<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Discussion on Remove ING DIRECT Security Through Obscurity | Userscripts.org</title>
    <link>http://userscripts.org/scripts/show/3998</link>
    <description>Recent comments on userscript: Remove ING DIRECT Security Through Obscurity</description>
    <language>en-us</language>
    <ttl>60</ttl>
    <item>
      <title>Archived Comments, replied by Matthew Flaschen</title>
      <description>&lt;p&gt;I've uploaded a new version that works with the latest ING site updates.&lt;/p&gt;</description>
      <pubDate>Sun, 28 Sep 2008 15:53:50 +0000</pubDate>
      <guid isPermaLink="false">userscripts.org:12751:38006</guid>
      <author>Matthew Flaschen</author>
      <link>http://userscripts.org/posts/38006</link>
    </item>
    <item>
      <title>Archived Comments, replied by Jon K</title>
      <description>&lt;p&gt;Matthew,&lt;/p&gt;

&lt;p&gt;Could you write a script that would allow me to sort the &quot;View my Account&quot; table by Account Nickname, Balance, or Available Balance?&lt;/p&gt;</description>
      <pubDate>Thu, 21 Jun 2007 17:00:26 +0000</pubDate>
      <guid isPermaLink="false">userscripts.org:12751:38007</guid>
      <author>Jon K</author>
      <link>http://userscripts.org/posts/38007</link>
    </item>
    <item>
      <title>Archived Comments, replied by Matthew Flaschen</title>
      <description>&lt;p&gt;I've updated it to work on the new ING login page, and added a function.  When ING enrolls me in the &quot;&lt;a href=&quot;https://secure.ingdirect.com/myaccount/StaticContent.html?start=https://home.ingdirect.com/privacy/privacy_security.asp?s=PrivacyPolicy[[s_and]]nf=false&quot;&gt;new security feature&quot;&lt;/a&gt;, I'm planning to post a proof of concept exploit for that too.  It seems fundamentally flawed.  They have to show you the picture and phrase before authenticating you, so an unauthenticated adversary has that data available to phish with.  I don't know what the details are, but this problem seems unavoidable.&lt;/p&gt;</description>
      <pubDate>Wed, 26 Jul 2006 13:19:15 +0000</pubDate>
      <guid isPermaLink="false">userscripts.org:12751:38008</guid>
      <author>Matthew Flaschen</author>
      <link>http://userscripts.org/posts/38008</link>
    </item>
    <item>
      <title>Archived Comments, replied by Matthew Flaschen</title>
      <description>&lt;p&gt;Thank you.  It was meant as a proof of concept as much as anything else, though I do use it (but only on my own computer).&lt;/p&gt;</description>
      <pubDate>Mon, 08 May 2006 22:02:00 +0000</pubDate>
      <guid isPermaLink="false">userscripts.org:12751:38009</guid>
      <author>Matthew Flaschen</author>
      <link>http://userscripts.org/posts/38009</link>
    </item>
    <item>
      <title>Archived Comments, replied by Julien Couvreur</title>
      <description>&lt;p&gt;The virtual keyboard does mitigate the key logger threat.
&lt;br /&gt;Admitedly, other threats remain, such a software recorder. But imo the ING Direct login screen is not useless.&lt;/p&gt;

&lt;p&gt;Nice script though.&lt;/p&gt;</description>
      <pubDate>Tue, 02 May 2006 19:39:31 +0000</pubDate>
      <guid isPermaLink="false">userscripts.org:12751:38010</guid>
      <author>Julien Couvreur</author>
      <link>http://userscripts.org/posts/38010</link>
    </item>
    <item>
      <title>Archived Comments, replied by Jesse Andrews</title>
      <description>&lt;p&gt;The following is an archive of comments made before threaded discussions was implemented (November 16th, 2008)&lt;/p&gt;</description>
      <pubDate>Wed, 17 Nov 2004 01:05:04 +0000</pubDate>
      <guid isPermaLink="false">userscripts.org:12751:38005</guid>
      <author>Jesse Andrews</author>
      <link>http://userscripts.org/posts/38005</link>
    </item>
  </channel>
</rss>
