<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Chase&#8217;s completely insecure and broken &#8220;secure&#8221; document exchange system (aka securedx, secure-dx)</title>
	<atom:link href="http://www.pixelmonkey.org/2009/08/21/chase-insecure/feed" rel="self" type="application/rss+xml" />
	<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=chase-insecure</link>
	<description>Andrew J. Montalenti's Blog</description>
	<lastBuildDate>Wed, 18 Jan 2012 21:43:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: greens survive only when reds die online games</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-4#comment-162327</link>
		<dc:creator>greens survive only when reds die online games</dc:creator>
		<pubDate>Wed, 18 Jan 2012 21:43:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-162327</guid>
		<description>&lt;strong&gt;greens survive only when reds die online games...&lt;/strong&gt;

[...]&#187; Chase&#8217;s completely insecure and broken &#8220;secure&#8221; document exchange system (aka securedx, secure-dx) &#124; pixelmonkey.org &#8211; alter or abolish?[...]...</description>
		<content:encoded><![CDATA[<p><strong>greens survive only when reds die online games&#8230;</strong></p>
<p>[...]&raquo; Chase&#8217;s completely insecure and broken &#8220;secure&#8221; document exchange system (aka securedx, secure-dx) | pixelmonkey.org &#8211; alter or abolish?[...]&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Depannage Informatique</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-4#comment-162053</link>
		<dc:creator>Depannage Informatique</dc:creator>
		<pubDate>Wed, 18 Jan 2012 06:39:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-162053</guid>
		<description>&lt;strong&gt;Depannage Informatique...&lt;/strong&gt;

[...]&#187; Chase&#8217;s completely insecure and broken &#8220;secure&#8221; document exchange system (aka securedx, secure-dx) &#124; pixelmonkey.org &#8211; alter or abolish?[...]...</description>
		<content:encoded><![CDATA[<p><strong>Depannage Informatique&#8230;</strong></p>
<p>[...]&raquo; Chase&#8217;s completely insecure and broken &#8220;secure&#8221; document exchange system (aka securedx, secure-dx) | pixelmonkey.org &#8211; alter or abolish?[...]&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fake credit card, fake scan credit card</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-4#comment-156183</link>
		<dc:creator>fake credit card, fake scan credit card</dc:creator>
		<pubDate>Mon, 02 Jan 2012 06:49:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-156183</guid>
		<description>&lt;strong&gt;fake credit card, fake scan credit card...&lt;/strong&gt;

[...]&#187; Chase&#8217;s completely insecure and broken &#8220;secure&#8221; document exchange system (aka securedx, secure-dx) &#124; pixelmonkey.org &#8211; alter or abolish?[...]...</description>
		<content:encoded><![CDATA[<p><strong>fake credit card, fake scan credit card&#8230;</strong></p>
<p>[...]&raquo; Chase&#8217;s completely insecure and broken &#8220;secure&#8221; document exchange system (aka securedx, secure-dx) | pixelmonkey.org &#8211; alter or abolish?[...]&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chase&#8217;s dubious offer &#124; Fairweather Zealot</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-4#comment-155353</link>
		<dc:creator>Chase&#8217;s dubious offer &#124; Fairweather Zealot</dc:creator>
		<pubDate>Thu, 29 Dec 2011 17:40:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-155353</guid>
		<description>[...] me, that looks like a spoof URL. In reality, I was able to find out¹ it belongs to a company specializing in secure document transfer. Sounds good but why not have it [...]</description>
		<content:encoded><![CDATA[<p>[...] me, that looks like a spoof URL. In reality, I was able to find out¹ it belongs to a company specializing in secure document transfer. Sounds good but why not have it [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: how to make hair grow faster</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-4#comment-152366</link>
		<dc:creator>how to make hair grow faster</dc:creator>
		<pubDate>Sat, 17 Dec 2011 17:02:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-152366</guid>
		<description>&lt;strong&gt;how to make hair grow faster...&lt;/strong&gt;

