<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments for Chris Timson</title>
	<atom:link href="http://www.christimson.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.christimson.com</link>
	<description>Finally joining the bandwagon</description>
	<pubDate>Tue, 06 Jan 2009 02:51:02 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>Comment on vpamazon by A Stickler</title>
		<link>http://www.christimson.com/2008/07/24/vpamazon/#comment-53</link>
		<dc:creator>A Stickler</dc:creator>
		<pubDate>Thu, 31 Jul 2008 13:56:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.christimson.com/?p=16#comment-53</guid>
		<description>In fact, "infact" should be TWO words - "in" and "fact".
I, too, am puzzled about the vpamazon link.</description>
		<content:encoded><![CDATA[<p>In fact, &#8220;infact&#8221; should be TWO words - &#8220;in&#8221; and &#8220;fact&#8221;.<br />
I, too, am puzzled about the vpamazon link.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on vpamazon by Ed</title>
		<link>http://www.christimson.com/2008/07/24/vpamazon/#comment-45</link>
		<dc:creator>Ed</dc:creator>
		<pubDate>Sat, 26 Jul 2008 22:44:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.christimson.com/?p=16#comment-45</guid>
		<description>Anyone would have thought that you're trying to pilther people who search for 'vpamazon' looking for business cards and then end up on this page (and seed Google's page ranking whilst your at it... :D). And no, I don't think they are being clever...

Now what you really want to do is buy vpamazon.com and funnel people through that. It'd be pretty sure to end up on the top spot...

I'm humoured that my blog appears in the search listings for vpamazon too :D (well for the time being...)</description>
		<content:encoded><![CDATA[<p>Anyone would have thought that you&#8217;re trying to pilther people who search for &#8216;vpamazon&#8217; looking for business cards and then end up on this page (and seed Google&#8217;s page ranking whilst your at it&#8230; :D). And no, I don&#8217;t think they are being clever&#8230;</p>
<p>Now what you really want to do is buy vpamazon.com and funnel people through that. It&#8217;d be pretty sure to end up on the top spot&#8230;</p>
<p>I&#8217;m humoured that my blog appears in the search listings for vpamazon too <img src='http://www.christimson.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> (well for the time being&#8230;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Natwest and the flawed security concept by Chris</title>
		<link>http://www.christimson.com/2008/06/30/natwest-and-the-flawed-security-concept/#comment-32</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Tue, 01 Jul 2008 11:36:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.christimson.com/?p=13#comment-32</guid>
		<description>SSL prevents snooping and does a great job of it, so fraudsters choose a different approach. What I'm saying is that moving to a mechanism that doesn't prevent it seems like a backwards step.

Clearly keyloggers win, but I do know of people who have worked with (eg: inadvertently employed) fraudsters. I know it's not a suitable approach for organised crime, but it's clearly still something to take into account.

Telephone banking seems to just require a customer number and 2 digits from a pin. So once you've got the customer number it seems you've got a 1 in 100 chance of guessing the pin number, scary really. Online banking requires 3 digits of password (alpha-numeric) and 3 digits of pin, which is in excess of 1 in 238 million.

Keyloggers are less important with Natwest (still quite important) as you would have to see multiple login attempts in order to get all of the digits of the pin and password.

I'm sure that online banking is a major source of fraud, I just don't think that their method of tackling it has been very well thought out.

In further news, Natwest did today suggest that we consider switching to a different bank. That was after phoning me from a withheld number, announcing themselves as being from "the bank" and asking for my password.</description>
		<content:encoded><![CDATA[<p>SSL prevents snooping and does a great job of it, so fraudsters choose a different approach. What I&#8217;m saying is that moving to a mechanism that doesn&#8217;t prevent it seems like a backwards step.</p>
<p>Clearly keyloggers win, but I do know of people who have worked with (eg: inadvertently employed) fraudsters. I know it&#8217;s not a suitable approach for organised crime, but it&#8217;s clearly still something to take into account.</p>
<p>Telephone banking seems to just require a customer number and 2 digits from a pin. So once you&#8217;ve got the customer number it seems you&#8217;ve got a 1 in 100 chance of guessing the pin number, scary really. Online banking requires 3 digits of password (alpha-numeric) and 3 digits of pin, which is in excess of 1 in 238 million.</p>
<p>Keyloggers are less important with Natwest (still quite important) as you would have to see multiple login attempts in order to get all of the digits of the pin and password.</p>
<p>I&#8217;m sure that online banking is a major source of fraud, I just don&#8217;t think that their method of tackling it has been very well thought out.</p>
<p>In further news, Natwest did today suggest that we consider switching to a different bank. That was after phoning me from a withheld number, announcing themselves as being from &#8220;the bank&#8221; and asking for my password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Natwest and the flawed security concept by Ed</title>
		<link>http://www.christimson.com/2008/06/30/natwest-and-the-flawed-security-concept/#comment-31</link>
		<dc:creator>Ed</dc:creator>
		<pubDate>Tue, 01 Jul 2008 11:13:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.christimson.com/?p=13#comment-31</guid>
		<description>re: Telephone banking and fraud

