<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: What&#8217;s Wrong with this Picture?</title>
	<atom:link href="http://qyv.net/jisblog/2008/04/16/whats-wrong-with-this-picture/feed/" rel="self" type="application/rss+xml" />
	<link>http://qyv.net/jisblog/2008/04/16/whats-wrong-with-this-picture/</link>
	<description>Ramblings of a Security Technologist</description>
	<pubDate>Tue, 06 Jan 2009 10:45:46 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Donald Eastlake 3rd</title>
		<link>http://qyv.net/jisblog/2008/04/16/whats-wrong-with-this-picture/comment-page-1/#comment-3867</link>
		<dc:creator>Donald Eastlake 3rd</dc:creator>
		<pubDate>Sun, 24 Aug 2008 02:49:50 +0000</pubDate>
		<guid isPermaLink="false">http://qyv.net/jisblog/2008/04/16/whats-wrong-with-this-picture/#comment-3867</guid>
		<description>The EMV (EuroCard, MasterCard, Visa) protocol which authenticates via a smart card chip in the card, has existed for years. All European cards have these. If/when the losses get big enough, people will move to such technologies.

Donald</description>
		<content:encoded><![CDATA[<p>The EMV (EuroCard, MasterCard, Visa) protocol which authenticates via a smart card chip in the card, has existed for years. All European cards have these. If/when the losses get big enough, people will move to such technologies.</p>
<p>Donald</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: M Gettes</title>
		<link>http://qyv.net/jisblog/2008/04/16/whats-wrong-with-this-picture/comment-page-1/#comment-2232</link>
		<dc:creator>M Gettes</dc:creator>
		<pubDate>Thu, 17 Apr 2008 14:05:52 +0000</pubDate>
		<guid isPermaLink="false">http://qyv.net/jisblog/2008/04/16/whats-wrong-with-this-picture/#comment-2232</guid>
		<description>I understand and completely agree with your point.  As you very well know - changing the system is extremely difficult since it, this fine credit card system, is essentially the basis for commerce.  How can we use the current system to better employ security techniques in a way actually usable by human beings with limited understanding of the issues?  I like what some banks are doing - offering (on the internet) the ability to obtain short-term credit card numbers with appropriate limits on time and dollars.  This is essentially using my current card as a qualifier to obtain other short-term card uses.  This is, of course, analogous to short-term PKI certs and so on.  If we could do this in a way where the net was not so required - or distribute it via telephones (isn't this what Bank of America and the MIT center for the future of banking should be doing?) so anyone could use it - then we might make the overall system better by limiting exposures.  It ain't perfect - but I think it is better.

/mrg</description>
		<content:encoded><![CDATA[<p>I understand and completely agree with your point.  As you very well know - changing the system is extremely difficult since it, this fine credit card system, is essentially the basis for commerce.  How can we use the current system to better employ security techniques in a way actually usable by human beings with limited understanding of the issues?  I like what some banks are doing - offering (on the internet) the ability to obtain short-term credit card numbers with appropriate limits on time and dollars.  This is essentially using my current card as a qualifier to obtain other short-term card uses.  This is, of course, analogous to short-term PKI certs and so on.  If we could do this in a way where the net was not so required - or distribute it via telephones (isn&#8217;t this what Bank of America and the MIT center for the future of banking should be doing?) so anyone could use it - then we might make the overall system better by limiting exposures.  It ain&#8217;t perfect - but I think it is better.</p>
<p>/mrg</p>
]]></content:encoded>
	</item>
</channel>
</rss>
