MIME-Version: 1.0
Content-Location: file:///C:/11665D13/Surfersignorecommonsecuritycuesonbankingsites.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:v=3D"urn:schemas-microsoft-com:vml"
xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:w=3D"urn:schemas-microsoft-com:office:word"
xmlns:p=3D"urn:schemas-microsoft-com:office:powerpoint"
xmlns:oa=3D"urn:schemas-microsoft-com:office:activation"
xmlns:st1=3D"urn:schemas-microsoft-com:office:smarttags"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DWord.Document>
<meta name=3DGenerator content=3D"Microsoft Word 10">
<meta name=3DOriginator content=3D"Microsoft Word 10">
<link rel=3DFile-List
href=3D"Surfersignorecommonsecuritycuesonbankingsites_files/filelist.xml">
<title>Study: surfers ignore common security cues on banking sites</title>
<o:SmartTagType namespaceuri=3D"urn:schemas-microsoft-com:office:smarttags"
 name=3D"PersonName"/>
<!--[if gte mso 9]><xml>
 <o:DocumentProperties>
  <o:Author>Vasana</o:Author>
  <o:Template>Normal</o:Template>
  <o:LastAuthor>COMTR</o:LastAuthor>
  <o:Revision>2</o:Revision>
  <o:TotalTime>5</o:TotalTime>
  <o:Created>2007-07-01T09:43:00Z</o:Created>
  <o:LastSaved>2007-07-01T12:58:00Z</o:LastSaved>
  <o:Pages>1</o:Pages>
  <o:Words>685</o:Words>
  <o:Characters>3907</o:Characters>
  <o:Lines>32</o:Lines>
  <o:Paragraphs>9</o:Paragraphs>
  <o:CharactersWithSpaces>4583</o:CharactersWithSpaces>
  <o:Version>10.2625</o:Version>
 </o:DocumentProperties>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:WordDocument>
  <w:SpellingState>Clean</w:SpellingState>
  <w:GrammarState>Clean</w:GrammarState>
  <w:PunctuationKerning/>
  <w:Compatibility>
   <w:BreakWrappedTables/>
   <w:SnapToGridInCell/>
   <w:ApplyBreakingRules/>
   <w:WrapTextWithPunct/>
   <w:UseAsianBreakRules/>
   <w:UseFELayout/>
   <w:DontGrowAutofit/>
  </w:Compatibility>
  <w:BrowserLevel>MicrosoftInternetExplorer4</w:BrowserLevel>
  <w:ValidateAgainstSchemas/>
  <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>
  <w:IgnoreMixedContent>false</w:IgnoreMixedContent>
  <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>
 </w:WordDocument>
</xml><![endif]--><!--[if !mso]><object
 classid=3D"clsid:38481807-CA0E-42D2-BF39-B33AF135CC4D" id=3Dieooui></objec=
t>
<style>
st1\:*{behavior:url(#ieooui) }
</style>
<![endif]-->
<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:"MS Mincho";
	panose-1:2 2 6 9 4 2 5 8 3 4;
	mso-font-alt:"MS Mincho";
	mso-font-charset:128;
	mso-generic-font-family:modern;
	mso-font-pitch:fixed;
	mso-font-signature:-1610612033 1757936891 16 0 131231 0;}
@font-face
	{font-family:"Angsana New";
	panose-1:2 2 6 3 5 4 5 2 3 4;
	mso-font-charset:0;
	mso-generic-font-family:roman;
	mso-font-pitch:variable;
	mso-font-signature:16777219 0 0 0 65537 0;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:1627421319 -2147483648 8 0 66047 0;}
@font-face
	{font-family:Verdana;
	panose-1:2 11 6 4 3 5 4 4 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:536871559 0 0 0 415 0;}
@font-face
	{font-family:"\@MS Mincho";
	panose-1:2 2 6 9 4 2 5 8 3 4;
	mso-font-charset:128;
	mso-generic-font-family:modern;
	mso-font-pitch:fixed;
	mso-font-signature:-1610612033 1757936891 16 0 131231 0;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-parent:"";
	margin:0cm;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	mso-bidi-font-size:14.0pt;
	font-family:"Times New Roman";
	mso-fareast-font-family:"Times New Roman";
	mso-bidi-font-family:"Angsana New";}
h1
	{mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	mso-pagination:widow-orphan;
	mso-outline-level:1;
	font-size:24.0pt;
	font-family:Tahoma;
	mso-fareast-font-family:"MS Mincho";
	font-weight:bold;}
a:link, span.MsoHyperlink
	{color:#9D0404;
	mso-text-animation:none;
	text-decoration:none;
	text-underline:none;
	text-decoration:none;
	text-line-through:none;}
a:visited, span.MsoHyperlinkFollowed
	{color:purple;
	text-decoration:underline;
	text-underline:single;}
p
	{mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:Tahoma;
	mso-fareast-font-family:"Times New Roman";}
p.tagfull, li.tagfull, div.tagfull
	{mso-style-name:"tag full";
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:Tahoma;
	mso-fareast-font-family:"Times New Roman";}
span.replace4
	{mso-style-name:replace4;
	display:none;
	mso-hide:all;}
span.SpellE
	{mso-style-name:"";
	mso-spl-e:yes;}
span.GramE
	{mso-style-name:"";
	mso-gram-e:yes;}
@page Section1
	{size:595.3pt 841.9pt;
	margin:72.0pt 90.0pt 72.0pt 90.0pt;
	mso-header-margin:35.4pt;
	mso-footer-margin:35.4pt;
	mso-paper-source:0;}
div.Section1
	{page:Section1;}
-->
</style>
<!--[if gte mso 10]>
<style>
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";}
</style>
<![endif]--><!--[if gte mso 9]><xml>
 <w:LatentStyles DefLockedState=3D"false" LatentStyleCount=3D"156">  </w:La=
tentStyles>
</xml><![endif]-->
</head>

