<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Who the fuck is yaron shohat and why does he want my social security number</title>
	<atom:link href="http://paddymullen.com/2009/05/21/yaron-shohat/feed/" rel="self" type="application/rss+xml" />
	<link>http://paddymullen.com/2009/05/21/yaron-shohat/</link>
	<description>The flypaper of my mind</description>
	<lastBuildDate>Sat,  4 Feb 2012 17:25:42 -0500</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.6</generator>
	<item>
		<title>By: Ted</title>
		<link>http://paddymullen.com/2009/05/21/yaron-shohat/#comment-2140</link>
		<dc:creator>Ted</dc:creator>
		<pubDate>Sun, 12 Dec 2010 23:09:02 +0000</pubDate>
		<guid isPermaLink="false">http://paddymullen.com/?p=77#comment-2140</guid>
		<description>It is legit.  That&#039;s the terribly sad part.  I went through the bank&#039;s Verified by Visa links and it takes me exactly to the same site.  Worst is that the text on the securesuite.net FAQ says, &quot;to administer your account, login to the xxx bank&#039;s site&quot;, which ironically, redirects to a subdirectory at securesuite.net</description>
		<content:encoded><![CDATA[<p>It is legit.  That&#8217;s the terribly sad part.  I went through the bank&#8217;s Verified by Visa links and it takes me exactly to the same site.  Worst is that the text on the securesuite.net FAQ says, &#8220;to administer your account, login to the xxx bank&#8217;s site&#8221;, which ironically, redirects to a subdirectory at securesuite.net</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe</title>
		<link>http://paddymullen.com/2009/05/21/yaron-shohat/#comment-2115</link>
		<dc:creator>Joe</dc:creator>
		<pubDate>Tue, 14 Sep 2010 01:32:18 +0000</pubDate>
		<guid isPermaLink="false">http://paddymullen.com/?p=77#comment-2115</guid>
		<description>Same experience. My issue is that the URL for securesuite.net includes the string, opt_in_dispatcher . And the fact that I cannot just proceed without opt-in. That makes this site questionable, whether or not it&#039;s administered by a &quot;legit&quot; organization.</description>
		<content:encoded><![CDATA[<p>Same experience. My issue is that the URL for securesuite.net includes the string, opt_in_dispatcher . And the fact that I cannot just proceed without opt-in. That makes this site questionable, whether or not it&#8217;s administered by a &#8220;legit&#8221; organization.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jack wong</title>
		<link>http://paddymullen.com/2009/05/21/yaron-shohat/#comment-2104</link>
		<dc:creator>jack wong</dc:creator>
		<pubDate>Sat, 19 Jun 2010 22:51:12 +0000</pubDate>
		<guid isPermaLink="false">http://paddymullen.com/?p=77#comment-2104</guid>
		<description>I just tried to buy a few dollars worth of credit on Skype.com and a similar thing happened when I tried using my CapitalOne credit card. I noticed that securesuite.net was in the address bar and not Skype......hmmmm...

This is really sucky and piss poor from a security point of view for credit card companies to be playing around with crap like this!!</description>
		<content:encoded><![CDATA[<p>I just tried to buy a few dollars worth of credit on Skype.com and a similar thing happened when I tried using my CapitalOne credit card. I noticed that securesuite.net was in the address bar and not Skype&#8230;&#8230;hmmmm&#8230;</p>
<p>This is really sucky and piss poor from a security point of view for credit card companies to be playing around with crap like this!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: annoyed by securesuite.net</title>
		<link>http://paddymullen.com/2009/05/21/yaron-shohat/#comment-2089</link>
		<dc:creator>annoyed by securesuite.net</dc:creator>
		<pubDate>Mon, 01 Mar 2010 02:59:25 +0000</pubDate>
		<guid isPermaLink="false">http://paddymullen.com/?p=77#comment-2089</guid>
		<description>I can&#039;t believe that JetBlue does that.
That was truly a horrid online experience.
I was convinced that it was a phishing scam.
Why the hell are they asking for SS digits?</description>
		<content:encoded><![CDATA[<p>I can&#8217;t believe that JetBlue does that.<br />
That was truly a horrid online experience.<br />
I was convinced that it was a phishing scam.<br />
Why the hell are they asking for SS digits?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric Baird</title>
		<link>http://paddymullen.com/2009/05/21/yaron-shohat/#comment-2063</link>
		<dc:creator>Eric Baird</dc:creator>
		<pubDate>Fri, 25 Dec 2009 20:32:24 +0000</pubDate>
		<guid isPermaLink="false">http://paddymullen.com/?p=77#comment-2063</guid>
		<description>Yep, there seem to be people running critical stuff at Visa who appear to know nothing about internet security.

We&#039;re told never to enter our card details into an unknown popup window, and then Visa&#039;s securty system asks us to do exactly that. We&#039;re told that if we&#039;re dealing with a reputable financial company, they&#039;ll NEVER suddenly switch us to an unfamiliar domain name mid-way through a transaction. And that&#039;s exactly what Visa does. Who the hell are securesuite? Never heard of them. Why isn&#039;t the Domain explicitly a Visa site? That&#039;d at least give us the comfort of knowing that if the domain was fraudulently labelled, that the owners were probably comitting an offence  somehow. But if you enter your card details into a completely unknown domain whose name doesn&#039;t hook up to anything you&#039;ve ever heard of, and it goes wrong, then that&#039;s negligence on your part. We&#039;re told that any user who&#039;d do this is behaving irresponsibly. But they still ask us to do it.

And it gets even worse. 
One of the giveaway signs of a phishing site is that their domain is one letter away from that of another &quot;respectable&quot; domain (say, micrcsoft.com). &quot;Securesuite&quot; sounds like a one-letter spin on &quot;securesite&quot;, so the name immediately sets alarm bells ringing. 

So who the hell at Visa doesn&#039;t know these things? And what the hell are they doing being allowed to set up redirects and javascript stuff on a Visa security site?</description>
		<content:encoded><![CDATA[<p>Yep, there seem to be people running critical stuff at Visa who appear to know nothing about internet security.</p>
<p>We&#8217;re told never to enter our card details into an unknown popup window, and then Visa&#8217;s securty system asks us to do exactly that. We&#8217;re told that if we&#8217;re dealing with a reputable financial company, they&#8217;ll NEVER suddenly switch us to an unfamiliar domain name mid-way through a transaction. And that&#8217;s exactly what Visa does. Who the hell are securesuite? Never heard of them. Why isn&#8217;t the Domain explicitly a Visa site? That&#8217;d at least give us the comfort of knowing that if the domain was fraudulently labelled, that the owners were probably comitting an offence  somehow. But if you enter your card details into a completely unknown domain whose name doesn&#8217;t hook up to anything you&#8217;ve ever heard of, and it goes wrong, then that&#8217;s negligence on your part. We&#8217;re told that any user who&#8217;d do this is behaving irresponsibly. But they still ask us to do it.</p>
<p>And it gets even worse.<br />
One of the giveaway signs of a phishing site is that their domain is one letter away from that of another &#8220;respectable&#8221; domain (say, micrcsoft.com). &#8220;Securesuite&#8221; sounds like a one-letter spin on &#8220;securesite&#8221;, so the name immediately sets alarm bells ringing. </p>
<p>So who the hell at Visa doesn&#8217;t know these things? And what the hell are they doing being allowed to set up redirects and javascript stuff on a Visa security site?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