[...]&#187; Chase&#8217;s completely insecure and broken &#8220;secure&#8221; document exchange system (aka securedx, secure-dx) &#124; pixelmonkey.org &#8211; alter or abolish?[...]...</description>
		<content:encoded><![CDATA[<p><strong>how to make hair grow faster&#8230;</strong></p>
<p>[...]&raquo; Chase&#8217;s completely insecure and broken &#8220;secure&#8221; document exchange system (aka securedx, secure-dx) | pixelmonkey.org &#8211; alter or abolish?[...]&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Boston Red Sox</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-4#comment-152230</link>
		<dc:creator>Boston Red Sox</dc:creator>
		<pubDate>Sat, 17 Dec 2011 01:24:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-152230</guid>
		<description>This is an interesting blog. I have done a fair amount of work on network security systems. I am amazed at the number of Software Engineers on this blog that are complaining. Please read &quot;Not Phishing&#039;s&quot; entries on this blog. This is very normal for banks, law firms, hospitals, etc. etc. etc. to outsource services (such as secure document transfer) to third party providers (such as secure-dx). It is the organization&#039;s responsibility to vet the provider for compliance to their security standards. It seems alot of posters here are concerned about the fact that the username and password are sent over unsecured email. If you notice your email, the password has a time deadline on it and you are forced to change it on first logon. If someone else gets to the account before you, they would have to change the password. You would know that my account was compromised (password would be changed) and could immediately contact Chase to disable access. Although issuing of a password over unsecured email is questionable, the security mechanism is designed for you change the password as soon as possible, thus rendering the emailed password ineffective. Not sure what the complaint is here as long as you respond as soon as you get the email.
This blog sounds to me like a bunch of IT folks (or non-IT folks who have watched too many conspiracy movies) airing out their opinions on things they have overthought.</description>
		<content:encoded><![CDATA[<p>This is an interesting blog. I have done a fair amount of work on network security systems. I am amazed at the number of Software Engineers on this blog that are complaining. Please read &#8220;Not Phishing&#8217;s&#8221; entries on this blog. This is very normal for banks, law firms, hospitals, etc. etc. etc. to outsource services (such as secure document transfer) to third party providers (such as secure-dx). It is the organization&#8217;s responsibility to vet the provider for compliance to their security standards. It seems alot of posters here are concerned about the fact that the username and password are sent over unsecured email. If you notice your email, the password has a time deadline on it and you are forced to change it on first logon. If someone else gets to the account before you, they would have to change the password. You would know that my account was compromised (password would be changed) and could immediately contact Chase to disable access. Although issuing of a password over unsecured email is questionable, the security mechanism is designed for you change the password as soon as possible, thus rendering the emailed password ineffective. Not sure what the complaint is here as long as you respond as soon as you get the email.<br />
This blog sounds to me like a bunch of IT folks (or non-IT folks who have watched too many conspiracy movies) airing out their opinions on things they have overthought.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Chase Madness</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-4#comment-151548</link>
		<dc:creator>The Chase Madness</dc:creator>
		<pubDate>Tue, 13 Dec 2011 21:54:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-151548</guid>
		<description>I just went through the same experience.  Even knowing that I just submitted a claim through my banker I was still skeptical of this email.  At least if the email address said @chase.com it would be believable.  Why not post the response (pdf) on my online bank profile and they can send me an email saying, &quot;you have a notice.&quot;

