RE: [OT] Citibank worse at security than Sony

2011-06-16 Thread Steven M. Caesare
looks pretty amateurish. But things always go > wrong in large IT shops. > > -Original Message- > From: Ben Scott [mailto:mailvor...@gmail.com] > Sent: Wednesday, 15 June 2011 7:55 PM > To: NT System Admin Issues > Subject: Re: [OT] Citibank worse at security than Sony &

RE: [OT] Citibank worse at security than Sony

2011-06-16 Thread Steven M. Caesare
Egads. And oof. -sc > -Original Message- > From: Ben Scott [mailto:mailvor...@gmail.com] > Sent: Tuesday, June 14, 2011 11:36 PM > To: NT System Admin Issues > Subject: [OT] Citibank worse at security than Sony > > So... 200,000 or so Citigroup customers have

Re: [OT] Citibank worse at security than Sony

2011-06-16 Thread Ben Scott
On Wed, Jun 15, 2011 at 10:55 AM, Free, Bob wrote: > If recent history is any indicator, they will get a big bailout for their > malfeasance, any indiscretions will be ignored by regulators, they will pat > themselves on the back with huge bonuses for weathering the storm, and the > consumer will

Re: [OT] Citibank worse at security than Sony

2011-06-16 Thread Ben Scott
On Wed, Jun 15, 2011 at 10:52 AM, Andrew S. Baker wrote: > Well, we (collective we) have to stop giving them easy outs. > > They find ways to make sure that they can use hot-off-the-presses technology > to get order entry or other more-direct-to-revenue projects done, and heads > roll appropriatel

Re: [OT] Citibank worse at security than Sony

2011-06-16 Thread Ben Scott
On Wed, Jun 15, 2011 at 10:46 AM, Ken Schaefer wrote: > ... 10 years ago. If that’s when the app was developed, the programmers > probably > didn’t know better ... That excuse gets tossed around a lot -- "we weren't being attacked then", or "this is a new threat". I consider it bull. Compu

Re: [OT] Citibank worse at security than Sony

2011-06-16 Thread Ben Scott
On Wed, Jun 15, 2011 at 8:17 AM, Ken Schaefer wrote: > You can push all you like. But it's not your area of expertise. So you rely > on other people to tell you that the app works well. Things will always still > slip through the cracks. This isn't something that "slipped through the cracks".

Re: [OT] Citibank worse at security than Sony

2011-06-15 Thread Jonathan Link
h Sony, one has to wonder where their priorities are with data >> protection .. >> >> >> >> a >> >> -Original Message- >> From: Matthew B Ames [mailto:matthew.a...@qinetiq.com] >> Sent: 15 June 2011 07:24 >> To: NT System

RE: [OT] Citibank worse at security than Sony

2011-06-15 Thread Guyer, Don
x: 610-233-0404 www.fiserv.com <http://www.fiserv.com/> From: Alan Davies [mailto:adav...@cls-services.com] Sent: Wednesday, June 15, 2011 11:19 AM To: NT System Admin Issues Subject: RE: [OT] Citibank worse at security than Sony Just to point out the obvious - Citi are FS, ie.

RE: [OT] Citibank worse at security than Sony

2011-06-15 Thread Alan Davies
this bad and slip through un-noticed for any period of time! a From: Ken Schaefer [mailto:k...@adopenstatic.com] Sent: 15 June 2011 15:46 To: NT System Admin Issues Subject: RE: [OT] Citibank worse at security than Sony Probably. But some executive sponsor

Re: [OT] Citibank worse at security than Sony

2011-06-15 Thread Andrew S. Baker
t; > > > *From:* Andrew S. Baker [mailto:asbz...@gmail.com] > *Sent:* Wednesday, June 15, 2011 4:31 AM > > *To:* NT System Admin Issues > *Subject:* Re: [OT] Citibank worse at security than Sony > > > > *>>**As with Sony, one has to wonder where their pr

RE: [OT] Citibank worse at security than Sony

2011-06-15 Thread Free, Bob
. From: Andrew S. Baker [mailto:asbz...@gmail.com] Sent: Wednesday, June 15, 2011 4:31 AM To: NT System Admin Issues Subject: Re: [OT] Citibank worse at security than Sony >>As with Sony, one has to wonder where their priorities are with data >>protection .. It's all about sha

Re: [OT] Citibank worse at security than Sony

2011-06-15 Thread Andrew S. Baker
ate by the time the next refresh > project is entering kick-off meetings. > > > > Cheers > > Ken > > > > *From:* Andrew S. Baker [mailto:asbz...@gmail.com] > *Sent:* Wednesday, 15 June 2011 9:48 PM > > *To:* NT System Admin Issues > *Subject:* Re: [OT]

