<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Q&amp;A with Bruce Schneier offers a good summary of security philosophy</title>
	<atom:link href="http://www.andrewpatrick.ca/security-and-privacy/qa-with-bruce-schneier-offers-a-good-summary-of-security-philosophy/feed" rel="self" type="application/rss+xml" />
	<link>http://www.andrewpatrick.ca/security-and-privacy/qa-with-bruce-schneier-offers-a-good-summary-of-security-philosophy</link>
	<description></description>
	<lastBuildDate>Sat, 24 Sep 2011 19:03:30 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Jessica</title>
		<link>http://www.andrewpatrick.ca/security-and-privacy/qa-with-bruce-schneier-offers-a-good-summary-of-security-philosophy/comment-page-1#comment-3284</link>
		<dc:creator>Jessica</dc:creator>
		<pubDate>Fri, 14 Dec 2007 05:12:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.andrewpatrick.ca//qa-with-bruce-schneier-offers-a-good-summary-of-security-philosophy/#comment-3284</guid>
		<description>That makes sense. And makes me somewhat less grumpy about the &quot;being ambushed suddenly with the choose a username&quot; factor.

And no, I don&#039;t think they do see the number. I know when I print statements it only shows the last 4.  I think it only shows the last 4 on screen too.

Of course you can still use your credit card number to login to check PC Points.</description>
		<content:encoded><![CDATA[<p>That makes sense. And makes me somewhat less grumpy about the &#8220;being ambushed suddenly with the choose a username&#8221; factor.</p>
<p>And no, I don&#8217;t think they do see the number. I know when I print statements it only shows the last 4.  I think it only shows the last 4 on screen too.</p>
<p>Of course you can still use your credit card number to login to check PC Points.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew</title>
		<link>http://www.andrewpatrick.ca/security-and-privacy/qa-with-bruce-schneier-offers-a-good-summary-of-security-philosophy/comment-page-1#comment-3247</link>
		<dc:creator>Andrew</dc:creator>
		<pubDate>Thu, 13 Dec 2007 00:20:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.andrewpatrick.ca//qa-with-bruce-schneier-offers-a-good-summary-of-security-philosophy/#comment-3247</guid>
		<description>Funny you should ask, PC Financial just did this change yesterday for my Mastercard account. Of course, it happened when I was in a hurry and I was ambushed, meaning I was not given a chance to do this at a time when I could come up with a good username. I hope I chose a good one. I did store it in my KeePass password archive.

The reason may be to prevent the credit card number from being leaked in a phishing attack or through malware. With a username, the bad guys can&#039;t create false credit cards but with the number they can.

I will have to look more carefully, but is the credit card number visible once you login using the the new username? It might be cool if the bad guys did not get the card number even if they login to your account.</description>
		<content:encoded><![CDATA[<p>Funny you should ask, PC Financial just did this change yesterday for my Mastercard account. Of course, it happened when I was in a hurry and I was ambushed, meaning I was not given a chance to do this at a time when I could come up with a good username. I hope I chose a good one. I did store it in my KeePass password archive.</p>
<p>The reason may be to prevent the credit card number from being leaked in a phishing attack or through malware. With a username, the bad guys can&#8217;t create false credit cards but with the number they can.</p>
<p>I will have to look more carefully, but is the credit card number visible once you login using the the new username? It might be cool if the bad guys did not get the card number even if they login to your account.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jessica</title>
		<link>http://www.andrewpatrick.ca/security-and-privacy/qa-with-bruce-schneier-offers-a-good-summary-of-security-philosophy/comment-page-1#comment-3243</link>
		<dc:creator>Jessica</dc:creator>
		<pubDate>Wed, 12 Dec 2007 23:14:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.andrewpatrick.ca//qa-with-bruce-schneier-offers-a-good-summary-of-security-philosophy/#comment-3243</guid>
		<description>Hi Andrew, speaking of security I remember at one point you posting stuff about financial institutions and security.

Can you think of any valid reason that would make having one&#039;s credit card institution switch from signing in with credit card number + password to userID that you create (like your Myspace or Facebook!) + password?</description>
		<content:encoded><![CDATA[<p>Hi Andrew, speaking of security I remember at one point you posting stuff about financial institutions and security.</p>
<p>Can you think of any valid reason that would make having one&#8217;s credit card institution switch from signing in with credit card number + password to userID that you create (like your Myspace or Facebook!) + password?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

