<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: TJX Credit Card Hackers Busted &#8211; Largest US Data Breach</title>
	<atom:link href="http://www.darknet.org.uk/2008/08/tjx-credit-card-hackers-busted-largest-us-data-breach/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/08/tjx-credit-card-hackers-busted-largest-us-data-breach/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 14 Feb 2012 00:17:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: zupakomputer</title>
		<link>http://www.darknet.org.uk/2008/08/tjx-credit-card-hackers-busted-largest-us-data-breach/#comment-124604</link>
		<dc:creator>zupakomputer</dc:creator>
		<pubDate>Mon, 18 Aug 2008 11:00:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=968#comment-124604</guid>
		<description>What jobs?! None over here. Not even those kinds where you get trained (from your own web surfing I mean, as issues arise) as-you-earn.</description>
		<content:encoded><![CDATA[<p>What jobs?! None over here. Not even those kinds where you get trained (from your own web surfing I mean, as issues arise) as-you-earn.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lyz</title>
		<link>http://www.darknet.org.uk/2008/08/tjx-credit-card-hackers-busted-largest-us-data-breach/#comment-124594</link>
		<dc:creator>lyz</dc:creator>
		<pubDate>Sat, 16 Aug 2008 18:01:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=968#comment-124594</guid>
		<description>lol, not telling that. just forgot to mention that a while back.</description>
		<content:encoded><![CDATA[<p>lol, not telling that. just forgot to mention that a while back.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2008/08/tjx-credit-card-hackers-busted-largest-us-data-breach/#comment-124586</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Sat, 16 Aug 2008 10:18:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=968#comment-124586</guid>
		<description>@lyz: Correct, so do ones that aren&#039;t dealing with the online world (can anyone say Scada) and thats why we will all have jobs till computers are no longer relevant, I don&#039;t see that happening for a long, long time.</description>
		<content:encoded><![CDATA[<p>@lyz: Correct, so do ones that aren&#8217;t dealing with the online world (can anyone say Scada) and thats why we will all have jobs till computers are no longer relevant, I don&#8217;t see that happening for a long, long time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lyz</title>
		<link>http://www.darknet.org.uk/2008/08/tjx-credit-card-hackers-busted-largest-us-data-breach/#comment-124575</link>
		<dc:creator>lyz</dc:creator>
		<pubDate>Sat, 16 Aug 2008 07:52:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=968#comment-124575</guid>
		<description>That&#039;s why every company dealing with the online world needs a staff dedicated to securing the network, coz&#039; some other people doesn&#039;t really care about this thing. And we know that it&#039;s a fact. Am not against anything here...</description>
		<content:encoded><![CDATA[<p>That&#8217;s why every company dealing with the online world needs a staff dedicated to securing the network, coz&#8217; some other people doesn&#8217;t really care about this thing. And we know that it&#8217;s a fact. Am not against anything here&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2008/08/tjx-credit-card-hackers-busted-largest-us-data-breach/#comment-124572</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Sat, 16 Aug 2008 07:22:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=968#comment-124572</guid>
		<description>@Brill: But proper compliances such as PCI and SOX require regular log reviews and and regular testing of security, of course this is like the whole no speeding, or no lieing, some people don&#039;t some do... Just shows PCI and SOX needs more spot checking etc. It also needs to enforce security training and policies for IT staff.

@lyz: cmon little companies only need either a IT guy that knows what he is doing, or out source it. I used to be a consultant, and I always warned customers on security issues, and locked down issues. WPA is easy to setup and if I came in and found an ap that wasn&#039;t WPA compatible I would turn it off, warn them and geez get it replaced with a $100 ap that did.
Even 1 person companies need to know about security issues, like they know they need insurance, accounting etc.</description>
		<content:encoded><![CDATA[<p>@Brill: But proper compliances such as PCI and SOX require regular log reviews and and regular testing of security, of course this is like the whole no speeding, or no lieing, some people don&#8217;t some do&#8230; Just shows PCI and SOX needs more spot checking etc. It also needs to enforce security training and policies for IT staff.</p>
<p>@lyz: cmon little companies only need either a IT guy that knows what he is doing, or out source it. I used to be a consultant, and I always warned customers on security issues, and locked down issues. WPA is easy to setup and if I came in and found an ap that wasn&#8217;t WPA compatible I would turn it off, warn them and geez get it replaced with a $100 ap that did.<br />
Even 1 person companies need to know about security issues, like they know they need insurance, accounting etc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brill</title>
		<link>http://www.darknet.org.uk/2008/08/tjx-credit-card-hackers-busted-largest-us-data-breach/#comment-124566</link>
		<dc:creator>Brill</dc:creator>
		<pubDate>Fri, 15 Aug 2008 19:58:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=968#comment-124566</guid>
		<description>About being PCI compliant, when I say that its a minimum what I am trying to say is that all Laws/regulations become obsolete by definition. Even if the security requirements of any law and/or specification change in response to any incidents... we all know that there are allways new security threats/holes appearing at very  high speed (in fact that is a perfect example of why regulations become obsolete).
