:: IdeaJoy: Tech, Grace, Art, Proverbs ... | contact ::
[::..IdeaJoy Stuf..::]
Who Reads What
Resonate Media Radar
Atom Site Feed
djking. Get yours at flagrantdisregard.com/flickr
[::..google news..::]
Canada
New Brunswick
Java
[::..the net next door..::]
Java
User Friendly
Kevin Frank
Bible Gateway
Philip Yancey
DNTO
Jakob Nielsen
Martin Roth
CJUG
[::..neighbourhood blogs..::]
Bene Diction
Jordon Cooper
Ian's Messy Desk
Urban Onramps
Wendy Cooper
Stranger in a Strange Land
The Homeless Guy
What in Tarnation?
paradox1x
Thunderstruck
Quantum Tea
AvoidingEvil.com
This Classical Life
The Heresy
U2 Sermons
Linea Lanoie
Margie Goodyear
Waving or Drowning?
Can You Hear ...
Meditatio
After the Movie
incontheivable
Kevin's little floating adventure
SwanSmith
Blue Christian on a Red Background
Obvious Pop
A Desperate Kind of Faithful
Chicken and Egg
Doctor in Denial
VincentBytes
Liminal Life
[::..blog hubs..::]
Resonate Blogs
BlogsCanada
[::..weather..::]
Calgary
Edmonton
Fredericton
[::..archive..::]
05/01/2002 - 06/01/2002
06/01/2002 - 07/01/2002
07/01/2002 - 08/01/2002
08/01/2002 - 09/01/2002
09/01/2002 - 10/01/2002
10/01/2002 - 11/01/2002
11/01/2002 - 12/01/2002
12/01/2002 - 01/01/2003
01/01/2003 - 02/01/2003
02/01/2003 - 03/01/2003
03/01/2003 - 04/01/2003
04/01/2003 - 05/01/2003
05/01/2003 - 06/01/2003
06/01/2003 - 07/01/2003
07/01/2003 - 08/01/2003
08/01/2003 - 09/01/2003
09/01/2003 - 10/01/2003
10/01/2003 - 11/01/2003
11/01/2003 - 12/01/2003
12/01/2003 - 01/01/2004
01/01/2004 - 02/01/2004
02/01/2004 - 03/01/2004
03/01/2004 - 04/01/2004
04/01/2004 - 05/01/2004
05/01/2004 - 06/01/2004
06/01/2004 - 07/01/2004
07/01/2004 - 08/01/2004
08/01/2004 - 09/01/2004
09/01/2004 - 10/01/2004
10/01/2004 - 11/01/2004
11/01/2004 - 12/01/2004
12/01/2004 - 01/01/2005
01/01/2005 - 02/01/2005
02/01/2005 - 03/01/2005
03/01/2005 - 04/01/2005
04/01/2005 - 05/01/2005
05/01/2005 - 06/01/2005
06/01/2005 - 07/01/2005
07/01/2005 - 08/01/2005
08/01/2005 - 09/01/2005
09/01/2005 - 10/01/2005
10/01/2005 - 11/01/2005
11/01/2005 - 12/01/2005
12/01/2005 - 01/01/2006
01/01/2006 - 02/01/2006
02/01/2006 - 03/01/2006
03/01/2006 - 04/01/2006
04/01/2006 - 05/01/2006
05/01/2006 - 06/01/2006
06/01/2006 - 07/01/2006
07/01/2006 - 08/01/2006
08/01/2006 - 09/01/2006
09/01/2006 - 10/01/2006
10/01/2006 - 11/01/2006
11/01/2006 - 12/01/2006
12/01/2006 - 01/01/2007
01/01/2007 - 02/01/2007
02/01/2007 - 03/01/2007
03/01/2007 - 04/01/2007
04/01/2007 - 05/01/2007
05/01/2007 - 06/01/2007
06/01/2007 - 07/01/2007
07/01/2007 - 08/01/2007
08/01/2007 - 09/01/2007
09/01/2007 - 10/01/2007
10/01/2007 - 11/01/2007
11/01/2007 - 12/01/2007
12/01/2007 - 01/01/2008
01/01/2008 - 02/01/2008
02/01/2008 - 03/01/2008
03/01/2008 - 04/01/2008
04/01/2008 - 05/01/2008
05/01/2008 - 06/01/2008
06/01/2008 - 07/01/2008
07/01/2008 - 08/01/2008
08/01/2008 - 09/01/2008
09/01/2008 - 10/01/2008
10/01/2008 - 11/01/2008
11/01/2008 - 12/01/2008
12/01/2008 - 01/01/2009
01/01/2009 - 02/01/2009
02/01/2009 - 03/01/2009
03/01/2009 - 04/01/2009
04/01/2009 - 05/01/2009
05/01/2009 - 06/01/2009
06/01/2009 - 07/01/2009
07/01/2009 - 08/01/2009