Point 1. I'm quite convinced that fraud on accounts is not due to people "snooping on the line" - they wouldn't be any online fraud if this was the case, as SSL would see to that.

Point 2. Mass installs of keyloggers verses people sat around you hearing a few letters from your password (or indeed wiretaps on your line). Humm. I think keyloggers win. Unless organised criminals are now putting people into buildings around the country in order to get banking passwords. (are the digits from your PIN entered into the phone via DTMF or read aloud?)

Point 3. As it's been over 8 years since I did telephone banking, what details do they have for online banking that they don't use for telephone banking?

Of course another source of fraud (other than keylogging) is phishing sites, again organised crime. Now, it is conceivable that criminals in far flung countries will, rather than use a botnet of computers to log into accounts and transfer money, that they will individually phone up the online banking services one by one and transfer money to their accounts. But doing it using online banking is a much safer bet for the criminal and probably the way most of it is done.

Now, I know that *you* check for keyloggers everytime you use online banking (or su on a server for that matter) and that you're not going to fall for a phishing site - thus making *your* online banking as safe as it could be, but as for telephone banking being less secure than online banking for the general population - I'm less convinced.

I'd be interested to see statistics for bank fraud via different banking instruction methods. I'd imagine in the current climate that online banking would be at the top of the list, which you are now protected from, like it or not!

It is however crazy that they can't rollout a magic box to you - or just tell the computer that they have even if they haven't and let you use your personal magic box...</description>
		<content:encoded><![CDATA[<p>re: Telephone banking and fraud</p>
<p>Point 1. I&#8217;m quite convinced that fraud on accounts is not due to people &#8220;snooping on the line&#8221; - they wouldn&#8217;t be any online fraud if this was the case, as SSL would see to that.</p>
<p>Point 2. Mass installs of keyloggers verses people sat around you hearing a few letters from your password (or indeed wiretaps on your line). Humm. I think keyloggers win. Unless organised criminals are now putting people into buildings around the country in order to get banking passwords. (are the digits from your PIN entered into the phone via DTMF or read aloud?)</p>
<p>Point 3. As it&#8217;s been over 8 years since I did telephone banking, what details do they have for online banking that they don&#8217;t use for telephone banking?</p>
<p>Of course another source of fraud (other than keylogging) is phishing sites, again organised crime. Now, it is conceivable that criminals in far flung countries will, rather than use a botnet of computers to log into accounts and transfer money, that they will individually phone up the online banking services one by one and transfer money to their accounts. But doing it using online banking is a much safer bet for the criminal and probably the way most of it is done.</p>
<p>Now, I know that *you* check for keyloggers everytime you use online banking (or su on a server for that matter) and that you&#8217;re not going to fall for a phishing site - thus making *your* online banking as safe as it could be, but as for telephone banking being less secure than online banking for the general population - I&#8217;m less convinced.</p>
<p>I&#8217;d be interested to see statistics for bank fraud via different banking instruction methods. I&#8217;d imagine in the current climate that online banking would be at the top of the list, which you are now protected from, like it or not!</p>
<p>It is however crazy that they can&#8217;t rollout a magic box to you - or just tell the computer that they have even if they haven&#8217;t and let you use your personal magic box&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hello world! by Chris</title>
		<link>http://www.christimson.com/2007/11/11/hello-world/#comment-21</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Thu, 03 Apr 2008 13:21:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.christimson.com/?p=1#comment-21</guid>
		<description>Hi Chris, thanks for visiting the Blog and thanks for leaving a comment.
I've seen your site many times when I've googled our name. I've often searched for timson.com/net/*.uk etc but for some reason I never got around to buying christimson.*
If I'm going to overtake your position on google I really need to update the blog more frequently!</description>
		<content:encoded><![CDATA[<p>Hi Chris, thanks for visiting the Blog and thanks for leaving a comment.<br />
I&#8217;ve seen your site many times when I&#8217;ve googled our name. I&#8217;ve often searched for timson.com/net/*.uk etc but for some reason I never got around to buying christimson.*<br />
If I&#8217;m going to overtake your position on google I really need to update the blog more frequently!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hello world! by Chris Timson</title>
		<link>http://www.christimson.com/2007/11/11/hello-world/#comment-19</link>
		<dc:creator>Chris Timson</dc:creator>
		<pubDate>Mon, 31 Mar 2008 16:58:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.christimson.com/?p=1#comment-19</guid>
		<description>Hi,

