<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Blog Tracking Services Compromise Online Bank Security?</title>
	<atom:link href="http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/</link>
	<description>Connecting the dots ...</description>
	<lastBuildDate>Sat, 21 Nov 2009 06:03:39 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: NexGen Technology Blog » Are Blog Tracking Services A Security Risk? Citibank Thinks So</title>
		<link>http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7221</link>
		<dc:creator>NexGen Technology Blog » Are Blog Tracking Services A Security Risk? Citibank Thinks So</dc:creator>
		<pubDate>Tue, 20 Nov 2007 17:50:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7221</guid>
		<description>[...] Erdos uses both MyBlogLog and BlogRovr and got a rather interesting message whilst trying to log into [...]</description>
		<content:encoded><![CDATA[<p>[...] Erdos uses both MyBlogLog and BlogRovr and got a rather interesting message whilst trying to log into [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zoli Erdos</title>
		<link>http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7212</link>
		<dc:creator>Zoli Erdos</dc:creator>
		<pubDate>Tue, 20 Nov 2007 06:35:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7212</guid>
		<description>Citi does not test for the presence of browser extensions: I just went back and tested it after uninstalling BlogRovr, then again with a vanilla IE7 and saw the same message, so it&#039;s a generic warning.  

This was at citicards.com, trying to send a customer service message, but I suppose the same situations applies to any site that offers message boxes.</description>
		<content:encoded><![CDATA[<p>Citi does not test for the presence of browser extensions: I just went back and tested it after uninstalling BlogRovr, then again with a vanilla IE7 and saw the same message, so it&#8217;s a generic warning.  </p>
<p>This was at citicards.com, trying to send a customer service message, but I suppose the same situations applies to any site that offers message boxes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zoli Erdos</title>
		<link>http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7211</link>
		<dc:creator>Zoli Erdos</dc:creator>
		<pubDate>Tue, 20 Nov 2007 06:23:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7211</guid>
		<description>Yes, I also thought they were referring to trackers that  come with a browser plug-in. In this case I was using FireFox and there is a BlogRovr plugin, which I was testing... and, like Niall points out, coComment has a plugin, too, and who knows whatever else. Not very reassuring... I&#039;m turning BlogRovr off.</description>
		<content:encoded><![CDATA[<p>Yes, I also thought they were referring to trackers that  come with a browser plug-in. In this case I was using FireFox and there is a BlogRovr plugin, which I was testing&#8230; and, like Niall points out, coComment has a plugin, too, and who knows whatever else. Not very reassuring&#8230; I&#8217;m turning BlogRovr off.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Todd Sampson</title>
		<link>http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7209</link>
		<dc:creator>Todd Sampson</dc:creator>
		<pubDate>Tue, 20 Nov 2007 04:44:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7209</guid>
		<description>I am pretty sure that Niall is right.  It is the only thing that makes sense.  MyBlogLog and other web-based services would need to be installed on the Citibank site itself for any usage tracking to occur. 

Cheers,
Todd</description>
		<content:encoded><![CDATA[<p>I am pretty sure that Niall is right.  It is the only thing that makes sense.  MyBlogLog and other web-based services would need to be installed on the Citibank site itself for any usage tracking to occur. </p>
<p>Cheers,<br />
Todd</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Niall Kennedy</title>
		<link>http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7208</link>
		<dc:creator>Niall Kennedy</dc:creator>
		<pubDate>Tue, 20 Nov 2007 04:40:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7208</guid>
		<description>I am guessing Citibank is warning you about the Firefox extensions and other browser modifications that may scan the page looking for actionable objects. A service such as coComment might sniff for comment boxes such as this one looking for an opportunity to send that comment field to its remote web service for storage and indexing.

Were you running Firefox? The Citibank page could look for certain JS variables present in the DOM and send you a warning. Gmail currently issues tips/warnings for its members with Firebug turned on for example.</description>
		<content:encoded><![CDATA[<p>I am guessing Citibank is warning you about the Firefox extensions and other browser modifications that may scan the page looking for actionable objects. A service such as coComment might sniff for comment boxes such as this one looking for an opportunity to send that comment field to its remote web service for storage and indexing.</p>
<p>Were you running Firefox? The Citibank page could look for certain JS variables present in the DOM and send you a warning. Gmail currently issues tips/warnings for its members with Firebug turned on for example.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TechCrunch: Are Blog Tracking Services A Security Risk? Citibank Thinks So</title>
		<link>http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7206</link>
		<dc:creator>TechCrunch: Are Blog Tracking Services A Security Risk? Citibank Thinks So</dc:creator>
		<pubDate>Tue, 20 Nov 2007 03:59:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7206</guid>
		<description>[...] Erdos uses both MyBlogLog and BlogRovr and got a rather interesting message whilst trying to log into [...]</description>
		<content:encoded><![CDATA[<p>[...] Erdos uses both MyBlogLog and BlogRovr and got a rather interesting message whilst trying to log into [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Voyagerfan5761</title>
		<link>http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7188</link>
		<dc:creator>Voyagerfan5761</dc:creator>
		<pubDate>Mon, 19 Nov 2007 06:00:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7188</guid>
		<description>No service I know of could steal data from a banking site, but I&#039;m no more security expert than you, so...</description>
		<content:encoded><![CDATA[<p>No service I know of could steal data from a banking site, but I&#8217;m no more security expert than you, so&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul</title>
		<link>http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7184</link>
		<dc:creator>Paul</dc:creator>
		<pubDate>Mon, 19 Nov 2007 03:27:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.zoliblog.com/2007/11/18/blog-tracking-services-compromise-online-bank-security/#comment-7184</guid>
		<description>It could well be a threat vector. Essentially it turns a one way service into a two way</description>
		<content:encoded><![CDATA[<p>It could well be a threat vector. Essentially it turns a one way service into a two way</p>
]]></content:encoded>
	</item>
</channel>
</rss>