<body lang=3DEN-US link=3D"#9D0404" vlink=3Dpurple style=3D'tab-interval:36=
.0pt'>

<div class=3DSection1>

<p class=3DMsoNormal style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt=
:auto;
line-height:160%;mso-outline-level:1;background:#9D9A95'><b><span
style=3D'font-size:18.0pt;line-height:160%;font-family:Verdana;mso-bidi-fon=
t-family:
Tahoma;mso-font-kerning:18.0pt'><a
href=3D"http://arstechnica.com/news.ars/post/20070205-8771.html"><span
style=3D'mso-bidi-font-size:14.0pt;line-height:160%'>Study: surfers ignore =
common
security cues on banking sites</span></a><o:p></o:p></span></b></p>

<p class=3DMsoNormal style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt=
:auto;
line-height:160%;background:#9D9A95'><span style=3D'font-size:9.0pt;line-he=
ight:
160%;font-family:Verdana;mso-bidi-font-family:Tahoma'>By <a
href=3D"http://arstechnica.com/authors.ars/I+Palindrome+I"><span
style=3D'mso-bidi-font-size:14.0pt;line-height:160%'>Eric <span class=3DSpe=
llE>Bangeman</span></span></a>
| Published: February 05, 2007 - 02:22PM CT <o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt=
:auto;
line-height:160%;background:#9D9A95'><span style=3D'mso-bidi-font-family:Ta=
homa'>Passw</span><st1:PersonName
st=3D"on"><span style=3D'mso-bidi-font-family:Tahoma'>o</span></st1:PersonN=
ame><span
style=3D'mso-bidi-font-family:Tahoma'>rd pr</span><st1:PersonName st=3D"on"=
><span
 style=3D'mso-bidi-font-family:Tahoma'>o</span></st1:PersonName><span
style=3D'mso-bidi-font-family:Tahoma'>tecti</span><st1:PersonName st=3D"on"=
><span
 style=3D'mso-bidi-font-family:Tahoma'>o</span></st1:PersonName><span
style=3D'mso-bidi-font-family:Tahoma'>n has its limitati</span><st1:PersonN=
ame
st=3D"on"><span style=3D'mso-bidi-font-family:Tahoma'>o</span></st1:PersonN=
ame><span
style=3D'mso-bidi-font-family:Tahoma'>ns, especially when </span>it c<st1:P=
ersonName
st=3D"on">o</st1:PersonName>mes t<st1:PersonName st=3D"on">o</st1:PersonNam=
e>
things like <st1:PersonName st=3D"on">o</st1:PersonName>nline banking. That=
's why
milli<st1:PersonName st=3D"on">o</st1:PersonName>ns <st1:PersonName st=3D"o=
n">o</st1:PersonName>f
<span class=3DSpellE>phishing</span> attempts are made every day&#8212;it's
relatively easy t<st1:PersonName st=3D"on">o</st1:PersonName> craft realist=
ic-l<st1:PersonName
st=3D"on">o</st1:PersonName><st1:PersonName st=3D"on">o</st1:PersonName>kin=
g web pages
that c<st1:PersonName st=3D"on">o</st1:PersonName>nvince users t<st1:Person=
Name
st=3D"on">o</st1:PersonName> divulge passw<st1:PersonName st=3D"on">o</st1:=
PersonName>rds
and <st1:PersonName st=3D"on">o</st1:PersonName>ther pers<st1:PersonName st=
=3D"on">o</st1:PersonName>nal
details. Financial instituti<st1:PersonName st=3D"on">o</st1:PersonName>ns =
are
well aware <st1:PersonName st=3D"on">o</st1:PersonName>f this and as a resu=
lt,
have c<st1:PersonName st=3D"on">o</st1:PersonName>me up with additi<st1:Per=
sonName
st=3D"on">o</st1:PersonName>nal authenticati<st1:PersonName st=3D"on">o</st=
1:PersonName>n
measures f<st1:PersonName st=3D"on">o</st1:PersonName>r their cust<st1:Pers=
onName
st=3D"on">o</st1:PersonName>mers. A new study c<st1:PersonName st=3D"on">o<=
/st1:PersonName>nducted
by researchers fr<st1:PersonName st=3D"on">o</st1:PersonName>m MIT and Harv=
ard
casts d<st1:PersonName st=3D"on">o</st1:PersonName>ubts <st1:PersonName st=
=3D"on">o</st1:PersonName>n
the efficacy <st1:PersonName st=3D"on">o</st1:PersonName>f such measures.<s=
pan
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana;mso-bidi-font=
-family:
Tahoma'><o:p></o:p></span></p>

