<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Bank of America Email policies invite fraud</title>
	<atom:link href="http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/</link>
	<description>General interest observations and true web-log.</description>
	<lastBuildDate>Sat, 21 Nov 2009 13:46:20 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: fraud</title>
		<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/comment-page-1/#comment-1576692</link>
		<dc:creator>fraud</dc:creator>
		<pubDate>Sat, 12 Sep 2009 21:24:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.dvorak.org/blog/?p=38261#comment-1576692</guid>
		<description>Be aware of Domainsponsor scam company. This company operates under domainsponsor and oversee names and washes money via oversee company. Tax fraud and cheating is what they do. Stay away from them. Classaction lawsuit is coming.</description>
		<content:encoded><![CDATA[<p>Be aware of Domainsponsor scam company. This company operates under domainsponsor and oversee names and washes money via oversee company. Tax fraud and cheating is what they do. Stay away from them. Classaction lawsuit is coming.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jjtr.internet</title>
		<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/comment-page-1/#comment-1487161</link>
		<dc:creator>jjtr.internet</dc:creator>
		<pubDate>Fri, 13 Feb 2009 01:36:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.dvorak.org/blog/?p=38261#comment-1487161</guid>
		<description>bankofamerica.online_link@emailaccount.com 

is this a valid email account of boa</description>
		<content:encoded><![CDATA[<p><a href="mailto:bankofamerica.online_link@emailaccount.com" rel="nofollow" target="_blank">bankofamerica.online_link@emailaccount.com</a> </p>
<p>is this a valid email account of boa</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paddy-O</title>
		<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/comment-page-1/#comment-1478457</link>
		<dc:creator>Paddy-O</dc:creator>
		<pubDate>Wed, 28 Jan 2009 17:25:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.dvorak.org/blog/?p=38261#comment-1478457</guid>
		<description># 18 ran6110 said,  &quot;Check it out! Bailout Recipients Hosted Call To Defeat Key Labor Bill&quot;

God! I read &quot;the Employee Free Choice Act &quot;.  Amazing that they want to do away with secret balloting for Unions.  How scary is that?  Bunch of thugs.</description>
		<content:encoded><![CDATA[<p># 18 ran6110 said,  &#8220;Check it out! Bailout Recipients Hosted Call To Defeat Key Labor Bill&#8221;</p>
<p>God! I read &#8220;the Employee Free Choice Act &#8220;.  Amazing that they want to do away with secret balloting for Unions.  How scary is that?  Bunch of thugs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tahos</title>
		<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/comment-page-1/#comment-1478454</link>
		<dc:creator>tahos</dc:creator>
		<pubDate>Wed, 28 Jan 2009 17:22:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.dvorak.org/blog/?p=38261#comment-1478454</guid>
		<description>I think ther&#039;s some confusion here about messages that are &quot;spam&quot; versus messages that are &quot;phish.&quot; There is a very important distinction: the definition of SPAM is pretty subjective. However the definition of phish is not. Which one are we talking about here? 

Marc seems like a smart enough guy that he took a look at the e-mail headers and figured out that an e-mail from bank of america came from a third-party sender. He seems to want all e-mail from bank of america to come from a machine that has a DNS record with something like .bankofamerica.com in it. Sounds fair, but also difficult especially since it&#039;s a fairly large company. Here&#039;s another idea.

How about if bank of america used some kind of tag on their messages to indicate they were legitimately from them? 

I took a look at some legit e-mail I got from Bank of America, the customer loyalty e-mail similar to what Marc received, and there are SPF records authorizing those for bank of america&#039;s domains. So, they actually *have* done something to allow systems to validate e-mail from them. Some other e-mail I get from them has DKIM signatures on it, so I know they are working on that too.

Maybe instead of switching banks, we should also go to our ISPs and spam vendors and ask them to start paying attention to the e-mail authentication protocols as well?</description>
		<content:encoded><![CDATA[<p>I think ther&#8217;s some confusion here about messages that are &#8220;spam&#8221; versus messages that are &#8220;phish.&#8221; There is a very important distinction: the definition of SPAM is pretty subjective. However the definition of phish is not. Which one are we talking about here? </p>
<p>Marc seems like a smart enough guy that he took a look at the e-mail headers and figured out that an e-mail from bank of america came from a third-party sender. He seems to want all e-mail from bank of america to come from a machine that has a DNS record with something like .bankofamerica.com in it. Sounds fair, but also difficult especially since it&#8217;s a fairly large company. Here&#8217;s another idea.</p>
<p>How about if bank of america used some kind of tag on their messages to indicate they were legitimately from them? </p>
<p>I took a look at some legit e-mail I got from Bank of America, the customer loyalty e-mail similar to what Marc received, and there are SPF records authorizing those for bank of america&#8217;s domains. So, they actually *have* done something to allow systems to validate e-mail from them. Some other e-mail I get from them has DKIM signatures on it, so I know they are working on that too.</p>
<p>Maybe instead of switching banks, we should also go to our ISPs and spam vendors and ask them to start paying attention to the e-mail authentication protocols as well?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J Random</title>
		<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/comment-page-1/#comment-1478452</link>
		<dc:creator>J Random</dc:creator>
		<pubDate>Wed, 28 Jan 2009 17:20:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.dvorak.org/blog/?p=38261#comment-1478452</guid>
		<description>As soon as you introduce third party email services you&#039;re going to see cases where clue-impaired and sketchy operators can&#039;t properly maintain DNS entries for each campaign.

