<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Navy Federal Credit Union Web Site Operating with Security Issue</title>
	<atom:link href="http://techmiso.com/2434/navy-federal-credit-union-web-site-operating-with-security-issue/feed/" rel="self" type="application/rss+xml" />
	<link>http://techmiso.com/2434/navy-federal-credit-union-web-site-operating-with-security-issue/</link>
	<description>Tech evangelism and Miso soup like no other</description>
	<lastBuildDate>Fri, 12 Mar 2010 14:33:01 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bank Jobs Dubai</title>
		<link>http://techmiso.com/2434/navy-federal-credit-union-web-site-operating-with-security-issue/comment-page-1/#comment-5096</link>
		<dc:creator>Bank Jobs Dubai</dc:creator>
		<pubDate>Sat, 30 Jan 2010 09:08:25 +0000</pubDate>
		<guid isPermaLink="false">http://techmiso.com/?p=2434#comment-5096</guid>
		<description>This site will be interesting specially for the student.</description>
		<content:encoded><![CDATA[<p>This site will be interesting specially for the student.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dubai Job</title>
		<link>http://techmiso.com/2434/navy-federal-credit-union-web-site-operating-with-security-issue/comment-page-1/#comment-5020</link>
		<dc:creator>Dubai Job</dc:creator>
		<pubDate>Thu, 07 Jan 2010 10:00:57 +0000</pubDate>
		<guid isPermaLink="false">http://techmiso.com/?p=2434#comment-5020</guid>
		<description>lots of credit, thats why we are facing this worst economic&lt;br&gt;condition these days. i hope we can have a solution regarding &lt;br&gt;this matter.</description>
		<content:encoded><![CDATA[<p>lots of credit, thats why we are facing this worst economic<br />condition these days. i hope we can have a solution regarding <br />this matter.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mfarney</title>
		<link>http://techmiso.com/2434/navy-federal-credit-union-web-site-operating-with-security-issue/comment-page-1/#comment-2940</link>
		<dc:creator>mfarney</dc:creator>
		<pubDate>Wed, 23 Dec 2009 03:48:25 +0000</pubDate>
		<guid isPermaLink="false">http://techmiso.com/?p=2434#comment-2940</guid>
		<description>When it comes to banking and people&#039;s money there shouldn&#039;t be such problems. I use internet banking all the time and if I heard my bank had such a problem I&#039;d probably find myself another one to handle my earnings. &lt;br&gt;__________________ &lt;br&gt;Mathew Farney - &lt;a rel=&quot;follow&quot; href=&quot;http://www.123-reg.co.uk/web-hosting/&quot; rel=&quot;nofollow&quot;&gt;Web Hosting&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>When it comes to banking and people&#39;s money there shouldn&#39;t be such problems. I use internet banking all the time and if I heard my bank had such a problem I&#39;d probably find myself another one to handle my earnings. <br />__________________ <br />Mathew Farney &#8211; <a rel="follow" href="http://www.123-reg.co.uk/web-hosting/" rel="nofollow">Web Hosting</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris H</title>
		<link>http://techmiso.com/2434/navy-federal-credit-union-web-site-operating-with-security-issue/comment-page-1/#comment-1239</link>
		<dc:creator>Chris H</dc:creator>
		<pubDate>Fri, 04 Sep 2009 03:42:24 +0000</pubDate>
		<guid isPermaLink="false">http://techmiso.com/?p=2434#comment-1239</guid>
		<description>I&#039;m glad to see this is resolved!  I&#039;m also glad to see that NFCU has finally secured their home page also with SSL.  Although they only have secured &lt;a href=&quot;http://www.navyfederal.org&quot; rel=&quot;nofollow&quot;&gt;http://www.navyfederal.org&lt;/a&gt;  All the other sites (&lt;a href=&quot;http://navyfcu.org&quot; rel=&quot;nofollow&quot;&gt;navyfcu.org&lt;/a&gt;, &lt;a href=&quot;http://nfcu.org&quot; rel=&quot;nofollow&quot;&gt;nfcu.org&lt;/a&gt;, etc) throw SSL certificate errors.  Not exactly how I would have configured the web server for best customer experience, but effective.&lt;br&gt;On another note, if you are online banking no matter what the institution,  YOU NEED TO PAY ATTENTION TO EVERY LITTLE ERROR, POP UP AND THE SUCH ON THE WEBSITE!!!!  