RE: [OT] Citibank worse at security than Sony

2011-06-15 Thread Ken Schaefer
hs ago when you started the project is obsolete by the time it's installed, and completely out-of-date by the time the next refresh project is entering kick-off meetings. Cheers Ken From: Andrew S. Baker [mailto:asbz...@gmail.com] Sent: Wednesday, 15 June 2011 9:48 PM To: NT System Admin Issu

Re: [OT] Citibank worse at security than Sony

2011-06-15 Thread Andrew S. Baker
; > > > Cheers > > Ken > > > > *From:* Andrew S. Baker [mailto:asbz...@gmail.com] > *Sent:* Wednesday, 15 June 2011 7:31 PM > > *To:* NT System Admin Issues > *Subject:* Re: [OT] Citibank worse at security than Sony > > > > *>>**As with Sony, o

RE: [OT] Citibank worse at security than Sony

2011-06-15 Thread Ziots, Edward
static.com] Sent: Wednesday, June 15, 2011 12:20 AM To: NT System Admin Issues Subject: RE: [OT] Citibank worse at security than Sony I doubt any fat cat bankers signed off, knowingly, on an insecure site. People going to jail would be the IT folks who should have known better. That said, do you kn

RE: [OT] Citibank worse at security than Sony

2011-06-15 Thread Ken Schaefer
e IT shops. -Original Message- From: Ben Scott [mailto:mailvor...@gmail.com] Sent: Wednesday, 15 June 2011 7:55 PM To: NT System Admin Issues Subject: Re: [OT] Citibank worse at security than Sony On Wed, Jun 15, 2011 at 7:39 AM, Ken Schaefer wrote: > Hmm - at the individual application developm

Re: [OT] Citibank worse at security than Sony

2011-06-15 Thread Ben Scott
On Wed, Jun 15, 2011 at 7:39 AM, Ken Schaefer wrote: > Hmm – at the individual application development level, in a large org, no > one cares about shareholder value. That's why the people at the top need to be the ones pushing for security. It can't be driven from the bottom. -- Ben ~ Finall

Re: [OT] Citibank worse at security than Sony

2011-06-15 Thread Ben Scott
On Wed, Jun 15, 2011 at 12:19 AM, Ken Schaefer wrote: > I doubt any fat cat bankers signed off, knowingly, on an insecure site. I don't think they said "make the site insecure", but they're the ones responsible[1] for the security of their systems, and they're the ones that set priorities for t

RE: [OT] Citibank worse at security than Sony

2011-06-15 Thread Ken Schaefer
ather than actually trying to attack your application) Cheers Ken From: Andrew S. Baker [mailto:asbz...@gmail.com] Sent: Wednesday, 15 June 2011 7:31 PM To: NT System Admin Issues Subject: Re: [OT] Citibank worse at security than Sony >>As with Sony, one has to wonder where their priorities ar

Re: [OT] Citibank worse at security than Sony

2011-06-15 Thread Andrew S. Baker
eir priorities are with data > protection .. > > > > a > > -Original Message- > From: Matthew B Ames [mailto:matthew.a...@qinetiq.com] > Sent: 15 June 2011 07:24 > To: NT System Admin Issues > Subject: RE: [OT] Citibank worse at security than Sony > > As a s

RE: [OT] Citibank worse at security than Sony

2011-06-15 Thread Matthew B Ames
-- From: Alan Davies [mailto:adav...@cls-services.com] Sent: 15 June 2011 10:31 To: NT System Admin Issues Subject: RE: [OT] Citibank worse at security than Sony What floors me is how sophisticated they are saying the attack is! Honestly, this article makes me so angry! http://www.nytimes.com/2

RE: [OT] Citibank worse at security than Sony

2011-06-15 Thread Alan Davies
netiq.com] Sent: 15 June 2011 07:24 To: NT System Admin Issues Subject: RE: [OT] Citibank worse at security than Sony As a software engineer I would feel rather guilty to develop a system that was that poor. I used to have a Citi credit card. I had better check it is no long active. -Origin

RE: [OT] Citibank worse at security than Sony

2011-06-14 Thread Matthew B Ames
Subject: [OT] Citibank worse at security than Sony So... 200,000 or so Citigroup customers have had their person info stolen. Someone logged in to one account properly, then changed the account number in the URL to someone else, and the site happily served up that account instead. I hesitate

RE: [OT] Citibank worse at security than Sony

2011-06-14 Thread Ken Schaefer
Scott [mailto:mailvor...@gmail.com] Sent: Wednesday, 15 June 2011 11:36 AM To: NT System Admin Issues Subject: [OT] Citibank worse at security than Sony So... 200,000 or so Citigroup customers have had their person info stolen. Someone logged in to one account properly, then changed the account numb

[OT] Citibank worse at security than Sony

2011-06-14 Thread Ben Scott
So... 200,000 or so Citigroup customers have had their person info stolen. Someone logged in to one account properly, then changed the account number in the URL to someone else, and the site happily served up that account instead. I hesitate to even call the first party an "attacker". Is it re