<p style=3D'line-height:160%;background:#9D9A95'><span style=3D'font-size:9=
.0pt;
line-height:160%;font-family:Verdana'>Researchers studied a system used by a
handful </span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;lin=
e-height:
 160%;font-family:Verdana'>o</span></st1:PersonName><span style=3D'font-siz=
e:
9.0pt;line-height:160%;font-family:Verdana'>f financial instituti</span><st=
1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ns where cus=
t</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>mers select =
an
image that will always be displayed when they l</span><st1:PersonName st=3D=
"on"><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>g int</span>=
<st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> their acc</=
span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>unt. The site
authenticati</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n images are=
 a cue
f</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;line-heigh=
t:160%;
 font-family:Verdana'>o</span></st1:PersonName><span style=3D'font-size:9.0=
pt;
line-height:160%;font-family:Verdana'>r bank cust</span><st1:PersonName st=
=3D"on"><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>mers that th=
e page
they are viewing is in fact legitimate.<o:p></o:p></span></p>

<p style=3D'line-height:160%;background:#9D9A95'><span style=3D'font-size:9=
.0pt;
line-height:160%;font-family:Verdana'>Last fall, the researchers t</span><s=
t1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>k 67 study
participants and watched them g</span><st1:PersonName st=3D"on"><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> thr</span><=
st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ugh typical =
</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>nline banking
activities. The researchers had rem</span><st1:PersonName st=3D"on"><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ved the site
authenticati</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n images t</=
span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> see h</span=
><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>w many </spa=
n><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>f the partic=
ipants
w</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;line-heigh=
t:160%;
 font-family:Verdana'>o</span></st1:PersonName><span style=3D'font-size:9.0=
pt;
line-height:160%;font-family:Verdana'>uld l</span><st1:PersonName st=3D"on"=
><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>g in anyway.=
 The
results were disturbing. Of the 60 participants wh</span><st1:PersonName st=
=3D"on"><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> made it thr=
</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ugh the stud=
y (the
</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;line-height=
:160%;
 font-family:Verdana'>o</span></st1:PersonName><span style=3D'font-size:9.0=
pt;
line-height:160%;font-family:Verdana'>ther seven failed t</span><st1:Person=
Name
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> f</span><st=
1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ll</span><st=
1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>w instructi<=
/span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ns </span><s=
t1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>r didn't have
their acti</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ns fully cap=
tured
by researchers), </span><st1:PersonName st=3D"on"><span style=3D'font-size:=
9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>nly tw</span=
><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> </span><st1=
:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>f them f</sp=
an><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>und s</span>=
<st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>mething fish=
y with
the image-less l</span><st1:PersonName st=3D"on"><span style=3D'font-size:9=
.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>gin pages and
refused t</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> l</span><st=
1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>g in. The </=
span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ther 58 sign=
ed </span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n with littl=
e </span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>r n</span><s=
t1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> trepidati</=
span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n.<o:p></o:p=
></span></p>

