brand, have adopted a technology that behaves just like the phishing attacks about which they constantly warn us.</p>
<p>Verified by Visa would have more credibility if credit card companies were required to post the passwords to account-holders. This wouldn&#8217;t be difficult &#8211; it&#8217;s what they do with PINs, after all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/comment-page-1/#comment-12103</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Thu, 12 Nov 2009 23:05:52 +0000</pubDate>
		<guid isPermaLink="false">http://eviljim.com/?p=427#comment-12103</guid>
		<description>Hi 

Good article. I did a blog post similar to this a few weeks back but focusing more so on their forgot password functionality. 

I was already enrolled for 3D Secure but when prompted for my 3D secure password I selected the &#039;forgot password&#039; option. Then I was prompted to enter some information to verify my identity. All of this information except for my date of birth was available on my card. Finding someone&#039;s date of birth is not difficult with the popularity of social networking sites. 

I was able to change my password and make my purchase. Not very secure in my view!! You can find the complete blog post here - 

http://www.webpayments.ie/blog/fundamental-flaw-with-3d-secure.html

Dave</description>
		<content:encoded><![CDATA[<p>Hi </p>
<p>Good article. I did a blog post similar to this a few weeks back but focusing more so on their forgot password functionality. </p>
<p>I was already enrolled for 3D Secure but when prompted for my 3D secure password I selected the &#8216;forgot password&#8217; option. Then I was prompted to enter some information to verify my identity. All of this information except for my date of birth was available on my card. Finding someone&#8217;s date of birth is not difficult with the popularity of social networking sites. </p>
<p>I was able to change my password and make my purchase. Not very secure in my view!! You can find the complete blog post here &#8211; </p>
<p><a href="http://www.webpayments.ie/blog/fundamental-flaw-with-3d-secure.html" rel="nofollow">http://www.webpayments.ie/blog/fundamental-flaw-with-3d-secure.html</a></p>
<p>Dave</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul D. Waite</title>
		<link>http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/comment-page-1/#comment-12012</link>
		<dc:creator>Paul D. Waite</dc:creator>
		<pubDate>Wed, 11 Nov 2009 16:43:21 +0000</pubDate>
		<guid isPermaLink="false">http://eviljim.com/?p=427#comment-12012</guid>
		<description>It’s getting pretty popular in the UK too: Tesco and a couple of other sites are using it.

Thankfully Amazon doesn’t yet. I’m using PayPal wherever it’s offered now.</description>
		<content:encoded><![CDATA[<p>It’s getting pretty popular in the UK too: Tesco and a couple of other sites are using it.</p>
<p>Thankfully Amazon doesn’t yet. I’m using PayPal wherever it’s offered now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexander Limi (limi) 's status on Wednesday, 11-Nov-09 15:26:03 UTC - Identi.ca</title>
		<link>http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/comment-page-1/#comment-12011</link>
		<dc:creator>Alexander Limi (limi) 's status on Wednesday, 11-Nov-09 15:26:03 UTC - Identi.ca</dc:creator>
		<pubDate>Wed, 11 Nov 2009 15:26:07 +0000</pubDate>
		<guid isPermaLink="false">http://eviljim.com/?p=427#comment-12011</guid>
		<description>[...]  http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/        a few seconds ago  from web [...]</description>
		<content:encoded><![CDATA[<p>[...]  <a href="http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/" rel="nofollow">http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/</a>        a few seconds ago  from web [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/comment-page-1/#comment-12010</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Wed, 11 Nov 2009 15:19:45 +0000</pubDate>
		<guid isPermaLink="false">http://eviljim.com/?p=427#comment-12010</guid>
		<description>Moreover, if you use NoScript in Firefox, it really screws up. I hate it too.</description>
		<content:encoded><![CDATA[<p>Moreover, if you use NoScript in Firefox, it really screws up. I hate it too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Fairs</title>
		<link>http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/comment-page-1/#comment-12008</link>
		<dc:creator>Dan Fairs</dc:creator>
		<pubDate>Wed, 11 Nov 2009 15:15:25 +0000</pubDate>
		<guid isPermaLink="false">http://eviljim.com/?p=427#comment-12008</guid>
		<description>Absolutely agree. Plus, of course, the password is trivially easy to reset. Relying on a date of birth as &#039;secret&#039; is laughable these days.

Time to write to Visa, I think.</description>
		<content:encoded><![CDATA[<p>Absolutely agree. Plus, of course, the password is trivially easy to reset. Relying on a date of birth as &#8216;secret&#8217; is laughable these days.</p>
<p>Time to write to Visa, I think.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pete Fairhurst</title>
		<link>http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/comment-page-1/#comment-12007</link>
		<dc:creator>Pete Fairhurst</dc:creator>
		<pubDate>Wed, 11 Nov 2009 14:48:25 +0000</pubDate>
		<guid isPermaLink="false">http://eviljim.com/?p=427#comment-12007</guid>
		<description>For corporations that waste (likely) billions on fraud recovery every year, it&#039;s astonishing - nae outright despicable - the apparently pathetic amounts of money they&#039;re willing to invest in online customer mechanisms like Verified by Visa.