Have to wonder what your Authentication-Results: headers look like though. Did the message pass an SPF check? I can see that BofA created a record to delegate that to Conversen, but maybe Conversen screwed the pooch. Also, was any signing technology like DK/DKIM used, and did that verify?

You ultimately have to make your own choices about what you&#039;ll accept, and if you&#039;ll only accept FCrDNS-checked messages then good luck. But BofA isn&#039;t the only company you&#039;ll have an issue with...</description>
		<content:encoded><![CDATA[<p>As soon as you introduce third party email services you&#8217;re going to see cases where clue-impaired and sketchy operators can&#8217;t properly maintain DNS entries for each campaign.</p>
<p>Have to wonder what your Authentication-Results: headers look like though. Did the message pass an SPF check? I can see that BofA created a record to delegate that to Conversen, but maybe Conversen screwed the pooch. Also, was any signing technology like DK/DKIM used, and did that verify?</p>
<p>You ultimately have to make your own choices about what you&#8217;ll accept, and if you&#8217;ll only accept FCrDNS-checked messages then good luck. But BofA isn&#8217;t the only company you&#8217;ll have an issue with&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mr Diesel</title>
		<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/comment-page-1/#comment-1478370</link>
		<dc:creator>Mr Diesel</dc:creator>
		<pubDate>Wed, 28 Jan 2009 14:58:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.dvorak.org/blog/?p=38261#comment-1478370</guid>
		<description>#16

That is a great solution.  MY bank has started charging me (on a free account) a monthly charge and I&#039;m taking everything over to a credit union.

Screw the banks.</description>
		<content:encoded><![CDATA[<p>#16</p>
<p>That is a great solution.  MY bank has started charging me (on a free account) a monthly charge and I&#8217;m taking everything over to a credit union.</p>
<p>Screw the banks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LtSiver</title>
		<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/comment-page-1/#comment-1478344</link>
		<dc:creator>LtSiver</dc:creator>
		<pubDate>Wed, 28 Jan 2009 14:19:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.dvorak.org/blog/?p=38261#comment-1478344</guid>
		<description>Heh I agree Marc. Keep in mind this is also the bank that came up with that horribly stupid &quot;SiteKey&quot; feature... Which is totally susceptible to man in the middle if you&#039;re not the bank of america website.</description>
		<content:encoded><![CDATA[<p>Heh I agree Marc. Keep in mind this is also the bank that came up with that horribly stupid &#8220;SiteKey&#8221; feature&#8230; Which is totally susceptible to man in the middle if you&#8217;re not the bank of america website.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ran6110</title>
		<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/comment-page-1/#comment-1478150</link>
		<dc:creator>ran6110</dc:creator>
		<pubDate>Wed, 28 Jan 2009 03:40:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.dvorak.org/blog/?p=38261#comment-1478150</guid>
		<description>Check it out!

Bailout Recipients Hosted Call To Defeat Key Labor Bill

http://tr.im/d5rn

&quot;Three days after receiving $25 billion in federal bailout funds, Bank of America Corp. hosted a conference call with conservative activists and business officials to organize opposition to the U.S. labor community&#039;s top legislative priority.&quot;</description>
		<content:encoded><![CDATA[<p>Check it out!</p>
<p>Bailout Recipients Hosted Call To Defeat Key Labor Bill</p>
<p><a href="http://tr.im/d5rn" rel="nofollow" rel="nofollow" target="_blank"></a><a href='http://tr.im/d5rn' rel="nofollow" target="_blank">http://tr.im/d5rn</a></p>
<p>&#8220;Three days after receiving $25 billion in federal bailout funds, Bank of America Corp. hosted a conference call with conservative activists and business officials to organize opposition to the U.S. labor community&#8217;s top legislative priority.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paddy-O</title>
		<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/comment-page-1/#comment-1478063</link>
		<dc:creator>Paddy-O</dc:creator>
		<pubDate>Wed, 28 Jan 2009 01:19:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.dvorak.org/blog/?p=38261#comment-1478063</guid>
		<description># 13 Marc Perkel said,  &quot;Yes Paddy-O - you see my point then?&quot;

