<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>What The Hell? Security &#187; fraud</title>
	<atom:link href="http://whatthehellsecurity.com/category/fraud/feed/" rel="self" type="application/rss+xml" />
	<link>http://whatthehellsecurity.com</link>
	<description>startling new ways of thinking about security</description>
	<lastBuildDate>Wed, 16 Feb 2011 08:38:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='whatthehellsecurity.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>What The Hell? Security &#187; fraud</title>
		<link>http://whatthehellsecurity.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://whatthehellsecurity.com/osd.xml" title="What The Hell? Security" />
	<atom:link rel='hub' href='http://whatthehellsecurity.com/?pushpress=hub'/>
		<item>
		<title>When Security is Bad for Security</title>
		<link>http://whatthehellsecurity.com/2010/09/21/when-security-is-bad-for-security/</link>
		<comments>http://whatthehellsecurity.com/2010/09/21/when-security-is-bad-for-security/#comments</comments>
		<pubDate>Tue, 21 Sep 2010 20:32:50 +0000</pubDate>
		<dc:creator>hell if i know</dc:creator>
				<category><![CDATA[fraud]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security sense]]></category>
		<category><![CDATA[security soapbox]]></category>

		<guid isPermaLink="false">http://whatthehellsecurity.com/?p=2037</guid>
		<description><![CDATA[Copyright © What The Hell? Security There are 3 kinds of security in business:  Good security, acceptable security and bad security. Good security is the kind that works for the business and for the people who work in it.  It aligns with universally known objectives, and is communicated in a way that motivates people to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whatthehellsecurity.com&amp;blog=8356378&amp;post=2037&amp;subd=whatthehellsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://whatthehellsecurity.com/2010/09/21/when-security-is-bad-for-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ljh</media:title>
		</media:content>

		<media:content url="http://whatthehellsecurity.files.wordpress.com/2010/09/chase-email1.png?w=150" medium="image">
			<media:title type="html">chase-email</media:title>
		</media:content>
	</item>
		<item>
		<title>VeriSign Says “What The Hell? Security” Blogger Was Right</title>
		<link>http://whatthehellsecurity.com/2010/06/08/verisign-says-what-the-hell-security-blogger-was-right/</link>
		<comments>http://whatthehellsecurity.com/2010/06/08/verisign-says-what-the-hell-security-blogger-was-right/#comments</comments>
		<pubDate>Tue, 08 Jun 2010 07:13:12 +0000</pubDate>
		<dc:creator>hell if i know</dc:creator>
				<category><![CDATA[certificate authorities]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false">http://whatthehellsecurity.com/?p=1723</guid>
		<description><![CDATA[Copyright © What The Hell? Security MOUNTING VIEW, June 7, 2010 &#8212; VeriSign today acknowledged that the real reason it sold its Authentication Services business to Symantec is that it felt remorse over its SSL bribing business model after reading a post at What The Hell? Security. &#8220;Once that What The Hell? Security guy exposed us, we knew [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whatthehellsecurity.com&amp;blog=8356378&amp;post=1723&amp;subd=whatthehellsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://whatthehellsecurity.com/2010/06/08/verisign-says-what-the-hell-security-blogger-was-right/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ljh</media:title>
		</media:content>

		<media:content url="http://whatthehellsecurity.files.wordpress.com/2010/06/dollar-sign-logo.png?w=300" medium="image">
			<media:title type="html">dollar-sign-logo</media:title>
		</media:content>
	</item>
		<item>
		<title>Phishing: Full or Responsible Disclosure?</title>
		<link>http://whatthehellsecurity.com/2010/05/16/phishing-full-or-responsible-disclosure/</link>
		<comments>http://whatthehellsecurity.com/2010/05/16/phishing-full-or-responsible-disclosure/#comments</comments>
		<pubDate>Mon, 17 May 2010 06:20:16 +0000</pubDate>
		<dc:creator>hell if i know</dc:creator>
				<category><![CDATA[fraud]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://whatthehellsecurity.com/?p=1628</guid>
		<description><![CDATA[Copyright © What The Hell? Security I&#8217;m on the horns of a dilemma. I&#8217;ve come up with a few phishing use cases not yet witnessed in the wild. Should I exercise full disclosure or responsible disclosure? That&#8217;s a completely nonsensical question of course. Who the hell would I report it to? Onguard Online? Phishtank? APWG?&#160; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whatthehellsecurity.com&amp;blog=8356378&amp;post=1628&amp;subd=whatthehellsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://whatthehellsecurity.com/2010/05/16/phishing-full-or-responsible-disclosure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ljh</media:title>
		</media:content>

