var json_comments = new Array("<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1264876\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=16563\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-16563-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=16563\">Trai_Dep</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1264876\"><abbr class=\"published\" title=\"2007-04-13T05:22:37-05:00\">April 13, 2007  5:22 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1264876);\">Moderate</a> |</span>	<script type=\"text/javascript\" src=\"http://consumerist.com/mt-static/plugins/Moderate/moderate.js\"></script>	<script type=\"text/javascript\">		successMsg = \"\";	</script><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1264876');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Somebody alert Boston Homeland Security: Soghoian just stole <b>billions of dollars </b> from the Federal Reserve.</p><p>Oh, wait...</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1264876, 'Trai_Dep')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1264883\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=85404\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=85404\">werdna</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1264883\"><abbr class=\"published\" title=\"2007-04-13T05:23:38-05:00\">April 13, 2007  5:23 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1264883);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1264883');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Of course Sitekey is vulnerable because it depends on the competence of the person using it. Most people going to a BOA phishing site would commpletely forget about the fact that they have a sitekey (I know I would). BOA is still a good target for phishers because there will still be a small percent of people that will put in their info unaware of sitekey.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1264883, 'werdna')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1264959\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=82973\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-82973-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=82973\">Bradley</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1264959\"><abbr class=\"published\" title=\"2007-04-13T05:41:46-05:00\">April 13, 2007  5:41 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1264959);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1264959');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Ill just have to patiently explain to them that this must be where that large sum of money I deposited went to.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1264959, 'Bradley')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1265063\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=15009\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=15009\">Skeptic</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1265063\"><abbr class=\"published\" title=\"2007-04-13T06:18:06-05:00\">April 13, 2007  6:18 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1265063);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1265063');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Cute. The man in the middle attack succeeds again...</p><p>This just goes to show that the Site Key system is not only an inconvenient time waster that most people ignore, but it provides only a false sense of security even for those people who do pay attention.</p><p>BofA needs to replace security theater with actual security. The only thing that will make them do that are laws that hold banks strictly and financially accountable for when they give out funds to people other than the account holder. The law needs teeth in the form of punitive damages and an exemption from mandatory arbitration clauses.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1265063, 'Skeptic')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1265507\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=11093\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-11093-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=11093\">Xkeeper</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1265507\"><abbr class=\"published\" title=\"2007-04-13T11:45:55-05:00\">April 13, 2007 11:45 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1265507);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1265507');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Consider especially that since this is \"invulnerable to security attacks\", well, that just gives people a false sense of security.</p><p>And with that comes a lowered guard.</p><p>If this method ever becomes prevailant, you can be pretty damn sure that it might even be more effective than the other one... Especially since if it's right, they will have access whil emaking it look entirely normal to you.</p><p>Uh oh.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1265507, 'Xkeeper')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1265528\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=8695\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-8695-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=8695\">medalian1</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1265528\"><abbr class=\"published\" title=\"2007-04-13T11:59:20-05:00\">April 13, 2007 11:59 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1265528);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1265528');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I hate that sitekey and ING's pin thing. I just like username/passwords. Sucks that we have so many stupid people!</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1265528, 'medalian1')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1265581\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=50951\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-50951-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=50951\">5cents</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1265581\"><abbr class=\"published\" title=\"2007-04-13T12:25:28-05:00\">April 13, 2007 12:25 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1265581);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1265581');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>What a fantastically amazing graphic.  Everything is just so clear :)  Agreed, BoA is out of line saying is's invulberable.  I find SiteKey a bit gimmicky too.  </p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1265581, '5cents')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1265593\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=72370\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-72370-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=72370\">OnceWasCool</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1265593\"><abbr class=\"published\" title=\"2007-04-13T12:32:53-05:00\">April 13, 2007 12:32 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1265593);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1265593');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>This just proves that some people just shouldn't have a computer.</p><p>I told my wife, if the bank or credit card companies contact you through email, just delete it no matter what it says. She has a URL to our bank and our credit card companies and she has been very smart about it.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1265593, 'OnceWasCool')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1265893\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=68654\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-68654-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=68654\">mac-phisto</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1265893\"><abbr class=\"published\" title=\"2007-04-13T13:41:21-05:00\">April 13, 2007  1:41 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1265893);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1265893');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>heheh. i blame the regulators. they are the ones touting dual authentication. prove positive that if someone wants to steal, they will find a way.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1265893, 'mac-phisto')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1266171\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=83276\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=83276\">MameDennis</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1266171\"><abbr class=\"published\" title=\"2007-04-13T14:24:28-05:00\">April 13, 2007  2:24 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1266171);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1266171');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Until BOA lets me create a more secure password for my account than I have with my CD club, the sitekey leaves me unimpressed.  