<p style=3D'line-height:160%;background:#9D9A95'><span style=3D'font-size:9=
.0pt;
line-height:160%;font-family:Verdana'>Even m</span><st1:PersonName st=3D"on=
"><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>re tr</span>=
<st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ubling is th=
at 20 </span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>f the partic=
ipants
were given additi</span><st1:PersonName st=3D"on"><span style=3D'font-size:=
9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>nal instruct=
i</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ns &quot;t</=
span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> behave
securely.&quot; Despite the warnings, lack </span><st1:PersonName st=3D"on"=
><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>f site
authenticati</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n images, an=
d even
the researchers' intr</span><st1:PersonName st=3D"on"><span style=3D'font-s=
ize:
 9.0pt;line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ducing s</sp=
an><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>me blatant
spelling err</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>rs, the
participants willingly l</span><st1:PersonName st=3D"on"><span style=3D'fon=
t-size:
 9.0pt;line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>gged in and
attempted t</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> g</span><st=
1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> ab</span><s=
t1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ut their </s=
pan><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>nline banking
business. &quot;We were surprised t</span><st1:PersonName st=3D"on"><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> find that p=
articipants
assigned t</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> the security
primed gr</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>up behaved l=
ess
securely than th</span><st1:PersonName st=3D"on"><span style=3D'font-size:9=
.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>se in the r<=
/span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>le playing g=
r</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>up, wh</span=
><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> had n</span=
><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>
security-priming,&quot; n</span><st1:PersonName st=3D"on"><span style=3D'fo=
nt-size:
 9.0pt;line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ted the stud=
y's
auth</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;line-he=
ight:
 160%;font-family:Verdana'>o</span></st1:PersonName><span style=3D'font-siz=
e:
9.0pt;line-height:160%;font-family:Verdana'>rs.<o:p></o:p></span></p>

<p style=3D'line-height:160%;background:#9D9A95'><span style=3D'font-size:9=
.0pt;
line-height:160%;font-family:Verdana'>The study's c</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>nclusi</span=
><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ns sh</span>=
<st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>uld give add=
ed h</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>pe t</span><=
st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> <span
class=3DSpellE>phishers</span> ar</span><st1:PersonName st=3D"on"><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>und the w</s=
pan><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>rld: users
typically d</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n't play cl<=
/span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>se attenti</=
span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n t</span><s=
t1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> security in=
dicat</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>rs. All
participants entered their passw</span><st1:PersonName st=3D"on"><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>rds even whe=
n the
HTTPS indicat</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0p=
t;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>rs were rem<=
/span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ved indicati=
ng
that the site they were accessing was n</span><st1:PersonName st=3D"on"><sp=
an
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>t secure. Si=
te
authenticati</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n images wer=
e </span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>f little help
either, as rem</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0=
pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ving the ima=
ge and
replacing it with a &quot;this site is being upgraded&quot; message failed =
t</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> deter the v=
ast
maj</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;line-hei=
ght:
 160%;font-family:Verdana'>o</span></st1:PersonName><span style=3D'font-siz=
e:
9.0pt;line-height:160%;font-family:Verdana'>rity </span><st1:PersonName st=
=3D"on"><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>f subjects.<=
o:p></o:p></span></p>

<p style=3D'line-height:160%;background:#9D9A95'><span style=3D'font-size:9=
.0pt;
line-height:160%;font-family:Verdana'>It's a disturbing bit </span><st1:Per=
sonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>f news f</sp=
an><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>r banks that=
 have
struggled with the questi</span><st1:PersonName st=3D"on"><span style=3D'fo=
nt-size:
 9.0pt;line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n </span><st=
1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>f h</span><s=
t1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>w t</span><s=
t1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> tighten up =
their </span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>wn security
measures. S</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>me instituti=
</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ns have g</s=
pan><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ne t</span><=
st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> a <a
href=3D"http://arstechnica.com/news.ars/post/20060213-6174.html">two-factor
authentication system</a> c</span><st1:PersonName st=3D"on"><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>nsisting </s=
pan><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>f a passw</s=
pan><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>rd and a USB=
 key
that flashes a c</span><st1:PersonName st=3D"on"><span style=3D'font-size:9=
.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>de <span
class=3DGramE>that changes</span> every minute. Cust</span><st1:PersonName =
st=3D"on"><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>mers are req=
uired
t</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;line-height=
:160%;
 font-family:Verdana'>o</span></st1:PersonName><span style=3D'font-size:9.0=
pt;
line-height:160%;font-family:Verdana'> enter their passw</span><st1:PersonN=
ame
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>rd and the c=
</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>de fr</span>=
<st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>m the key, b=
ut
even <a href=3D"http://arstechnica.com/news.ars/post/20060711-7237.html">th=
at's
not <span class=3DSpellE>phisher</span>-proof</a>: using a man-in-the-middle
attack, Russian <span class=3DSpellE>phishers</span> attempted t</span><st1=
:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> extract the=
 passw</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>rds and c</s=
pan><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>des fr</span=
><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>m unwary Cit=
ibank
cust</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;line-he=
ight:
 160%;font-family:Verdana'>o</span></st1:PersonName><span style=3D'font-siz=
e:
9.0pt;line-height:160%;font-family:Verdana'>mers and then authenticate t</s=
pan><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> Citibank wi=
thin
the 60-sec</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>nd time fram=
e all</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>wed by the c=
</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>de. <o:p></o=
:p></span></p>

