var json_comments = new Array("<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1190069\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=29982\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=29982\">velocipenguin</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/03/how-tjmaxx-hackers-stole-457-million-credit-cards.html#comment-1190069\"><abbr class=\"published\" title=\"2007-03-30T21:52:21-05:00\">March 30, 2007  9:52 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1190069);\">Moderate</a> |</span>	<script type=\"text/javascript\" src=\"http://consumerist.com/mt-static/plugins/Moderate/moderate.js\"></script>	<script type=\"text/javascript\">		successMsg = \"\";	</script><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1190069');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>The article only says that the crackers in question had access to the decryption <i>algorithm</i> used by TJX.  Access to the algorithm is not at all important, unless your company is run by idiots who think using a s00p3r-s3kr1t proprietary crypto scheme guarantees security.  Most of the world's most important crypto algorithms - including 3DES, the (somewhat inadequate) scheme used by every bank in the world - are available to the public.  The only thing that counts is the encryption key;  if TJX left their crypto keys in an area accessible to malicious intruders, then they deserve to be sued for everything they've got.  Encryption - regardless of algorithm - is completely worthless unless the key is kept as secure as possible.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1190069, 'velocipenguin')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1190645\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">electronics    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/03/how-tjmaxx-hackers-stole-457-million-credit-cards.html#comment-1190645\"><abbr class=\"published\" title=\"2007-03-31T00:02:19-05:00\">March 31, 2007 12:02 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1190645);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1190645');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>a worm? I suspect that Paula Rosenblum doesn't know what she's talking about when it comes to technology. The hackers didn't give a rat about how many cards they had access to, only that they had access to them. Whether it was 100, 1 million, or 45 million doesn't make a difference. The amount of abuse of the credit cards was likely very, very low when compared to the credit cards exposed. Hackers don't go after stuff like this to get in the media because as soon as that happens, it means that they can't leach off people's accounts anymore.</p><p>Throughout the breach, they had *access to* upwards of 45.7 million cards, but that doesn't mean that they *got* 45.7 million cards. The payment card industry tries to take the most liberal guess possible, since they have to worry about all the cardholders who potentially got their data stolen. </p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1190645, 'electronics')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment last\" id=\"comment-1191417\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=53106\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-53106-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=53106\">faust1200</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/03/how-tjmaxx-hackers-stole-457-million-credit-cards.html#comment-1191417\"><abbr class=\"published\" title=\"2007-03-31T04:35:34-05:00\">March 31, 2007  4:35 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1191417);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1191417');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>It was totally social engineering.  </p><p>Here's part of the alleged transcript:</p><p>\"Hello!! This is Terrance James Maxx.  I seemed to have forgotten my password and I can't get onto the server...\"</p><p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1191417, 'faust1200')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>");


