<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: My SSN is showing?</title>
	<atom:link href="http://xato.com/bl/2007/02/06/my-ssn-is-showing/feed/" rel="self" type="application/rss+xml" />
	<link>http://xato.com/privacy/my-ssn-is-showing</link>
	<description>Mark Burnetts Windows Security</description>
	<pubDate>Mon, 01 Dec 2008 20:06:33 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Rev</title>
		<link>http://xato.com/privacy/my-ssn-is-showing#comment-191</link>
		<dc:creator>Rev</dc:creator>
		<pubDate>Fri, 02 Mar 2007 17:35:44 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/02/06/my-ssn-is-showing/#comment-191</guid>
		<description>The last four digits of an SSN is ever Social Engineer's "Golden Ticket". Many companies use the last four digits of your ssn as their primary means of authentication. Even if an account with a utility company or other service provider has been password protected company reps are often sympathetic to customers who "can never remember all of their passwords". The information contained in this email alone may have been enough for an attacker to gain access to your account considering they would now know not only the last four digits of your SSN, but also the name of your financial institution and I would assume your first and last name. (which would be trivial to obtain if not included).</description>
		<content:encoded><![CDATA[<p>The last four digits of an SSN is ever Social Engineer&#8217;s &#8220;Golden Ticket&#8221;. Many companies use the last four digits of your ssn as their primary means of authentication. Even if an account with a utility company or other service provider has been password protected company reps are often sympathetic to customers who &#8220;can never remember all of their passwords&#8221;. The information contained in this email alone may have been enough for an attacker to gain access to your account considering they would now know not only the last four digits of your SSN, but also the name of your financial institution and I would assume your first and last name. (which would be trivial to obtain if not included).</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.679 seconds -->