		<media:content url="http://whatthehellsecurity.files.wordpress.com/2010/06/disclosure.png?w=147" medium="image">
			<media:title type="html">disclosure</media:title>
		</media:content>
	</item>
		<item>
		<title>Fishing for Red Herring Phishing Solutions</title>
		<link>http://whatthehellsecurity.com/2010/04/13/fishing-for-red-herring-phishing-solutions/</link>
		<comments>http://whatthehellsecurity.com/2010/04/13/fishing-for-red-herring-phishing-solutions/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 19:34:12 +0000</pubDate>
		<dc:creator>hell if i know</dc:creator>
				<category><![CDATA[certificate authorities]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false">http://whatthehellsecurity.com/?p=1478</guid>
		<description><![CDATA[We interrupt The 9 Laws of Phishing to bring you two important questions sponsored by the Incorrectly-Thinks-Email-Is-Broken Coalition, newly joined by eCert. Question 1: What is the most dangerous sport? Boxing?  Sky diving?  Running with the bulls in Pamplona? Answer: Whatever you said, you weren&#8217;t even close.  It&#8217;s fishing.  No kidding.  Fishers experience more per [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whatthehellsecurity.com&amp;blog=8356378&amp;post=1478&amp;subd=whatthehellsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://whatthehellsecurity.com/2010/04/13/fishing-for-red-herring-phishing-solutions/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ljh</media:title>
		</media:content>

		<media:content url="http://whatthehellsecurity.files.wordpress.com/2010/04/anti-herring.png?w=135" medium="image">
			<media:title type="html">anti-herring</media:title>
		</media:content>
	</item>
		<item>
		<title>Bit.ly Fantasizes of Combating Twitter Scams</title>
		<link>http://whatthehellsecurity.com/2009/12/08/bit-ly-fantasizes-of-combating-twitter-scams/</link>
		<comments>http://whatthehellsecurity.com/2009/12/08/bit-ly-fantasizes-of-combating-twitter-scams/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 03:18:01 +0000</pubDate>
		<dc:creator>hell if i know</dc:creator>
				<category><![CDATA[fraud]]></category>
		<category><![CDATA[hypertext]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security soapbox]]></category>

		<guid isPermaLink="false">http://whatthehellsecurity.com/?p=974</guid>
		<description><![CDATA[Copyright © 2009 What The Hell? Security If you believe that Bit.ly is going to solve their shortened URL problem the way they intend to, have I got a story for you. [Sidebar:  Be aware that it's completely safe to click on the links in the previous paragraph.  If you don't believe me, select View [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whatthehellsecurity.com&amp;blog=8356378&amp;post=974&amp;subd=whatthehellsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://whatthehellsecurity.com/2009/12/08/bit-ly-fantasizes-of-combating-twitter-scams/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ljh</media:title>
		</media:content>

		<media:content url="http://whatthehellsecurity.files.wordpress.com/2009/12/directions1.png?w=300" medium="image">
			<media:title type="html">directions</media:title>
		</media:content>
	</item>
		<item>
		<title>Blocking Dirty Bits Not As Good As Identifying Good Bits</title>
		<link>http://whatthehellsecurity.com/2009/12/03/blocking-dirty-bits-not-as-good-as-identifying-good-bits/</link>
		<comments>http://whatthehellsecurity.com/2009/12/03/blocking-dirty-bits-not-as-good-as-identifying-good-bits/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 23:53:25 +0000</pubDate>
		<dc:creator>hell if i know</dc:creator>
				<category><![CDATA[fraud]]></category>
		<category><![CDATA[hypertext]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://whatthehellsecurity.com/?p=871</guid>
		<description><![CDATA[Copyright © 2009 What The Hell? Security John Pescatore makes a point about warning vs. blocking bad links.  But here&#8217;s the thing about links:  We&#8217;re thinking about them all wrong. Now, of course there are bad links.  They end up on blacklists.  Let&#8217;s pretend they&#8217;re more than marginally useful.  (If you have issue with that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whatthehellsecurity.com&amp;blog=8356378&amp;post=871&amp;subd=whatthehellsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://whatthehellsecurity.com/2009/12/03/blocking-dirty-bits-not-as-good-as-identifying-good-bits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ljh</media:title>
		</media:content>

		<media:content url="http://whatthehellsecurity.files.wordpress.com/2009/12/url-space1.png?w=300" medium="image">
			<media:title type="html">url-space</media:title>
		</media:content>
	</item>
		<item>
		<title>What The Hell?  Phishing &amp; Malware Misdiagnosis P2</title>
		<link>http://whatthehellsecurity.com/2009/11/23/what-the-hell-spike-in-misdiagnosis-part-2/</link>
		<comments>http://whatthehellsecurity.com/2009/11/23/what-the-hell-spike-in-misdiagnosis-part-2/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 20:20:01 +0000</pubDate>
		<dc:creator>hell if i know</dc:creator>
				<category><![CDATA[fraud]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://whatthehellsecurity.com/?p=774</guid>
		<description><![CDATA[Copyright © 2009 What The Hell? Security Referring to my previous post, here is the skinny on my Anti-Fraudulent Hot Dog Vendor Detector. Well, hold on. I&#8217;m up to Version 2.0. Before I describe that, I really should explain Version 1.0. Here&#8217;s a theoretical average day in its life.  Bear with me, there&#8217;s actually something [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whatthehellsecurity.com&amp;blog=8356378&amp;post=774&amp;subd=whatthehellsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://whatthehellsecurity.com/2009/11/23/what-the-hell-spike-in-misdiagnosis-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ljh</media:title>
		</media:content>