They are necesary (as a minimum) but people should be aware that just because a company is PCI compliant or SOX compliant, etc. doesn&#039;t mean that is also &quot;SECURE&quot;</description>
		<content:encoded><![CDATA[<p>About being PCI compliant, when I say that its a minimum what I am trying to say is that all Laws/regulations become obsolete by definition. Even if the security requirements of any law and/or specification change in response to any incidents&#8230; we all know that there are allways new security threats/holes appearing at very  high speed (in fact that is a perfect example of why regulations become obsolete).<br />
They are necesary (as a minimum) but people should be aware that just because a company is PCI compliant or SOX compliant, etc. doesn&#8217;t mean that is also &#8220;SECURE&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lyz</title>
		<link>http://www.darknet.org.uk/2008/08/tjx-credit-card-hackers-busted-largest-us-data-breach/#comment-124549</link>
		<dc:creator>lyz</dc:creator>
		<pubDate>Fri, 15 Aug 2008 11:46:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=968#comment-124549</guid>
		<description>Not talking about TJX here.. I meant companies that are not having those strict wireless policies.. :D</description>
		<content:encoded><![CDATA[<p>Not talking about TJX here.. I meant companies that are not having those strict wireless policies.. :D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2008/08/tjx-credit-card-hackers-busted-largest-us-data-breach/#comment-124548</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Fri, 15 Aug 2008 11:33:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=968#comment-124548</guid>
		<description>@lyz: again not buying it, a company like TJX has a cso, or at least someone in there security department. They need to wake up or as you put it they will be replaced with new staff.</description>
		<content:encoded><![CDATA[<p>@lyz: again not buying it, a company like TJX has a cso, or at least someone in there security department. They need to wake up or as you put it they will be replaced with new staff.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lyz</title>
		<link>http://www.darknet.org.uk/2008/08/tjx-credit-card-hackers-busted-largest-us-data-breach/#comment-124544</link>
		<dc:creator>lyz</dc:creator>
		<pubDate>Fri, 15 Aug 2008 10:56:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=968#comment-124544</guid>
		<description>Maybe coz&#039; some other people are not that knowledgeable technically speaking? Having a working internet connection is fine and enough for them. They don&#039;t care about the pro&#039;s and con&#039;s. That&#039;s why information dissemination is important. 

Or maybe it&#039;s time to tell them to hire new IT/network staffs! :D lol</description>
		<content:encoded><![CDATA[<p>Maybe coz&#8217; some other people are not that knowledgeable technically speaking? Having a working internet connection is fine and enough for them. They don&#8217;t care about the pro&#8217;s and con&#8217;s. That&#8217;s why information dissemination is important. </p>
<p>Or maybe it&#8217;s time to tell them to hire new IT/network staffs! :D lol</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2008/08/tjx-credit-card-hackers-busted-largest-us-data-breach/#comment-124536</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Fri, 15 Aug 2008 04:54:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=968#comment-124536</guid>
		<description>correct Brill they establish a minimum that needs to be maintained, in this case it wasn&#039;t and they got caught out. PCI responded by becomming more secure and strict.
From this and other articles it is now saying they broke wep passwords and dumped in trojans and keyloggers to get the info, interesting how any company in this day and age doesn&#039;t have a strict wireless policy. Good ones are wpa1(min) prefferable 2 with keyphrase longer than 12 characters, or none at all depending on location, ssid prefferably off, and policy set on laptops to only allow infrastructure mode.</description>
		<content:encoded><![CDATA[<p>correct Brill they establish a minimum that needs to be maintained, in this case it wasn&#8217;t and they got caught out. PCI responded by becomming more secure and strict.<br />
From this and other articles it is now saying they broke wep passwords and dumped in trojans and keyloggers to get the info, interesting how any company in this day and age doesn&#8217;t have a strict wireless policy. Good ones are wpa1(min) prefferable 2 with keyphrase longer than 12 characters, or none at all depending on location, ssid prefferably off, and policy set on laptops to only allow infrastructure mode.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