I'm the Chris Timson who's just above you when you Google Chris Timson (but for how much longer, I wonder?). So far as I'm aware there's about 6 of us world wide, including a Selectman (whatever one of those is) in Massachusetts and a basketball player somewhere else over there, a press photographer in Canada and someone who is/was a researcher on Local Heroes. And me, the one with the concertina.

Cheers,

Chris

PS Good domain name!</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>I&#8217;m the Chris Timson who&#8217;s just above you when you Google Chris Timson (but for how much longer, I wonder?). So far as I&#8217;m aware there&#8217;s about 6 of us world wide, including a Selectman (whatever one of those is) in Massachusetts and a basketball player somewhere else over there, a press photographer in Canada and someone who is/was a researcher on Local Heroes. And me, the one with the concertina.</p>
<p>Cheers,</p>
<p>Chris</p>
<p>PS Good domain name!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on T-mobile by Chris</title>
		<link>http://www.christimson.com/2007/11/15/t-mobile/#comment-14</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Sun, 06 Jan 2008 22:45:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.christimson.com/?p=3#comment-14</guid>
		<description>Just to give an update.
They did get the billing wrong, but I phoned them up and they corrected it and sent me a credit note. This month's bill has arrived now, and it's correct this time. Wooo</description>
		<content:encoded><![CDATA[<p>Just to give an update.<br />
They did get the billing wrong, but I phoned them up and they corrected it and sent me a credit note. This month&#8217;s bill has arrived now, and it&#8217;s correct this time. Wooo</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hello world! by Blog-Ed</title>
		<link>http://www.christimson.com/2007/11/11/hello-world/#comment-10</link>
		<dc:creator>Blog-Ed</dc:creator>
		<pubDate>Sat, 24 Nov 2007 20:23:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.christimson.com/?p=1#comment-10</guid>
		<description>&lt;strong&gt;Chris has a blog......&lt;/strong&gt;

Chris appears to have got a blog. Not that he told me the address or anything - although he's hinted......</description>
		<content:encoded><![CDATA[<p><strong>Chris has a blog&#8230;&#8230;</strong></p>
<p>Chris appears to have got a blog. Not that he told me the address or anything - although he&#8217;s hinted&#8230;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on T-mobile by Chris</title>
		<link>http://www.christimson.com/2007/11/15/t-mobile/#comment-9</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Thu, 22 Nov 2007 14:32:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.christimson.com/?p=3#comment-9</guid>
		<description>Yeah right... I guess the proof of the pudding will be in the next bill.</description>
		<content:encoded><![CDATA[<p>Yeah right&#8230; I guess the proof of the pudding will be in the next bill.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hello world! by Chris</title>
		<link>http://www.christimson.com/2007/11/11/hello-world/#comment-8</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Thu, 22 Nov 2007 14:26:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.christimson.com/?p=1#comment-8</guid>
		<description>It was infact the evening of the day we were discussing it, I just thought "why not" and created it, didn't take long at all.</description>
		<content:encoded><![CDATA[<p>It was infact the evening of the day we were discussing it, I just thought &#8220;why not&#8221; and created it, didn&#8217;t take long at all.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