Most folks will ignote the SSL Certificate error that pops up when you visit &lt;a href=&quot;http://navyfcu.org&quot; rel=&quot;nofollow&quot;&gt;navyfcu.org&lt;/a&gt;, &lt;a href=&quot;http://nfcu.org&quot; rel=&quot;nofollow&quot;&gt;nfcu.org&lt;/a&gt; or others.  This is not good!  If you get a pop up like that, call the institution!!  If you don&#039;t see the lock icon for the site... Call the institution!!  Navy Federal was very succeptable to spoofing and man in the middle attacks by offering the login prompt on an insucure page.  Someone could have developed the exact same page and logged all the credentials that were used without even the user knowing.&lt;br&gt;I have been, and always will be a loyal NFCU member.  They&#039;re definitely one of the better financial institutions out there.</description>
		<content:encoded><![CDATA[<p>I&#39;m glad to see this is resolved!  I&#39;m also glad to see that NFCU has finally secured their home page also with SSL.  Although they only have secured <a href="http://www.navyfederal.org" rel="nofollow">http://www.navyfederal.org</a>  All the other sites (<a href="http://navyfcu.org" rel="nofollow">navyfcu.org</a>, <a href="http://nfcu.org" rel="nofollow">nfcu.org</a>, etc) throw SSL certificate errors.  Not exactly how I would have configured the web server for best customer experience, but effective.<br />On another note, if you are online banking no matter what the institution,  YOU NEED TO PAY ATTENTION TO EVERY LITTLE ERROR, POP UP AND THE SUCH ON THE WEBSITE!!!!  Most folks will ignote the SSL Certificate error that pops up when you visit <a href="http://navyfcu.org" rel="nofollow">navyfcu.org</a>, <a href="http://nfcu.org" rel="nofollow">nfcu.org</a> or others.  This is not good!  If you get a pop up like that, call the institution!!  If you don&#39;t see the lock icon for the site&#8230; Call the institution!!  Navy Federal was very succeptable to spoofing and man in the middle attacks by offering the login prompt on an insucure page.  Someone could have developed the exact same page and logged all the credentials that were used without even the user knowing.<br />I have been, and always will be a loyal NFCU member.  They&#39;re definitely one of the better financial institutions out there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Jarkoff</title>
		<link>http://techmiso.com/2434/navy-federal-credit-union-web-site-operating-with-security-issue/comment-page-1/#comment-1222</link>
		<dc:creator>Scott Jarkoff</dc:creator>
		<pubDate>Sun, 30 Aug 2009 19:47:24 +0000</pubDate>
		<guid isPermaLink="false">http://techmiso.com/?p=2434#comment-1222</guid>
		<description>While I completely sympathize with your situation, it is not the intent of this post to bring up Navy Federal banking policies. &lt;br&gt;&lt;br&gt;Our primary concern was the prospect of NFCU customers being phished, no thanks to their shoddy web site security. This appears to have been addressed and we are, as all NFCU customers should be, thankful.&lt;br&gt;&lt;br&gt;I wish you the best of luck resolving your issue. Nobody should have to deal with incorrect charges, especially if it is the fault of the bank.</description>
		<content:encoded><![CDATA[<p>While I completely sympathize with your situation, it is not the intent of this post to bring up Navy Federal banking policies. </p>
<p>Our primary concern was the prospect of NFCU customers being phished, no thanks to their shoddy web site security. This appears to have been addressed and we are, as all NFCU customers should be, thankful.</p>
<p>I wish you the best of luck resolving your issue. Nobody should have to deal with incorrect charges, especially if it is the fault of the bank.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Jarkoff</title>
		<link>http://techmiso.com/2434/navy-federal-credit-union-web-site-operating-with-security-issue/comment-page-1/#comment-1224</link>
		<dc:creator>Scott Jarkoff</dc:creator>
		<pubDate>Sun, 30 Aug 2009 19:44:14 +0000</pubDate>
		<guid isPermaLink="false">http://techmiso.com/?p=2434#comment-1224</guid>