:: Tuesday, December 07, 2004 ::

President's Choice Financial Sets It's Customers Up for Identiy Theft and Fraud

I've gotten my fair share of phishing attacks for American Banks that I'm not a customer of. They are easy to spot as I'm not a customer of these banks. I just delete them, no big deal. This email did catch my attention

Dear David King,

This email is to inform you that you have not logged into your President's Choice Financial MasterCard online account for 32 days. In order to ensure your online account status remains in an active state, please click here www.pcfinancial.ca or www.pcfinance.ca (for Quebec residents) and log into your account.

Regards,
Customer Service
President's Choice Financial
1-866-246-7262


It follows the classic Phising Attack Formula,

Dear Customer,

Due to [random technical reason] We ask that you to sign into your account, please click [url].


The only variant is that I do have a MasterCard with President's Choice Financial, so I called their 1-800 number from the back of my card. Turns out they do indeed send out these messages. This is just plain dangerous. They are setting up their customers to fall for Phishing Attacks.

Banks will tell you that they will never, under any circumstance, ask for your bank card PIN number. Anyone claiming to be from the bank and asking for your PIN is a fraud. It's a simple easy to understand rule.

The same logic should apply to emails asking you to log into your account. By sending out legitimate emails asking people to log into their account to keep them active President's Choice Financial is making fraud much easier. Ironicaly President's Choice attempte to warn it's customer about the dangers of Identity Theft.

I've tried to report the issue to Presiden't Choice with little success. The customer service people get very confused, one told me I needed to send a screen shot of the security issue.

Security needs to be more than 128 bit encryption and browser settings, it needs to be a culture.

- Peace

:: Dave King 20:47 :: ::
...

Comments:
128 bit encryption with browser settings works fine if you convince the banks or whoever to use https to authenticate the client and not just the server. I feel like screaming in anguish every time I need to supply username and password over https.

I keep thinking: they should let me send them my public key once, they should then add that key to my customer info. That way the bank can be sure I'm me in addition to me being sure they are them. As a result, I never ever send out login credentials anywhere, my browser merely "answers challenges" and so if I fall for a scam, they do not get my login credentials.

Aaarrrggghh!!!

Sigh. One of the most practical, useful, and peaceful applications for abstract mathematics reduced to a shadow of its true potential by big and stupid companies. I remember when people asked: "So what's abstract mathematics good for?" and I would cheerfully talk about asymmetric public key encryption. Now I guess the answer is "to give stupid corporation a precious gift that they will waste."

I suppose I should not get too upset because Jesus warns us not to cast our pearls before swine. And upon reflection, Our Lord gave us the precious gift of his very life knowing that people such as myself could waste it.
 
I was thinking about the people getting ripped off after falling for a phishing attack; having been trained to respond by the bank. But clearly we should stop and think about those poor mathimaticians.

Is this why they seek math that can't be applied, cause mortals just mess it up?

- Peace
 
Post a Comment