It&#039;s an abysmal system, truly abysmal. When it&#039;s not appearing as a floating overlay or JavaScript include/injection [sic], the Verified by Visa system often appears as an equally-anonymous IFRAME on merchant websites.

Beyond this, the interface itself is probably one of the most amateurish and unfriendly pieces of UI for something this mainstream that I&#039;ve come across in years. Ugly, cramped, perishingly small fonts, jammed up against equally small text boxes, surrounded by confusing, overly wordy &quot;instructions&quot;.

And can you *ever* remember your password from one instance to the next..?  No, me neither.</description>
		<content:encoded><![CDATA[<p>For corporations that waste (likely) billions on fraud recovery every year, it&#8217;s astonishing &#8211; nae outright despicable &#8211; the apparently pathetic amounts of money they&#8217;re willing to invest in online customer mechanisms like Verified by Visa.</p>
<p>It&#8217;s an abysmal system, truly abysmal. When it&#8217;s not appearing as a floating overlay or JavaScript include/injection [sic], the Verified by Visa system often appears as an equally-anonymous IFRAME on merchant websites.</p>
<p>Beyond this, the interface itself is probably one of the most amateurish and unfriendly pieces of UI for something this mainstream that I&#8217;ve come across in years. Ugly, cramped, perishingly small fonts, jammed up against equally small text boxes, surrounded by confusing, overly wordy &#8220;instructions&#8221;.</p>
<p>And can you *ever* remember your password from one instance to the next..?  No, me neither.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul</title>
		<link>http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/comment-page-1/#comment-12006</link>
		<dc:creator>Paul</dc:creator>
		<pubDate>Wed, 11 Nov 2009 14:16:33 +0000</pubDate>
		<guid isPermaLink="false">http://eviljim.com/?p=427#comment-12006</guid>
		<description>And when you do finally cave and realise this is going to be something we just have to live with if you want to continue to use the net in the immediate future, you&#039;ll notice that the form doesn&#039;t have a username box.

They make one up for you! A different one for each visa card you have - which for me is 3!

Really annoying!</description>
		<content:encoded><![CDATA[<p>And when you do finally cave and realise this is going to be something we just have to live with if you want to continue to use the net in the immediate future, you&#8217;ll notice that the form doesn&#8217;t have a username box.</p>
<p>They make one up for you! A different one for each visa card you have &#8211; which for me is 3!</p>
<p>Really annoying!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Julie</title>
		<link>http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/comment-page-1/#comment-11413</link>
		<dc:creator>Julie</dc:creator>
		<pubDate>Wed, 10 Jun 2009 08:30:12 +0000</pubDate>
		<guid isPermaLink="false">http://eviljim.com/?p=427#comment-11413</guid>
		<description>It does this everytime I was to purchase anything. You can sign up to Verified Visa on your online banking site, so instead of the form above you get to personalize your own greeting message and a just need to fill in a password.

On the other hand, how it&#039;s supposed to increase security is BEYOND ME.

Also may I add, even after I signed up, it has NEVER worked. I used to click the *No Thanks button, now it doesn&#039;t come up anymore.

Thanks a blo*dy lot Visa.</description>
		<content:encoded><![CDATA[<p>It does this everytime I was to purchase anything. You can sign up to Verified Visa on your online banking site, so instead of the form above you get to personalize your own greeting message and a just need to fill in a password.</p>
<p>On the other hand, how it&#8217;s supposed to increase security is BEYOND ME.</p>
<p>Also may I add, even after I signed up, it has NEVER worked. I used to click the *No Thanks button, now it doesn&#8217;t come up anymore.</p>
<p>Thanks a blo*dy lot Visa.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LINDA CROWELL</title>
		<link>http://eviljim.com/archives/2009/05/verified-by-visa-is-training-people-to-get-phished/comment-page-1/#comment-11412</link>
		<dc:creator>LINDA CROWELL</dc:creator>
		<pubDate>Sun, 07 Jun 2009 02:12:44 +0000</pubDate>
		<guid isPermaLink="false">http://eviljim.com/?p=427#comment-11412</guid>
		<description>I just got the same thing and like an idiot I filled it in because my Mac wouldn&#039;t let me buy without filling it. I called my Visa and they seemed confused but told me that it was PROBABLY okay?
Very strange.</description>
		<content:encoded><![CDATA[<p>I just got the same thing and like an idiot I filled it in because my Mac wouldn&#8217;t let me buy without filling it. I called my Visa and they seemed confused but told me that it was PROBABLY okay?<br />
Very strange.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
