<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
	>
<channel>
	<title>Comments on: Citizen&#8217;s Bank Online Gets Scary</title>
	<atom:link href="http://www.uie.com/brainsparks/2005/12/22/citizens-bank-online-gets-scary/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.uie.com/brainsparks/2005/12/22/citizens-bank-online-gets-scary/</link>
	<description>UIE\'s latest insights on the world of design</description>
	<lastBuildDate>Sat, 11 Feb 2012 08:11:47 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2</generator>
	<item>
		<title>By: Shane Shepherd</title>
		<link>http://www.uie.com/brainsparks/2005/12/22/citizens-bank-online-gets-scary/comment-page-1/#comment-524</link>
		<dc:creator>Shane Shepherd</dc:creator>
		<pubDate>Tue, 03 Jan 2006 22:14:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.uie.com/brainsparks/?p=150#comment-524</guid>
		<description>@Joshua:  The error you saw is a common ASP.NET error screen.  It would be nice if a more friendly message was displayed when an error occurs though.

@Ron West: FYI - The error displayed doesn&#039;t reveal anything about the server except that the site is built in ASP.NET....something a hacker probably could already tell by looking the file extensions (.aspx) on the rest of the site.  I&#039;m not trying to defend the appearance of the message, it should have been avoided.</description>
		<content:encoded><![CDATA[<p>@Joshua:  The error you saw is a common ASP.NET error screen.  It would be nice if a more friendly message was displayed when an error occurs though.</p>
<p>@Ron West: FYI &#8211; The error displayed doesn&#8217;t reveal anything about the server except that the site is built in ASP.NET&#8230;.something a hacker probably could already tell by looking the file extensions (.aspx) on the rest of the site.  I&#8217;m not trying to defend the appearance of the message, it should have been avoided.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kate</title>
		<link>http://www.uie.com/brainsparks/2005/12/22/citizens-bank-online-gets-scary/comment-page-1/#comment-476</link>
		<dc:creator>Kate</dc:creator>
		<pubDate>Sun, 25 Dec 2005 12:45:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.uie.com/brainsparks/?p=150#comment-476</guid>
		<description>o, i&#039;m sorry... not msn, but hotmail.com... SORRY</description>
		<content:encoded><![CDATA[<p>o, i&#8217;m sorry&#8230; not msn, but hotmail.com&#8230; SORRY</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kate</title>
		<link>http://www.uie.com/brainsparks/2005/12/22/citizens-bank-online-gets-scary/comment-page-1/#comment-475</link>
		<dc:creator>Kate</dc:creator>
		<pubDate>Sun, 25 Dec 2005 12:42:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.uie.com/brainsparks/?p=150#comment-475</guid>
		<description>Btw, the same problem is on the msn.com at the Opera browser (at least version (7.23)[my favourite]...</description>
		<content:encoded><![CDATA[<p>Btw, the same problem is on the msn.com at the Opera browser (at least version (7.23)[my favourite]&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: benry</title>
		<link>http://www.uie.com/brainsparks/2005/12/22/citizens-bank-online-gets-scary/comment-page-1/#comment-469</link>
		<dc:creator>benry</dc:creator>
		<pubDate>Sat, 24 Dec 2005 01:36:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.uie.com/brainsparks/?p=150#comment-469</guid>
		<description>I&#039;d guess that this was due to their new site launching. It&#039;s up now. Simply better efforts to launch off hours, with a page telling people the new site was coming would have avoided this problem and the reputational risk they have now to enjoy with your post.</description>
		<content:encoded><![CDATA[<p>I&#8217;d guess that this was due to their new site launching. It&#8217;s up now. Simply better efforts to launch off hours, with a page telling people the new site was coming would have avoided this problem and the reputational risk they have now to enjoy with your post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve Portigal</title>
		<link>http://www.uie.com/brainsparks/2005/12/22/citizens-bank-online-gets-scary/comment-page-1/#comment-468</link>
		<dc:creator>Steve Portigal</dc:creator>
		<pubDate>Fri, 23 Dec 2005 20:57:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.uie.com/brainsparks/?p=150#comment-468</guid>
		<description>I thought of you just now...I am having SBC problems and went to their system status page
http://csc1.sbcis.sbc.com/systemstatus/
and clicked on California and instead of any status I get a page of HTML (which of course I can&#039;t really exactly paste here because it gets interpreted as, well HTML...something like this, then):

HTML
HEAD
META NAME=&quot;ROBOTS&quot; CONTENT=&quot;NOINDEX, NOFOLLOW, NOARCHIVE&quot;&gt;
META HTTP-EQUIV=&quot;Expires&quot; CONTENT=&quot;0&quot;&gt;
META HTTP-EQUIV=&quot;Pragma&quot; CONTENT=&quot;no-cache&quot;&gt;
META HTTP-EQUIV=&quot;Cache-Control&quot; CONTENT=&quot;no-cache&quot;&gt;
TITLE&gt;SBC System Status: Summary
link rel=&quot;stylesheet&quot; href=&quot;/systemstatus/css/status.css&quot;&gt;
script language=&quot;javascript&quot;&gt;
function checkAll(){
	for (var i=0;i</description>
		<content:encoded><![CDATA[<p>I thought of you just now&#8230;I am having SBC problems and went to their system status page<br />
<a href="http://csc1.sbcis.sbc.com/systemstatus/" rel="nofollow">http://csc1.sbcis.sbc.com/systemstatus/</a><br />
and clicked on California and instead of any status I get a page of HTML (which of course I can&#8217;t really exactly paste here because it gets interpreted as, well HTML&#8230;something like this, then):</p>
<p>HTML<br />
HEAD<br />
META NAME=&#8221;ROBOTS&#8221; CONTENT=&#8221;NOINDEX, NOFOLLOW, NOARCHIVE&#8221;&gt;<br />
META HTTP-EQUIV=&#8221;Expires&#8221; CONTENT=&#8221;0&#8243;&gt;<br />
META HTTP-EQUIV=&#8221;Pragma&#8221; CONTENT=&#8221;no-cache&#8221;&gt;<br />
META HTTP-EQUIV=&#8221;Cache-Control&#8221; CONTENT=&#8221;no-cache&#8221;&gt;<br />
TITLE&gt;SBC System Status: Summary<br />
link rel=&#8221;stylesheet&#8221; href=&#8221;/systemstatus/css/status.css&#8221;&gt;<br />
script language=&#8221;javascript&#8221;&gt;<br />
function checkAll(){<br />
	for (var i=0;i</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ron West</title>
		<link>http://www.uie.com/brainsparks/2005/12/22/citizens-bank-online-gets-scary/comment-page-1/#comment-466</link>
		<dc:creator>Ron West</dc:creator>
		<pubDate>Fri, 23 Dec 2005 13:49:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.uie.com/brainsparks/?p=150#comment-466</guid>
		<description>I have seen this error before too.  I also do business with Citizens Bank and I also was concerned when I saw this error.  Not to metion that this error gives a potential hacker some useful knowledge about the application which scares me a bit more.  Thanks for posting this I am glad to see someone out there cares about this kind of stuff.</description>
		<content:encoded><![CDATA[<p>I have seen this error before too.  I also do business with Citizens Bank and I also was concerned when I saw this error.  Not to metion that this error gives a potential hacker some useful knowledge about the application which scares me a bit more.  Thanks for posting this I am glad to see someone out there cares about this kind of stuff.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