In addition to having multiple financial advisers leave the company and fraudulent activity for several family members, all who just happen to be Chase customers, I&#039;m excited for the new year and a fresh start with Chase.</description>
		<content:encoded><![CDATA[<p>I just went through the same experience.  Even knowing that I just submitted a claim through my banker I was still skeptical of this email.  At least if the email address said @chase.com it would be believable.  Why not post the response (pdf) on my online bank profile and they can send me an email saying, &#8220;you have a notice.&#8221;</p>
<p>In addition to having multiple financial advisers leave the company and fraudulent activity for several family members, all who just happen to be Chase customers, I&#8217;m excited for the new year and a fresh start with Chase.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alexey</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-4#comment-145147</link>
		<dc:creator>alexey</dc:creator>
		<pubDate>Tue, 15 Nov 2011 00:01:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-145147</guid>
		<description>November 2011 -- they are still doing it. Password is now in the same email, and looks like a randomly-generated one, but they then proceed to ask &quot;security&quot; questions, one of which is &quot;pet&#039;s name&quot;, that isn&#039;t really the real pet&#039;s name, but a made-up one they email in a separate message. I think they deserve a medal for the worst e-doc process out there!</description>
		<content:encoded><![CDATA[<p>November 2011 &#8212; they are still doing it. Password is now in the same email, and looks like a randomly-generated one, but they then proceed to ask &#8220;security&#8221; questions, one of which is &#8220;pet&#8217;s name&#8221;, that isn&#8217;t really the real pet&#8217;s name, but a made-up one they email in a separate message. I think they deserve a medal for the worst e-doc process out there!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pixelmonkey</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-142484</link>
		<dc:creator>pixelmonkey</dc:creator>
		<pubDate>Sun, 30 Oct 2011 03:00:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-142484</guid>
		<description>@Mentatchris sad to hear :(</description>
		<content:encoded><![CDATA[<p>@Mentatchris sad to hear <img src='http://www.pixelmonkey.org/wordpress/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mentatchris</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-142299</link>
		<dc:creator>Mentatchris</dc:creator>
		<pubDate>Fri, 28 Oct 2011 14:01:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-142299</guid>
		<description>This is still happening at Oct 2011 - these guys haven&#039;t learned a damn thing.  Still sending pwds in clear text, and still asking for patently ridiculous &quot;validation&quot;.

Very frustrating....</description>
		<content:encoded><![CDATA[<p>This is still happening at Oct 2011 &#8211; these guys haven&#8217;t learned a damn thing.  Still sending pwds in clear text, and still asking for patently ridiculous &#8220;validation&#8221;.</p>
<p>Very frustrating&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Borse Gucci</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-142152</link>
		<dc:creator>Borse Gucci</dc:creator>
		<pubDate>Thu, 27 Oct 2011 06:15:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-142152</guid>
		<description>&lt;strong&gt;Borse Gucci...&lt;/strong&gt;

[...]&#187; Chase&#8217;s completely insecure and broken &#8220;secure&#8221; document exchange system (aka securedx, secure-dx) &#124; pixelmonkey.org &#8211; alter or abolish?[...]...</description>
		<content:encoded><![CDATA[<p><strong>Borse Gucci&#8230;</strong></p>
<p>[...]&raquo; Chase&#8217;s completely insecure and broken &#8220;secure&#8221; document exchange system (aka securedx, secure-dx) | pixelmonkey.org &#8211; alter or abolish?[...]&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-133412</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Thu, 25 Aug 2011 02:37:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-133412</guid>
		<description>Nice... from mail1.secure-dx.com ([178.32.180.61])	by imta26.westchester.pa.mail.comcast.net with comcast	id QAMi1h00L1Ksfjm0SAMice; Wed, 24 Aug 2011 10:21:42 +0000

I thought someone had stole my identity, and was phishing passwords...</description>
		<content:encoded><![CDATA[<p>Nice&#8230; from mail1.secure-dx.com ([178.32.180.61])	by imta26.westchester.pa.mail.comcast.net with comcast	id QAMi1h00L1Ksfjm0SAMice; Wed, 24 Aug 2011 10:21:42 +0000</p>
<p>I thought someone had stole my identity, and was phishing passwords&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pligg.com</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-132812</link>
		<dc:creator>pligg.com</dc:creator>
		<pubDate>Sat, 20 Aug 2011 11:46:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-132812</guid>
		<description>&lt;strong&gt;secure-dx) &#124; pixelmonkey.org – alter or abolish?...&lt;/strong&gt;