<p style=3D'line-height:160%;background:#9D9A95'><span style=3D'font-size:9=
.0pt;
line-height:160%;font-family:Verdana'>Many banks see authenticati</span><st=
1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n systems th=
at
require an extra piece </span><st1:PersonName st=3D"on"><span style=3D'font=
-size:
 9.0pt;line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>f hardware a=
s n</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>t w</span><s=
t1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>rth their ti=
me
because they believe cust</span><st1:PersonName st=3D"on"><span style=3D'fo=
nt-size:
 9.0pt;line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>mers w</span=
><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n't want t</=
span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> use them, s=
</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> they have
enthusiastically embraced s</span><st1:PersonName st=3D"on"><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>luti</span><=
st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ns like site
authenticati</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n images t</=
span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> the p</span=
><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>int where th=
ey
assure cust</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>mers that if=
 they
see the image, they're at the right web site. &quot;When y</span><st1:Perso=
nName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>u see y</spa=
n><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ur image, y<=
/span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>u can be c</=
span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>nfident that=
 y</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>u're </span>=
<st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n Vanguard.c=
</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>m and n</spa=
n><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>t an imp</sp=
an><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ster site an=
d can
safely enter y</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0=
pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ur passw</sp=
an><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>rd,&quot; sa=
ys <a
href=3D"https://flagship.vanguard.com/VGApp/hnw/help/SecurityLogonFAQsConte=
nt.jsp">Vanguard's
enhanced logon FAQ page</a>, despite the fact that site authenticati</span>=
<st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n image sign=
-</span><st1:PersonName
st=3D"on"><span class=3DSpellE><span style=3D'font-size:9.0pt;line-height:1=
60%;
 font-family:Verdana'>o</span></span></st1:PersonName><span class=3DSpellE>=
<span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ns</span></s=
pan><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> <a
href=3D"http://cr-%20labs.com/publications/SiteKey-20060718.pdf">are vulner=
able
to attacks</a> (PDF) similar t</span><st1:PersonName st=3D"on"><span
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> the </span>=
<st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ne described=
 ab</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ve.<o:p></o:=
p></span></p>

<p style=3D'line-height:160%;background:#9D9A95'><span style=3D'font-size:9=
.0pt;
line-height:160%;font-family:Verdana'>S</span><st1:PersonName st=3D"on"><sp=
an
 style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>o</span></s=
t1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>me analysts
suggest that banks are m</span><st1:PersonName st=3D"on"><span style=3D'fon=
t-size:
 9.0pt;line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>re c</span><=
st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ncerned with=
 the
image </span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;line-=
height:
 160%;font-family:Verdana'>o</span></st1:PersonName><span style=3D'font-siz=
e:
9.0pt;line-height:160%;font-family:Verdana'>f security rather than being
secure. That's an </span><st1:PersonName st=3D"on"><span style=3D'font-size=
:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>versimplific=
ati</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n. As the st=
udy
suggests, the pr</span><st1:PersonName st=3D"on"><span style=3D'font-size:9=
.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>blem is much=
 m</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>re c</span><=
st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>mplex than
settling </span><st1:PersonName st=3D"on"><span style=3D'font-size:9.0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n the pr</sp=
an><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>per authenti=
cati</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n scheme. Un=
til
surfers learn t</span><st1:PersonName st=3D"on"><span style=3D'font-size:9.=
0pt;
 line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> rec</span><=
st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>gnize and </=
span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>bey cues tha=
t tell
them whether it's safe t</span><st1:PersonName st=3D"on"><span style=3D'fon=
t-size:
 9.0pt;line-height:160%;font-family:Verdana'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> be divulgin=
g pers</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>nal inf</spa=
n><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>rmati</span>=
<st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>n, n</span><=
st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> system is g=
</span><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>ing t</span>=
<st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'> be f</span>=
<st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>lpr</span><s=
t1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><st1:PersonName
st=3D"on"><span style=3D'font-size:9.0pt;line-height:160%;font-family:Verda=
na'>o</span></st1:PersonName><span
style=3D'font-size:9.0pt;line-height:160%;font-family:Verdana'>f.<o:p></o:p=
></span></p>

<p class=3DMsoNormal><o:p>&nbsp;</o:p></p>

</div>

</body>

</html>