No \"rogue characters\"?  Bah.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1266171, 'MameDennis')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1266518\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">Beerad    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1266518\"><abbr class=\"published\" title=\"2007-04-13T15:10:40-05:00\">April 13, 2007  3:10 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1266518);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1266518');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c1265063\" rel=\"nofollow\">Skeptic</a>: \"The only thing that will make them do that are laws that hold banks strictly and financially accountable for when they give out funds to people other than the account holder.\"</p><p>Umm, what exactly would this mean?  If the bank gets defrauded by someone and it's caught, they're still going to give me my money.  It's not like \"Oh snap, we're sorry, someone scammed us out of your money last month so you're broke now.\"   And if you actually want to impose punitive damages, as your next sentence suggests, I can't wait for the next wave of ID verification -- \"Oh, the fingerprint was last month.  Now we need a blood sample and a DNA swab.  Sorry, we're just protecting ourselves.\" </p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1266518, 'Beerad')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1266716\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=52253\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-52253-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=52253\">BMR</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1266716\"><abbr class=\"published\" title=\"2007-04-13T15:28:10-05:00\">April 13, 2007  3:28 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1266716);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1266716');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>the missing factor here is that a human must fall for it. so as long as there are humans with bank accounts, there will be one who falls for it.  that is not BoA's fault...that is just a fact.  They could go to the end of the earth the tighten security and there will always be a sucker giving their info away.  It is really naive to imply that BoA does not care about security - sure they deserve some criticism, but obviously they care about security.  They are a HUGE bank, billions and billions of dollars - duh, they care about security.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1266716, 'BMR')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1267601\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">bastarre    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1267601\"><abbr class=\"published\" title=\"2007-04-13T17:07:23-05:00\">April 13, 2007  5:07 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1267601);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1267601');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c1266171\" rel=\"nofollow\">MameDennis</a>: You ain't lying about that.  WTF do you mean I can't use special symbols?  That's a big part of what makes passwords strong.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1267601, 'bastarre')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1267893\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=73283\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=73283\">RubyKhan</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1267893\"><abbr class=\"published\" title=\"2007-04-13T17:38:09-05:00\">April 13, 2007  5:38 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1267893);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1267893');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Does anyone know of an online consumer banking site that uses a dongle like PayPal/Ebay? Some banks are starting to offer them on their business accounts.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1267893, 'RubyKhan')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1269112\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=80355\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=80355\">oldhat</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1269112\"><abbr class=\"published\" title=\"2007-04-13T19:50:47-05:00\">April 13, 2007  7:50 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1269112);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1269112');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>The worst part of this is that the Bank(s) hide behind all their security when things go wrong.</p><p>Like when somebody (usually an inside job) hacks the ATM system the bank thinks the customer is lying, since the system is perfect.</p><p>They put up all this and refuse to admit that it's not infallible.</p><p>If somebody robs the bank, no matter how it's done, it's the bank's fault. If it's a stolen identity, guess what, still the bank's fault! As they are the ones that got fooled! You still got your identity, but the bank got conned.</p><p>Yet, they blame you...</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1269112, 'oldhat')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1269875\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=68654\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-68654-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=68654\">mac-phisto</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1269875\"><abbr class=\"published\" title=\"2007-04-13T21:16:22-05:00\">April 13, 2007  9:16 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1269875);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1269875');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c1269112\" rel=\"nofollow\">oldhat</a>: you're right that it's the bank's <i>responsibility</i> b/c of laws developed to hold harmless ID theft victims. but i have encountered MANY instances where the \"victim\" acted more like an accomplice:</p><p>-$2,000 loss caused by a stolen ATM card <b>where the holder admitted to writing the PIN on the card with a sharpie pen</b>.</p><p>-$800+ loss due to a person who did not protect access to card & PIN from roommate.</p><p>-$4,500 loss due to a cardholder's acquaintance memorizing cardholder's PIN while accompanying her to ATM machine over the course of a few weeks. stole card & wiped out bank account in 3 days.</p><p>i believe the laws are written correctly, & i am not advocating otherwise. i am merely showing that some people are not as vigilant with sensitive information as they should be. ID theft is, after all, a socially engineered crime. if people weren't naive enough to fall for the bait, these scams wouldn't work.</p><p>& remember, banks aren't in business b/c they take losses. <b>BoA made $16.5 billion in profit in 2006 despite thousands of similar losses.</b> guess who's making up the difference?</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1269875, 'mac-phisto')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment last\" id=\"comment-1272906\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=86017\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=86017\">atbradley</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/04/bank-of-americas-perfect-security-system-actually-vulnerable-to-phishing.html#comment-1272906\"><abbr class=\"published\" title=\"2007-04-14T23:08:51-05:00\">April 14, 2007 11:08 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1272906);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1272906');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I'm a former Fleet Bank employee who ended up with a BoA account (and no job) after BoA's takeover of Fleet in 2005.  I've never been remotely impressed by SiteKey.  Look:  The idea is, you type in your login ID, then it shows you a picture and caption you picked out for yourself before you type in your password.  So you know it's really the bank's site before you type in your password.  Great.  Except that my login ID, <i>which BoA assigned when my account switched over, <b>is my debit card number!</b></i></p><p>So I guess all SiteKey is intended to do is make sure I know, right away, if I've given my debit card number to a phisher.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1272906, 'atbradley')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>");