» Chase’s completely insecure and broken “secure” document exchange system (aka securedx, secure-dx) &#124; pixelmonkey.org – alter or abolish?...</description>
		<content:encoded><![CDATA[<p><strong>secure-dx) | pixelmonkey.org – alter or abolish?&#8230;</strong></p>
<p>» Chase’s completely insecure and broken “secure” document exchange system (aka securedx, secure-dx) | pixelmonkey.org – alter or abolish?&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dustin</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-126161</link>
		<dc:creator>Dustin</dc:creator>
		<pubDate>Wed, 06 Jul 2011 14:12:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-126161</guid>
		<description>Glad that this post is as trafficked as it is. As a heads up to your readers, Fifth Third Bank just started using secure-dx, and like many others my reaction was the same. Thankfully I checked with my bank, and stumbled across your blog. Appreciate the work!</description>
		<content:encoded><![CDATA[<p>Glad that this post is as trafficked as it is. As a heads up to your readers, Fifth Third Bank just started using secure-dx, and like many others my reaction was the same. Thankfully I checked with my bank, and stumbled across your blog. Appreciate the work!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Khris</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-111384</link>
		<dc:creator>Khris</dc:creator>
		<pubDate>Fri, 01 Apr 2011 19:52:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-111384</guid>
		<description>Thanks for the initial post and detail on this. The fact that this is not a big phishing scheme baffles me. The website is totally legit and I still cannot believe it. At least it is now a sub-domain of Chase.com. Sheer Madness!!</description>
		<content:encoded><![CDATA[<p>Thanks for the initial post and detail on this. The fact that this is not a big phishing scheme baffles me. The website is totally legit and I still cannot believe it. At least it is now a sub-domain of Chase.com. Sheer Madness!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pixelmonkey</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-111059</link>
		<dc:creator>pixelmonkey</dc:creator>
		<pubDate>Wed, 30 Mar 2011 02:42:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-111059</guid>
		<description>@Heggie thanks, glad you found the post to be helpful</description>
		<content:encoded><![CDATA[<p>@Heggie thanks, glad you found the post to be helpful</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Heggie</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-110937</link>
		<dc:creator>Heggie</dc:creator>
		<pubDate>Tue, 29 Mar 2011 03:49:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-110937</guid>
		<description>thanks for the post Andrew, kudos for the write up..  ther two Chase sdx emails look completley like a phishing scheme, and my paranoia ratcheted up just as yours did.. so glad I found your post.  nice work.
-not a software engineer but knows enough IT to recognize a bad design..</description>
		<content:encoded><![CDATA[<p>thanks for the post Andrew, kudos for the write up..  ther two Chase sdx emails look completley like a phishing scheme, and my paranoia ratcheted up just as yours did.. so glad I found your post.  nice work.<br />
-not a software engineer but knows enough IT to recognize a bad design..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-110814</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Mon, 28 Mar 2011 01:14:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-110814</guid>
		<description>Also got Chase&#039;s streamlined re-fi offer in the mail and called the number given; also got concerned at the point they asked for birthplace etc. for security questions. Stopped at that point and did a double-check by looking at the Web page the rep suggested (www.chase.com/newlowerrate); unfortunately, it DOESN&#039;T show any phone numbers! Probably because they have different call centers for different batches of offers; still, it just shows how easily a scammer COULD piggy-back on this legit process.

Anticipating that some scammer will try to do so eventually (the issues in this blog have hardly changed since mid-2009, right?), I recommend that everyone complete a little due diligence along the way -- check the phone number, check that the link in the email goes to where it says it does, etc. In my case, calling the Chase Mortgage number and talking with a re-fi specialist did confirm that the offer and the rep was legit.

For the re-fi process, it appears (in)secure-dx.com is only being used to deliver loan documents for review, instead of snail-mailing printouts. Responses (incl. signatures) are via fax or email. So, not a big deal once you make peace with the preceding steps.

Apparently Chase trusts their automated document delivery to secure-dx.com more than via email. They did verify my identity every time I called, so they would be sure of the email address that I gave them to send the ID/password for secure-dx.com access to the documents they could have sent to that email address... but they sent the Authorization to Disclose Information form to that email address!

HELL, why not just post the documents in my online Chase mortgage account?!?