		<media:content url="http://whatthehellsecurity.files.wordpress.com/2009/11/cart2.jpg" medium="image">
			<media:title type="html">cart</media:title>
		</media:content>
	</item>
		<item>
		<title>What The Hell?  Spike in Phishing &amp; Malware Misdiagnosis</title>
		<link>http://whatthehellsecurity.com/2009/11/05/what-the-hell-spike-in-phishing-misdiagnosis/</link>
		<comments>http://whatthehellsecurity.com/2009/11/05/what-the-hell-spike-in-phishing-misdiagnosis/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 23:04:20 +0000</pubDate>
		<dc:creator>hell if i know</dc:creator>
				<category><![CDATA[fraud]]></category>
		<category><![CDATA[hypertext]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://whatthehellsecurity.com/?p=715</guid>
		<description><![CDATA[Copyright © 2009 What The Hell? Security What the hell? We have it all wrong again. Listen up everybody. This isn&#8217;t about Facebook. It&#8217;s like this. Consider the crime of stealing a credit card number in two scenarios, one offline and one online: Offline Online Victim Street Pedestrian Online Pedestrian Perpetrator Fraudulent Hot Dog Vendor* [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whatthehellsecurity.com&amp;blog=8356378&amp;post=715&amp;subd=whatthehellsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://whatthehellsecurity.com/2009/11/05/what-the-hell-spike-in-phishing-misdiagnosis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ljh</media:title>
		</media:content>
	</item>
		<item>
		<title>What The Hell?  The Web Isn&#8217;t Supposed To Be Secure!</title>
		<link>http://whatthehellsecurity.com/2009/09/28/what-the-hell-the-web-isnt-supposed-to-be-secure/</link>
		<comments>http://whatthehellsecurity.com/2009/09/28/what-the-hell-the-web-isnt-supposed-to-be-secure/#comments</comments>
		<pubDate>Tue, 29 Sep 2009 07:47:46 +0000</pubDate>
		<dc:creator>hell if i know</dc:creator>
				<category><![CDATA[fraud]]></category>
		<category><![CDATA[hypertext]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://whatthehellsecurity.wordpress.com/?p=351</guid>
		<description><![CDATA[Copyright © 2009 What The Hell? Security There&#8217;s a really good reason that Web security is such a pain. It&#8217;s not supposed to be secure. Sorry to break it to you, but hypertext was thirty years old before we decided to use the Web as a platform for commerce.  That&#8217;s, what, three years longer than [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whatthehellsecurity.com&amp;blog=8356378&amp;post=351&amp;subd=whatthehellsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://whatthehellsecurity.com/2009/09/28/what-the-hell-the-web-isnt-supposed-to-be-secure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ljh</media:title>
		</media:content>

		<media:content url="http://whatthehellsecurity.files.wordpress.com/2009/09/psychoanalyze-pinhead3.png" medium="image">
			<media:title type="html">psychoanalyze-pinhead</media:title>
		</media:content>
	</item>
		<item>
		<title>What The Hell?  Checkout Is The Last Place To Instill Trust!</title>
		<link>http://whatthehellsecurity.com/2009/09/15/what-the-hell-checkout-is-the-last-place-to-instill-trust/</link>
		<comments>http://whatthehellsecurity.com/2009/09/15/what-the-hell-checkout-is-the-last-place-to-instill-trust/#comments</comments>
		<pubDate>Wed, 16 Sep 2009 00:02:17 +0000</pubDate>
		<dc:creator>hell if i know</dc:creator>
				<category><![CDATA[certificate authorities]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false">http://whatthehellsecurity.wordpress.com/?p=518</guid>
		<description><![CDATA[Copyright © 2009 What The Hell? Security There&#8217;s a belief among CAs (ok, VeriSign) that a merchant can minimize the number of abandoned carts &#8212; presumably by promoting them to orders &#8212; by introducing trust symbols at checkout.&#160; Symbols like the green bar and VeriSign&#8217;s logo.&#160; Balderdash. Checkout is the last place to do it. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=whatthehellsecurity.com&amp;blog=8356378&amp;post=518&amp;subd=whatthehellsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://whatthehellsecurity.com/2009/09/15/what-the-hell-checkout-is-the-last-place-to-instill-trust/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ljh</media:title>
		</media:content>
	</item>
	</channel>
</rss>