		<description>The RSA email sent to our hosting provider, SliceHost, was sent after the purported response by NFCU in the comments. This was part of Update 2 above.&lt;br&gt;&lt;br&gt;I did not cover the SSL warning because I have not directly run across that issue. Rich had mentioned to me he saw something similar but then realized it was due to &lt;a href=&quot;http://navyfcu.org/&quot; rel=&quot;nofollow&quot;&gt;http://navyfcu.org/&lt;/a&gt; being the URL used to visit the site rather than &lt;a href=&quot;http://www.navyfcu.org/&quot; rel=&quot;nofollow&quot;&gt;http://www.navyfcu.org/&lt;/a&gt;. It seems the company is not automatically redirecting the former to the latter as they should, but that should not matter since, as you mentioned, Firefox issues a warning to the user.</description>
		<content:encoded><![CDATA[<p>The RSA email sent to our hosting provider, SliceHost, was sent after the purported response by NFCU in the comments. This was part of Update 2 above.</p>
<p>I did not cover the SSL warning because I have not directly run across that issue. Rich had mentioned to me he saw something similar but then realized it was due to <a href="http://navyfcu.org/" rel="nofollow">http://navyfcu.org/</a> being the URL used to visit the site rather than <a href="http://www.navyfcu.org/" rel="nofollow">http://www.navyfcu.org/</a>. It seems the company is not automatically redirecting the former to the latter as they should, but that should not matter since, as you mentioned, Firefox issues a warning to the user.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: facebook-500341233</title>
		<link>http://techmiso.com/2434/navy-federal-credit-union-web-site-operating-with-security-issue/comment-page-1/#comment-1223</link>
		<dc:creator>facebook-500341233</dc:creator>
		<pubDate>Sun, 30 Aug 2009 19:32:59 +0000</pubDate>
		<guid isPermaLink="false">http://techmiso.com/?p=2434#comment-1223</guid>
		<description>Did the RSA e-mail come before or after the purported response from NFCU in the comments?&lt;br&gt;&lt;br&gt;Also, have you covered that &lt;a href=&quot;http://www.nfcu.org&quot; rel=&quot;nofollow&quot;&gt;www.nfcu.org&lt;/a&gt; fires a SSL warning on Firefox and iPhone for using the wrong cert?  They had this issue fixed, but it popped up again starting about a week or so ago.  &lt;a href=&quot;http://NavyFederal.org&quot; rel=&quot;nofollow&quot;&gt;NavyFederal.org&lt;/a&gt; does not fire the warning.</description>
		<content:encoded><![CDATA[<p>Did the RSA e-mail come before or after the purported response from NFCU in the comments?</p>
<p>Also, have you covered that <a href="http://www.nfcu.org" rel="nofollow">http://www.nfcu.org</a> fires a SSL warning on Firefox and iPhone for using the wrong cert?  They had this issue fixed, but it popped up again starting about a week or so ago.  <a href="http://NavyFederal.org" rel="nofollow">NavyFederal.org</a> does not fire the warning.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: facebook-42604282</title>
		<link>http://techmiso.com/2434/navy-federal-credit-union-web-site-operating-with-security-issue/comment-page-1/#comment-1214</link>
		<dc:creator>facebook-42604282</dc:creator>
		<pubDate>Fri, 21 Aug 2009 16:49:52 +0000</pubDate>
		<guid isPermaLink="false">http://techmiso.com/?p=2434#comment-1214</guid>
		<description>I am probably a victim of NFCU&#039;s security &quot;oversight&quot; and now they are charging ME for their mistake with overcharges totalling close to $300 in one week!  Way to treat those serving our Country NFCU.</description>
		<content:encoded><![CDATA[<p>I am probably a victim of NFCU&#39;s security &#8220;oversight&#8221; and now they are charging ME for their mistake with overcharges totalling close to $300 in one week!  Way to treat those serving our Country NFCU.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DonaldWelker</title>
		<link>http://techmiso.com/2434/navy-federal-credit-union-web-site-operating-with-security-issue/comment-page-1/#comment-1209</link>
		<dc:creator>DonaldWelker</dc:creator>
		<pubDate>Thu, 20 Aug 2009 22:49:11 +0000</pubDate>
		<guid isPermaLink="false">http://techmiso.com/?p=2434#comment-1209</guid>