With decades in the field of systems design and development, I certainly agree this is the sloppiest process I&#039;ve seen for a provider in a &quot;trust&quot; industry. (With a nod to the recursively weird World Wide Web, see the post by &quot;motty&quot; on Nov 25, 2009 about trust at http://www.metafilter.com/86980/Banks-are-too-big-to-fail-at-social-media which is in turn commenting on THIS page...)</description>
		<content:encoded><![CDATA[<p>Also got Chase&#8217;s streamlined re-fi offer in the mail and called the number given; also got concerned at the point they asked for birthplace etc. for security questions. Stopped at that point and did a double-check by looking at the Web page the rep suggested (www.chase.com/newlowerrate); unfortunately, it DOESN&#8217;T show any phone numbers! Probably because they have different call centers for different batches of offers; still, it just shows how easily a scammer COULD piggy-back on this legit process.</p>
<p>Anticipating that some scammer will try to do so eventually (the issues in this blog have hardly changed since mid-2009, right?), I recommend that everyone complete a little due diligence along the way &#8212; check the phone number, check that the link in the email goes to where it says it does, etc. In my case, calling the Chase Mortgage number and talking with a re-fi specialist did confirm that the offer and the rep was legit.</p>
<p>For the re-fi process, it appears (in)secure-dx.com is only being used to deliver loan documents for review, instead of snail-mailing printouts. Responses (incl. signatures) are via fax or email. So, not a big deal once you make peace with the preceding steps.</p>
<p>Apparently Chase trusts their automated document delivery to secure-dx.com more than via email. They did verify my identity every time I called, so they would be sure of the email address that I gave them to send the ID/password for secure-dx.com access to the documents they could have sent to that email address&#8230; but they sent the Authorization to Disclose Information form to that email address!</p>
<p>HELL, why not just post the documents in my online Chase mortgage account?!?</p>
<p>With decades in the field of systems design and development, I certainly agree this is the sloppiest process I&#8217;ve seen for a provider in a &#8220;trust&#8221; industry. (With a nod to the recursively weird World Wide Web, see the post by &#8220;motty&#8221; on Nov 25, 2009 about trust at <a href="http://www.metafilter.com/86980/Banks-are-too-big-to-fail-at-social-media" rel="nofollow">http://www.metafilter.com/86980/Banks-are-too-big-to-fail-at-social-media</a> which is in turn commenting on THIS page&#8230;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: barbara o</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-104383</link>
		<dc:creator>barbara o</dc:creator>
		<pubDate>Tue, 01 Feb 2011 20:08:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-104383</guid>
		<description>Oops, that is, I HAD BofA accounts ...</description>
		<content:encoded><![CDATA[<p>Oops, that is, I HAD BofA accounts &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: barbara o</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-104382</link>
		<dc:creator>barbara o</dc:creator>
		<pubDate>Tue, 01 Feb 2011 20:07:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-104382</guid>
		<description>Chase are complete idiots when it comes to the web. I&#039;m a web designer, and I can&#039;t tell you how many times I&#039;ve complained to them about how much their online interface SUCKS. I got these dumb emails too (thing is, I have not contacted Chase about any fraudulent purchases ... ???) and reported them to abuse@chase.com figuring they were phishing. lol Hopefully they get the point. Looks like lots of other knowledgeable folks have done similar things. I have BofA, in fact switched accounts to Chase in 2009 after 15 years of banking with them cuz they were suddenly tacking all kinds of fees to my accounts. Well, Chase is not only doing the same exact thing now (despite claiming that they&#039;d &quot;never do this to their clients!&quot; two years ago) but they suck big time when it comes to the online environment. Which is why I&#039;m switching over to Schwab momentarily ...</description>