Oh, yes.</description>
		<content:encoded><![CDATA[<p># 13 Marc Perkel said,  &#8220;Yes Paddy-O &#8211; you see my point then?&#8221;</p>
<p>Oh, yes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AdmFubar</title>
		<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/comment-page-1/#comment-1478052</link>
		<dc:creator>AdmFubar</dc:creator>
		<pubDate>Wed, 28 Jan 2009 00:58:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.dvorak.org/blog/?p=38261#comment-1478052</guid>
		<description>everyone join a credit union.... enough said</description>
		<content:encoded><![CDATA[<p>everyone join a credit union&#8230;. enough said</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: the real billybob</title>
		<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/comment-page-1/#comment-1478037</link>
		<dc:creator>the real billybob</dc:creator>
		<pubDate>Wed, 28 Jan 2009 00:38:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.dvorak.org/blog/?p=38261#comment-1478037</guid>
		<description>Scank of America deserves to go down the tubes. They practice predatory lending on a daily basis.
Oooooooo don&#039;t get me started!</description>
		<content:encoded><![CDATA[<p>Scank of America deserves to go down the tubes. They practice predatory lending on a daily basis.<br />
Oooooooo don&#8217;t get me started!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mr. Fusion</title>
		<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/comment-page-1/#comment-1478026</link>
		<dc:creator>Mr. Fusion</dc:creator>
		<pubDate>Wed, 28 Jan 2009 00:20:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.dvorak.org/blog/?p=38261#comment-1478026</guid>
		<description>#13, Marc,

I really am sorry, but, Cow-Paddy has this comprehension problem. Even worse, he thinks he knows what this is about. It doesn&#039;t matter, he is going to suggest this is your fault.</description>
		<content:encoded><![CDATA[<p>#13, Marc,</p>
<p>I really am sorry, but, Cow-Paddy has this comprehension problem. Even worse, he thinks he knows what this is about. It doesn&#8217;t matter, he is going to suggest this is your fault.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marc Perkel</title>
		<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/comment-page-1/#comment-1477986</link>
		<dc:creator>Marc Perkel</dc:creator>
		<pubDate>Tue, 27 Jan 2009 23:19:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.dvorak.org/blog/?p=38261#comment-1477986</guid>
		<description>Yes Paddy-O - you see my point then?</description>
		<content:encoded><![CDATA[<p>Yes Paddy-O &#8211; you see my point then?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paddy-O</title>
		<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/comment-page-1/#comment-1477915</link>
		<dc:creator>Paddy-O</dc:creator>
		<pubDate>Tue, 27 Jan 2009 21:39:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.dvorak.org/blog/?p=38261#comment-1477915</guid>
		<description>#11 Holy crap.  customerloyalty.bankofamerica.com resolves to conversen.com</description>
		<content:encoded><![CDATA[<p>#11 Holy crap.  customerloyalty.bankofamerica.com resolves to conversen.com</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marc Perkel</title>
		<link>http://www.dvorak.org/blog/2009/01/27/bank-of-america-email-policies-invite-fraud/comment-page-1/#comment-1477911</link>
		<dc:creator>Marc Perkel</dc:creator>
		<pubDate>Tue, 27 Jan 2009 21:35:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.dvorak.org/blog/?p=38261#comment-1477911</guid>
		<description>The email was supposedly from BofA.

From: &quot;Bank of America&quot; 
Sender: BankofAmerica@customerloyalty.bankofamerica.com
To: &quot;Marc Perkel&quot; 
Reply-To: customerservice@card.bankofamerica.com
Date: 27 Jan 2009 13:07:49 -0500
Subject: Use your Platinum Plus(R) credit card today.
Received: from &lt;strong&gt;tr202154.cv47.net ([216.75.202.154])&lt;/strong&gt;
	by venus.junkemailfilter.com with esmtp (Exim 4.69)
	id 1LRsMQ-0006cA-IQ on interface=65.49.42.50
	for marc@perkel.com; Tue, 27 Jan 2009 10:08:47 -0800</description>
		<content:encoded><![CDATA[<p>The email was supposedly from BofA.</p>
<p>From: &#8220;Bank of America&#8221;<br />
Sender: <a href="mailto:BankofAmerica@customerloyalty.bankofamerica.com" rel="nofollow" target="_blank">BankofAmerica@customerloyalty.bankofamerica.com</a><br />
To: &#8220;Marc Perkel&#8221;<br />
Reply-To: <a href="mailto:customerservice@card.bankofamerica.com" rel="nofollow" target="_blank">customerservice@card.bankofamerica.com</a><br />
Date: 27 Jan 2009 13:07:49 -0500<br />
Subject: Use your Platinum Plus(R) credit card today.<br />
Received: from <strong>tr202154.cv47.net ([216.75.202.154])</strong><br />
	by venus.junkemailfilter.com with esmtp (Exim 4.69)<br />
	id 1LRsMQ-0006cA-IQ on interface=65.49.42.50<br />
	for <a href="mailto:marc@perkel.com" rel="nofollow" target="_blank">marc@perkel.com</a>; Tue, 27 Jan 2009 10:08:47 -0800</p>
]]></content:encoded>
	</item>
</channel>
</rss>