		<description>I would not argue that RSA&#039;s claims are not inaccurate and exaggerated, thus my statement that I don&#039;t concur with their actions. I am not surprised, because it is my impression that RSA is getting paid to troll the Net looking for their clients&#039; logos being used without express permission, and then to send the sort of notices you received -- which would be independent of the actual point of your blog. &lt;br&gt;&lt;br&gt;You didn&#039;t just put the picture up though, you linked it to something other than the logo owner. Now, I would expect that RSA would still have dinged you if you had linked the picture to NFCU, but perhaps it would have been worded differently (I think we both realize those notices are probably scripted). I don&#039;t argue that your usage is not fair use; IMO RSA should have referred this to NFCU to decide whether to pursue it or not.</description>
		<content:encoded><![CDATA[<p>I would not argue that RSA&#39;s claims are not inaccurate and exaggerated, thus my statement that I don&#39;t concur with their actions. I am not surprised, because it is my impression that RSA is getting paid to troll the Net looking for their clients&#39; logos being used without express permission, and then to send the sort of notices you received &#8212; which would be independent of the actual point of your blog. </p>
<p>You didn&#39;t just put the picture up though, you linked it to something other than the logo owner. Now, I would expect that RSA would still have dinged you if you had linked the picture to NFCU, but perhaps it would have been worded differently (I think we both realize those notices are probably scripted). I don&#39;t argue that your usage is not fair use; IMO RSA should have referred this to NFCU to decide whether to pursue it or not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Jarkoff</title>
		<link>http://techmiso.com/2434/navy-federal-credit-union-web-site-operating-with-security-issue/comment-page-1/#comment-1207</link>
		<dc:creator>Scott Jarkoff</dc:creator>
		<pubDate>Tue, 18 Aug 2009 16:07:37 +0000</pubDate>
		<guid isPermaLink="false">http://techmiso.com/?p=2434#comment-1207</guid>
		<description>I&#039;m struggling to follow your logic.&lt;br&gt;&lt;br&gt;Fair use allows us to use their logo in the manner utilized. We&#039;re&lt;br&gt;using the logo as part of an image of the NFCU web site and nothing&lt;br&gt;more.&lt;br&gt;&lt;br&gt;When clicked, the image merely takes visitors to an article on&lt;br&gt;TechMiso with the design looking absolutely nothing like the official&lt;br&gt;NFCU web site. Nowhere does TechMiso make an attempt to confuse users&lt;br&gt;in to believing they are visiting an officially sanctioned NFCU web&lt;br&gt;site. Furthermore, we make no attempt to phish NFCU customers.&lt;br&gt;&lt;br&gt;Based on the manner in which you worded your comment, are you&lt;br&gt;stipulating that the use of any company&#039;s logo may only follow what&lt;br&gt;that company considers acceptable?&lt;br&gt;&lt;br&gt;Please clarify why you are finding it so difficult to be surprised at&lt;br&gt;RSA&#039;s actions, especially considering _all_ the claims they had&lt;br&gt;attempted to making.</description>
		<content:encoded><![CDATA[<p>I&#39;m struggling to follow your logic.</p>
<p>Fair use allows us to use their logo in the manner utilized. We&#39;re<br />using the logo as part of an image of the NFCU web site and nothing<br />more.</p>
<p>When clicked, the image merely takes visitors to an article on<br />TechMiso with the design looking absolutely nothing like the official<br />NFCU web site. Nowhere does TechMiso make an attempt to confuse users<br />in to believing they are visiting an officially sanctioned NFCU web<br />site. Furthermore, we make no attempt to phish NFCU customers.</p>
<p>Based on the manner in which you worded your comment, are you<br />stipulating that the use of any company&#39;s logo may only follow what<br />that company considers acceptable?</p>
<p>Please clarify why you are finding it so difficult to be surprised at<br />RSA&#39;s actions, especially considering _all_ the claims they had<br />attempted to making.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