		<content:encoded><![CDATA[<p>Chase are complete idiots when it comes to the web. I&#8217;m a web designer, and I can&#8217;t tell you how many times I&#8217;ve complained to them about how much their online interface SUCKS. I got these dumb emails too (thing is, I have not contacted Chase about any fraudulent purchases &#8230; ???) and reported them to <a href="mailto:abuse@chase.com">abuse@chase.com</a> figuring they were phishing. lol Hopefully they get the point. Looks like lots of other knowledgeable folks have done similar things. I have BofA, in fact switched accounts to Chase in 2009 after 15 years of banking with them cuz they were suddenly tacking all kinds of fees to my accounts. Well, Chase is not only doing the same exact thing now (despite claiming that they&#8217;d &#8220;never do this to their clients!&#8221; two years ago) but they suck big time when it comes to the online environment. Which is why I&#8217;m switching over to Schwab momentarily &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rufus</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-103919</link>
		<dc:creator>Rufus</dc:creator>
		<pubDate>Fri, 28 Jan 2011 08:32:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-103919</guid>
		<description>Incredible.  My wife just went through the same bizarre process after unauthorized charges appeared on her card.  Exactly the same as what is described here.  Like everyone else, I googled secure.dx to try to get a fix on what sort of lame scam we had stumbled into.</description>
		<content:encoded><![CDATA[<p>Incredible.  My wife just went through the same bizarre process after unauthorized charges appeared on her card.  Exactly the same as what is described here.  Like everyone else, I googled secure.dx to try to get a fix on what sort of lame scam we had stumbled into.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-102390</link>
		<dc:creator>Jeff</dc:creator>
		<pubDate>Tue, 18 Jan 2011 15:41:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-102390</guid>
		<description>ROFL!!!  Amazing!  I am currently in the state of paranoia doing whois lookups on secure-dx.com and emailing the fraud center to tell them someone outside the US is trying to scam their customers. This is absurd!  Thanks for the post.</description>
		<content:encoded><![CDATA[<p>ROFL!!!  Amazing!  I am currently in the state of paranoia doing whois lookups on secure-dx.com and emailing the fraud center to tell them someone outside the US is trying to scam their customers. This is absurd!  Thanks for the post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brandon</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-100318</link>
		<dc:creator>Brandon</dc:creator>
		<pubDate>Mon, 03 Jan 2011 19:25:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-100318</guid>
		<description>Thanks for posting this. I found your article when I looked up an 866 phone number calling my phone. I recently had unauthorized activity on my card, and went through a claims process identical to the one you described. Besides being disconcerted that my card was somehow being used without my knowledge (despite the fact that it was still on my person), I wasn&#039;t tech-savvy enough (or didn&#039;t have enough common sense, even) to be alarmed at the process for filing my claim verification online. I&#039;m not sure what Chase was calling me about just now, but I&#039;m relieved that I found your post and now feel enlightened about the oddness of their process, and also relieved of fears that this is a phishing scam. Again, thanks!</description>
		<content:encoded><![CDATA[<p>Thanks for posting this. I found your article when I looked up an 866 phone number calling my phone. I recently had unauthorized activity on my card, and went through a claims process identical to the one you described. Besides being disconcerted that my card was somehow being used without my knowledge (despite the fact that it was still on my person), I wasn&#8217;t tech-savvy enough (or didn&#8217;t have enough common sense, even) to be alarmed at the process for filing my claim verification online. I&#8217;m not sure what Chase was calling me about just now, but I&#8217;m relieved that I found your post and now feel enlightened about the oddness of their process, and also relieved of fears that this is a phishing scam. Again, thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-100279</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Mon, 03 Jan 2011 14:52:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-100279</guid>
		<description>Another huge thank you for this post.  Started to get really freaked out because we got a streamline re-fi offer from Chase Mortgage.  I realized that I had no idea that the phone number I called was legit.  Then the secure link comes from this dumb address and I really started to get worried, because this is rinky dink.

