var json_comments = new Array("<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-908317\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=5372\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-5372-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=5372\">timmus</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/01/coned-customers-personal-info-highly-vulnerable-to-online-theft.html#comment-908317\"><abbr class=\"published\" title=\"2007-01-30T16:42:16-05:00\">January 30, 2007  4:42 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(908317);\">Moderate</a> |</span>	<script type=\"text/javascript\" src=\"http://consumerist.com/mt-static/plugins/Moderate/moderate.js\"></script>	<script type=\"text/javascript\">		successMsg = \"\";	</script><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=908317');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I think it would be beneficial if someone went ahead and wrote a bot to go through a range of 10,000 account numbers and at least post the name and a mangled address, and put it on a big ConEd sucks website.  The negative publicity with a relatively harmless leak would be better than letting it sit there and stew, becoming a goldmine for identity thieves.</p><p>Another idea might be to write letters to 500 NYC attorneys informing them that their very own identity information is vulnerable.  That would get a response quick, assuming most have ConEd accounts.</p><p>Reminds me of SBC (Southwestern Bell) in 1997 when you could call their voice response system and simply enter a phone number, no other authentication, and get account information.  Unbelievable.</p><p>Also my professional trade organization had a huge vulnerability.  If you entered an account number to get journal subscription information, it would \"confirm\" back a bunch of address/telephone number details tied to the account.  Since they only used the numerical ranges of 1-50,000 you could easily parse the entire database.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(908317, 'timmus')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-908342\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">cdmunch    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/01/coned-customers-personal-info-highly-vulnerable-to-online-theft.html#comment-908342\"><abbr class=\"published\" title=\"2007-01-30T16:45:36-05:00\">January 30, 2007  4:45 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(908342);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=908342');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I would hate to have thieves break in and see my four months of unpaid bills up there. </p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(908342, 'cdmunch')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-908498\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=2204\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-2204-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=2204\">Narnia</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/01/coned-customers-personal-info-highly-vulnerable-to-online-theft.html#comment-908498\"><abbr class=\"published\" title=\"2007-01-30T17:05:16-05:00\">January 30, 2007  5:05 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(908498);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=908498');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>By the way, your new <a href=\"http://en.wikipedia.org/wiki/Favicon\" rel=\"nofollow\">Favicon</a> looks like the Chicago Cubs \"C\". I like.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(908498, 'Narnia')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-908557\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=1056\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-1056-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=1056\">TPIRman</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/01/coned-customers-personal-info-highly-vulnerable-to-online-theft.html#comment-908557\"><abbr class=\"published\" title=\"2007-01-30T17:14:06-05:00\">January 30, 2007  5:14 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(908557);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=908557');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><a href=\"http://www.digg.com/security/ConEd_Customer_s_Personal_Info_Highly_Vulnerable_To_Online_Theft\" rel=\"nofollow\">Digg it</a>.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(908557, 'TPIRman')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-908783\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=1593\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=1593\">Kornkob</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/01/coned-customers-personal-info-highly-vulnerable-to-online-theft.html#comment-908783\"><abbr class=\"published\" title=\"2007-01-30T17:50:38-05:00\">January 30, 2007  5:50 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(908783);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=908783');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><i>Another idea might be to write letters to 500 NYC attorneys informing them that their very own identity information is vulnerable. That would get a response quick, assuming most have ConEd accounts.</i></p><p>Or brute force the system, grab everyone's names and start terminating service for any lawyer,  politician or ConEd executive found.   </p><p>Not that I'm suggesting that anyone actually <b>do</b> such a thing but you can be damned sure the problem would be fixed toot sweet once a bunch of McMansions go dark.   </p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(908783, 'Kornkob')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-908917\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=3962\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=3962\">louise</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/01/coned-customers-personal-info-highly-vulnerable-to-online-theft.html#comment-908917\"><abbr class=\"published\" title=\"2007-01-30T18:06:52-05:00\">January 30, 2007  6:06 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(908917);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=908917');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I was on a jury in a civil case involving Con Ed about 15 years ago; their lawyers were crude idiots.</p><p>And, worst of all, badly dressed!  </p><p>I doubt anything's changed in their law department.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(908917, 'louise')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-909085\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">sissnitz    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/01/coned-customers-personal-info-highly-vulnerable-to-online-theft.html#comment-909085\"><abbr class=\"published\" title=\"2007-01-30T18:30:52-05:00\">January 30, 2007  6:30 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(909085);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=909085');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Hey kornkob, I'm a lawyer, I have no McMansion (just a rent-gouged little 1br) and I'm drowning in student loan debt over here.  Let's just pick on the Con Ed execs and crooked politicos, OK?  :)</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(909085, 'sissnitz')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-909627\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=5372\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-5372-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=5372\">timmus</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/01/coned-customers-personal-info-highly-vulnerable-to-online-theft.html#comment-909627\"><abbr class=\"published\" title=\"2007-01-30T19:58:48-05:00\">January 30, 2007  7:58 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(909627);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=909627');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>No problem sissnitz... just get the people using over 5,000 kWh of power.  Those are gonna be the McMansions.  Or the sources of good weed.