<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Rabobank has insecure SMS banking</title>
	<atom:link href="http://specialbrands.net/2008/07/09/rabobank-has-insecure-sms-banking/feed/" rel="self" type="application/rss+xml" />
	<link>http://specialbrands.net/2008/07/09/rabobank-has-insecure-sms-banking/</link>
	<description>blaze your trail</description>
	<lastBuildDate>Sat, 04 Feb 2012 18:11:27 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: More SMS banking by M&#38;T #sms #bank #risk &#171; General Musing</title>
		<link>http://specialbrands.net/2008/07/09/rabobank-has-insecure-sms-banking/#comment-873</link>
		<dc:creator><![CDATA[More SMS banking by M&#38;T #sms #bank #risk &#171; General Musing]]></dc:creator>
		<pubDate>Thu, 22 Apr 2010 12:33:44 +0000</pubDate>
		<guid isPermaLink="false">http://webhat.wordpress.com/?p=124#comment-873</guid>
		<description><![CDATA[[...] SMS banking by M&amp;T #sms #bank&#160;#risk By webhat  Brian Szymanski send a reply to me concerning another bank implementing SMS banking: M&amp;T. Their demo, which you can find [...]]]></description>
		<content:encoded><![CDATA[<p>[...] SMS banking by M&amp;T #sms #bank&nbsp;#risk By webhat  Brian Szymanski send a reply to me concerning another bank implementing SMS banking: M&amp;T. Their demo, which you can find [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: webhat</title>
		<link>http://specialbrands.net/2008/07/09/rabobank-has-insecure-sms-banking/#comment-872</link>
		<dc:creator><![CDATA[webhat]]></dc:creator>
		<pubDate>Thu, 22 Apr 2010 11:29:36 +0000</pubDate>
		<guid isPermaLink="false">http://webhat.wordpress.com/?p=124#comment-872</guid>
		<description><![CDATA[Thanks for the video.

I just watched it, and it&#039;s not so bad really. You can&#039;t do payments over this, not unlike some of the other mobile banking services I&#039;ve profiled. My current bank has a way to access your current account details using MSN, although they do mask account numbers.

With a little social engineering you can get all these details from your bank over the telephone. I will post it with attribution in the next few days.]]></description>
		<content:encoded><![CDATA[<p>Thanks for the video.</p>
<p>I just watched it, and it&#8217;s not so bad really. You can&#8217;t do payments over this, not unlike some of the other mobile banking services I&#8217;ve profiled. My current bank has a way to access your current account details using MSN, although they do mask account numbers.</p>
<p>With a little social engineering you can get all these details from your bank over the telephone. I will post it with attribution in the next few days.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: brian szymanski</title>
		<link>http://specialbrands.net/2008/07/09/rabobank-has-insecure-sms-banking/#comment-867</link>
		<dc:creator><![CDATA[brian szymanski]]></dc:creator>
		<pubDate>Wed, 21 Apr 2010 07:46:51 +0000</pubDate>
		<guid isPermaLink="false">http://webhat.wordpress.com/?p=124#comment-867</guid>
		<description><![CDATA[using sms for banking is one of the stupidest ideas i can imagine. my bank, m and t bank of buffalo, ny, usa, is now doing it too. with no additional security or one time passwords whatsoever. the only thing they do is omit personally identifiable information, but with a cell phone number, how hard is that to track down? Not to mention the problems SMS spoofing introduces. See the video here:

https://www.mtb.com/PERSONAL/CONVENIENTBANKING/Pages/MobileBankingDemo.aspx

only a fool would sign up for this service. and i&#039;ve accelerated my plans to leave this bank.]]></description>
		<content:encoded><![CDATA[<p>using sms for banking is one of the stupidest ideas i can imagine. my bank, m and t bank of buffalo, ny, usa, is now doing it too. with no additional security or one time passwords whatsoever. the only thing they do is omit personally identifiable information, but with a cell phone number, how hard is that to track down? Not to mention the problems SMS spoofing introduces. See the video here:</p>
<p><a href="https://www.mtb.com/PERSONAL/CONVENIENTBANKING/Pages/MobileBankingDemo.aspx" rel="nofollow">https://www.mtb.com/PERSONAL/CONVENIENTBANKING/Pages/MobileBankingDemo.aspx</a></p>
<p>only a fool would sign up for this service. and i&#8217;ve accelerated my plans to leave this bank.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Abhishek Rao</title>
		<link>http://specialbrands.net/2008/07/09/rabobank-has-insecure-sms-banking/#comment-276</link>
		<dc:creator><![CDATA[Abhishek Rao]]></dc:creator>
		<pubDate>Wed, 30 Jul 2008 12:54:48 +0000</pubDate>
		<guid isPermaLink="false">http://webhat.wordpress.com/?p=124#comment-276</guid>
		<description><![CDATA[It is true that sms banking can be risky not only in the above way, but also in a case where the cell phone gets stolen and thus the secure data can be recovered from the sent transactions and inbox. While searching for an answer to this, I found that one of the bank called Barclays offers its customers mobile banking through USSD mode which works like balance enquiry and doesnt store anything on the cell phone. Its definately more secure than sms and faster in response time. The following online demo might explain all the security measures taken by bank while implementing USSD http://www.barclays.in/channels/mobile/hello_money_demo.htm]]></description>
		<content:encoded><![CDATA[<p>It is true that sms banking can be risky not only in the above way, but also in a case where the cell phone gets stolen and thus the secure data can be recovered from the sent transactions and inbox. While searching for an answer to this, I found that one of the bank called Barclays offers its customers mobile banking through USSD mode which works like balance enquiry and doesnt store anything on the cell phone. Its definately more secure than sms and faster in response time. The following online demo might explain all the security measures taken by bank while implementing USSD <a href="http://www.barclays.in/channels/mobile/hello_money_demo.htm" rel="nofollow">http://www.barclays.in/channels/mobile/hello_money_demo.htm</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