I never gave my social on the phone, and they seemed to know all the information they should have known, but still, let&#039;s make people feel better, not worse with our secure communications.  

I would have felt better if they&#039;d just sent the pdf&#039;s as an e-mail attachment.</description>
		<content:encoded><![CDATA[<p>Another huge thank you for this post.  Started to get really freaked out because we got a streamline re-fi offer from Chase Mortgage.  I realized that I had no idea that the phone number I called was legit.  Then the secure link comes from this dumb address and I really started to get worried, because this is rinky dink.</p>
<p>I never gave my social on the phone, and they seemed to know all the information they should have known, but still, let&#8217;s make people feel better, not worse with our secure communications.  </p>
<p>I would have felt better if they&#8217;d just sent the pdf&#8217;s as an e-mail attachment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-99628</link>
		<dc:creator>Jim</dc:creator>
		<pubDate>Thu, 30 Dec 2010 14:34:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-99628</guid>
		<description>WTF.  Just received a similar email regarding our mortgage refi - not a minor transaction!  And boy o boy, this makes me feel better:  

http://secure-dx.com/

broken page, running IIS.  nice.  Oh, they forgot to program for non-www.  nice.  IT kings!  Yeah, this system is ridiculous.  OK, with the www, it redirects to isentry.com - which is who the domain is registered to. 