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(909627, 'timmus')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-910044\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=2610\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-2610-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=2610\">dave the wet sprocket</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/01/coned-customers-personal-info-highly-vulnerable-to-online-theft.html#comment-910044\"><abbr class=\"published\" title=\"2007-01-30T21:01:34-05:00\">January 30, 2007  9:01 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(910044);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=910044');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><blockquote>We emailed this information to ConEd earlier this month but never received a reply back, so now we're going public.</blockquote><br />did you get multiple unsatisfactory responses from the reps/supervisors? did you escalate it to some executive-level csr? have any consumer protection agencies been notified?</p><p>maybe it's just me, but i'm a little leery of the whole \"we haven't gotten a response to this security issue, so we're gonna go ahead and tell everyone\" methodology. whether you're talking about exploitable open ports or buffer overruns or weak website security, it's advertising an issue to anyone who might be interested in taking advantage, who may not have known before the announcement.</p><p>say someone breaks into coned's system and starts going to town. say they found out about the vulnerability from consumerist or some link. coned may be the fools with the weak security, but consumerist would be part of the process that facilitated the escalation. if i stand on a street corner announcing to everyone, \"hey, the bank left the vault unlocked!\", i may not be guilty of a crime, but i'm still an *sshole.</p><p>unless of course you did more than just send them a single courtesy email a few weeks ago, in which case all is forgiven.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(910044, 'dave the wet sprocket')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-910492\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=5372\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-5372-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=5372\">timmus</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/01/coned-customers-personal-info-highly-vulnerable-to-online-theft.html#comment-910492\"><abbr class=\"published\" title=\"2007-01-30T22:15:30-05:00\">January 30, 2007 10:15 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(910492);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=910492');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Oh, kudos to Ben & Co. for the screenshot.. that really drives the point home.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(910492, 'timmus')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-911645\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">mattbrown    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/01/coned-customers-personal-info-highly-vulnerable-to-online-theft.html#comment-911645\"><abbr class=\"published\" title=\"2007-01-31T05:14:42-05:00\">January 31, 2007  5:14 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(911645);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=911645');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I'm going to call ConEd and see if they can disable the ability for my account to be accessed online.  We'll see what they say.  I commend myself on a revolutionary idea.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(911645, 'mattbrown')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-911689\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=44370\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-44370-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=44370\">Holden Caulfield</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/01/coned-customers-personal-info-highly-vulnerable-to-online-theft.html#comment-911689\"><abbr class=\"published\" title=\"2007-01-31T05:53:13-05:00\">January 31, 2007  5:53 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(911689);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=911689');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I gotta call you on this one dave. When somebody steals, it is not somebody elses fault. Period. The access to information is not what makes a person do wrong. I have no qualms with telling the world that somebody has been running around with their pants around their ankles and their junk there for all to see. But this is just my opinion. </p><p>I wouldnt think you were an asshole for yelling that the bank left the vault unlocked. I would think that the person who took advantage of the situation would be the asshole. Wait, can I say asshole on consumerist??</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(911689, 'Holden Caulfield')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-914985\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=2610\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-2610-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=2610\">dave the wet sprocket</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/01/coned-customers-personal-info-highly-vulnerable-to-online-theft.html#comment-914985\"><abbr class=\"published\" title=\"2007-01-31T20:57:35-05:00\">January 31, 2007  8:57 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(914985);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=914985');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>i'm not saying consumerist should be considered liable for any trouble that someone else decides to start over this. my concern is how much concern is shown for the consumers at risk.<br />was coned simply sent a single email as a warning? was it sent to anyone in particular, or some anonymous \"contact us\" address? were there any follow-up messages sent? was there any regulatory agency contacted before the rest of the world? more information is needed.<br />like i said, if more was done than a cursory notification, then all is forgiven. but if all that was sent was a single 'fyi', then coned wasn't the only one who fell asleep at the consumer protection switch. keep in mind that we're not talking about a bank- a criminal wouldn't just have the capacity to defraud coned. they'd have the capacity to defraud any number of innocent consumers. to enable that behavior on a consumer-centric site seems counterproductive.</p><p>it's a fuzzy area to be sure, but it seems to me that consumerist's obligation should be to steer clear of fuzziness when it's their own base at stake. i'm not talking about legal interpretations, i'm concerned about right and wrong. (even if it's just my own sense of it.)</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(914985, 'dave the wet sprocket')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-915136\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=44370\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-44370-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=44370\">Holden Caulfield</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/01/coned-customers-personal-info-highly-vulnerable-to-online-theft.html#comment-915136\"><abbr class=\"published\" title=\"2007-01-31T21:18:09-05:00\">January 31, 2007  9:18 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(915136);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=915136');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I completely understand what you meant with your pont. Just wanted to pick on you a bit. I definately would take the time to tell the person with the pants around the ankles several times that their pants were down before I proceed to call attention to his behaviour.</p><p>Now that I think about it, that kinda makes me an ass.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(915136, 'Holden Caulfield')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment last\" id=\"comment-10816232\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">Anonymous    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/01/coned-customers-personal-info-highly-vulnerable-to-online-theft.html#comment-10816232\"><abbr class=\"published\" title=\"2009-02-18T16:32:11-05:00\">February 18, 2009  4:32 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(10816232);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=10816232');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Feb 2009, and still nothing has changed on the coned.com site- unbelievable!  I was able to change direct payment info just with my account number and no other verification whatsoever!  This is scary.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(10816232, '')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>");