They refer me to this site to explain how this is a top-level state of the art security system (that happens to reek of phishing)...

http://www.wolterskluwerfs.com/Content/Products/ProductDetail/Secure_Document_Exchange.aspx

&quot;SDX Secure Document Exchange (SDX) provides a powerful, secure, and simple way for financial institutions to electronically transmit information and documents over the Internet. SDX employs industry-leading security, including PKI encryption and multi-level user authentication, to keep communications safe at every step of the process.&quot;

Ya.  &quot;industry-leading security&quot; like animated gifs are the cutting edge of graphic design.</description>
		<content:encoded><![CDATA[<p>WTF.  Just received a similar email regarding our mortgage refi &#8211; not a minor transaction!  And boy o boy, this makes me feel better:  </p>
<p><a href="http://secure-dx.com/" rel="nofollow">http://secure-dx.com/</a></p>
<p>broken page, running IIS.  nice.  Oh, they forgot to program for non-www.  nice.  IT kings!  Yeah, this system is ridiculous.  OK, with the www, it redirects to isentry.com &#8211; which is who the domain is registered to. </p>
<p>They refer me to this site to explain how this is a top-level state of the art security system (that happens to reek of phishing)&#8230;</p>
<p><a href="http://www.wolterskluwerfs.com/Content/Products/ProductDetail/Secure_Document_Exchange.aspx" rel="nofollow">http://www.wolterskluwerfs.com/Content/Products/ProductDetail/Secure_Document_Exchange.aspx</a></p>
<p>&#8220;SDX Secure Document Exchange (SDX) provides a powerful, secure, and simple way for financial institutions to electronically transmit information and documents over the Internet. SDX employs industry-leading security, including PKI encryption and multi-level user authentication, to keep communications safe at every step of the process.&#8221;</p>
<p>Ya.  &#8220;industry-leading security&#8221; like animated gifs are the cutting edge of graphic design.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kate</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-98616</link>
		<dc:creator>Kate</dc:creator>
		<pubDate>Thu, 23 Dec 2010 08:47:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-98616</guid>
		<description>OH, and the password isn&#039;t &quot;password&quot; anymore....but, it&#039;s still right there in the e-mail even if it is 43igsowtisf or something like that.</description>
		<content:encoded><![CDATA[<p>OH, and the password isn&#8217;t &#8220;password&#8221; anymore&#8230;.but, it&#8217;s still right there in the e-mail even if it is 43igsowtisf or something like that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kate</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-98615</link>
		<dc:creator>Kate</dc:creator>
		<pubDate>Thu, 23 Dec 2010 08:44:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-98615</guid>
		<description>it&#039;s december 2010 + this crap is still happening!  omg!  MONKEY, thanks for your post + investigation + suggestion.  I&#039;m just an end user, but with above average tech savy + this thing reads SCAM like crazy.  + it&#039;s not...that&#039;s mind blowing.  weirder--the call center in the phillipines that handles fraud charges were a disaster--didn&#039;t know 11 was november, not october, sent me to regular customer service for someone to &quot;read me my transactions&quot; even with a fax from me on their screen already showing all the fraud charges, and even the manager who was generally good, omitted over $100 in charges until I insisted several times that his numbers were wrong.  DISASTER!!!  NIGHTMARE!!!  + now they are adding all these rules to keep &quot;free checking&quot; ----I&#039;M OUTTA THERE.</description>
		<content:encoded><![CDATA[<p>it&#8217;s december 2010 + this crap is still happening!  omg!  MONKEY, thanks for your post + investigation + suggestion.  I&#8217;m just an end user, but with above average tech savy + this thing reads SCAM like crazy.  + it&#8217;s not&#8230;that&#8217;s mind blowing.  weirder&#8211;the call center in the phillipines that handles fraud charges were a disaster&#8211;didn&#8217;t know 11 was november, not october, sent me to regular customer service for someone to &#8220;read me my transactions&#8221; even with a fax from me on their screen already showing all the fraud charges, and even the manager who was generally good, omitted over $100 in charges until I insisted several times that his numbers were wrong.  DISASTER!!!  NIGHTMARE!!!  + now they are adding all these rules to keep &#8220;free checking&#8221; &#8212;-I&#8217;M OUTTA THERE.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Evelyn</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-96650</link>
		<dc:creator>Evelyn</dc:creator>
		<pubDate>Thu, 09 Dec 2010 20:05:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-96650</guid>
		<description>I love &quot;Not phishing &quot;. He/She is very detailed and is a wide thinker. ALso, I work for Chase and I know how these things worked, so it&#039;s really legit as to what I can say. All these things on this website are clearly and perfectly just moans and cries of people who had been defrauded and lost all their money because of a fraudster, and not Chase. You guys should think more about it, you try not to use your card online frequently or maybe, just even the thought of ALL banks having the same issue. Why not do this. Type in to Google, &quot;WAMU complaints&quot; or &quot;Wells Fargo bank complaints&quot;. See guys, you&#039;re not alone. The bank is here to protect your money, and even if you guys complain about it, All is in the REg E, and the government&#039;s federal law that what these banks are doing (such as Chase) are all legit.</description>
		<content:encoded><![CDATA[<p>I love &#8220;Not phishing &#8220;. He/She is very detailed and is a wide thinker. ALso, I work for Chase and I know how these things worked, so it&#8217;s really legit as to what I can say. All these things on this website are clearly and perfectly just moans and cries of people who had been defrauded and lost all their money because of a fraudster, and not Chase. You guys should think more about it, you try not to use your card online frequently or maybe, just even the thought of ALL banks having the same issue. Why not do this. Type in to Google, &#8220;WAMU complaints&#8221; or &#8220;Wells Fargo bank complaints&#8221;. See guys, you&#8217;re not alone. The bank is here to protect your money, and even if you guys complain about it, All is in the REg E, and the government&#8217;s federal law that what these banks are doing (such as Chase) are all legit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sue</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-91329</link>
		<dc:creator>sue</dc:creator>
		<pubDate>Tue, 02 Nov 2010 19:02:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-91329</guid>
		<description>this is the second time my chase account has been used without my consent but I didnt have to do any of this the frist time! they did every thing over the phone and refunded all the disputed charges Im not doing this but I will be calling the bank back and telling them what I think</description>
		<content:encoded><![CDATA[<p>this is the second time my chase account has been used without my consent but I didnt have to do any of this the frist time! they did every thing over the phone and refunded all the disputed charges Im not doing this but I will be calling the bank back and telling them what I think</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathaniel Jones Jr</title>
		<link>http://www.pixelmonkey.org/2009/08/21/chase-insecure/comment-page-3#comment-85342</link>
		<dc:creator>Nathaniel Jones Jr</dc:creator>
		<pubDate>Sat, 25 Sep 2010 13:36:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.pixelmonkey.org/?p=432#comment-85342</guid>
		<description>This about the  Dish Network that was charged to my checking account on 9/24/10
for 180.00 dallars. That I didn&#039;t know anything about.I don&#039;t know anyone that has
Dish Network. I have Time Warner.</description>
		<content:encoded><![CDATA[<p>This about the  Dish Network that was charged to my checking account on 9/24/10<br />
for 180.00 dallars. That I didn&#8217;t know anything about.I don&#8217;t know anyone that has<br />
Dish Network. I have Time Warner.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using memcached
Page Caching using memcached
Database Caching 1/34 queries in 0.120 seconds using memcached
Object Caching 692/696 objects using memcached

Served from: _ @ 2012-02-07 19:29:46 -->
