var json_comments = new Array("<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1713237\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=2234\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-2234-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=2234\">Fuzz</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1713237\"><abbr class=\"published\" title=\"2007-06-22T00:47:37-05:00\">June 22, 2007 12:47 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1713237);\">Moderate</a> |</span>	<script type=\"text/javascript\" src=\"http://consumerist.com/mt-static/plugins/Moderate/moderate.js\"></script>	<script type=\"text/javascript\">		successMsg = \"\";	</script><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1713237');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Another option is a virtual machine.  You can run them off your USB drive. Totally sandboxed, and you don't need to reboot.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1713237, 'Fuzz')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1713337\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=53169\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=53169\">Saeculorum</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1713337\"><abbr class=\"published\" title=\"2007-06-22T01:09:16-05:00\">June 22, 2007  1:09 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1713337);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1713337');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>A debit card is not covered under the Fair Credit Billing Act, even if it is swiped as a credit card. As such, there are none of the legally mandated protections that credit cards have.</p><p>Yes, your bank might offer to extend those protections anyway, but if your money is temporarily gone from your account due to fraud, your checks will still start to bounce.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1713337, 'Saeculorum')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1713406\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=72411\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=72411\">tentimesodds</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1713406\"><abbr class=\"published\" title=\"2007-06-22T01:25:56-05:00\">June 22, 2007  1:25 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1713406);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1713406');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Ben, if you use your debit card all over the place, it at least brings up the possibility that the number will be stolen. Especially at restaurants. If this happens on a debit card, you're SOL until it gets resolved. Credit card, different story.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1713406, 'tentimesodds')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1713800\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=114637\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=114637\">stopNgoBeau</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1713800\"><abbr class=\"published\" title=\"2007-06-22T03:12:02-05:00\">June 22, 2007  3:12 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1713800);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1713800');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Ditto  Saeculorum's post.  Your bank may offer full fraud protection, but the money that was fraudulently taken is still missing from your account until you get it taken care of.  With a credit card, your available limit just dips a bit, but you don't owe anything.</p><p>Also, I have contested three different fraudulent charges on my Capital One Bank debit card, and each one was reversed, against me, because they claimed they didn't get the requested documents from me, even though I faxed or emailed them in each time.  In all cases, the fax number on the form I had to fill out was either unknown by the person I was speaking to on the phone (thats the fax number listed on the form?  I've never heard of that extension), or they just never received it.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1713800, 'stopNgoBeau')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1714107\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=3187\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=3187\">nweaver</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1714107\"><abbr class=\"published\" title=\"2007-06-22T04:24:51-05:00\">June 22, 2007  4:24 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1714107);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1714107');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Notice I said my ATM card is ATM only, and NEVER used outside bank branches.  I refuse to use a \"check\" card.  I think I need to make it clearer why I do this.</p><p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1714107, 'nweaver')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1714111\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=66152\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=66152\">endless</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1714111\"><abbr class=\"published\" title=\"2007-06-22T04:25:27-05:00\">June 22, 2007  4:25 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1714111);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1714111');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I actually just setup a mac system for this exact purpose, online purchases and banking will from now on, be done on it.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1714111, 'endless')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1714118\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=3187\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=3187\">nweaver</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1714118\"><abbr class=\"published\" title=\"2007-06-22T04:26:33-05:00\">June 22, 2007  4:26 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1714118);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1714118');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>endless:  I have a Mac.  I still reboot into knoppix (you can do this if you have bootcamp installed on an x86 mac).</p><p>Online purchases?  Well, those use a credit card, so I don't care (much), I happily let Amazon save my credit card number, etc etc etc.<br /></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1714118, 'nweaver')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1714147\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=3187\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=3187\">nweaver</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1714147\"><abbr class=\"published\" title=\"2007-06-22T04:31:13-05:00\">June 22, 2007  4:31 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1714147);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1714147');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Endless:  I have a mac.  I use a mac.  I don't trust Apple's security enough, so I boot my Knoppix CD in my x86 Mac Mini...</p><p>AS for online shopping, as long as you use a credit card, who cares?  Feel free to use your Windows box, and don't even worry if it is 0wned (too much).    Credit card fraud online has the same impact as credit card fraud from TJ Max: it costs the card company and the merchants, but not you.<br /></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1714147, 'nweaver')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1714155\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=110622\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=110622\">samurailynn</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1714155\"><abbr class=\"published\" title=\"2007-06-22T04:33:08-05:00\">June 22, 2007  4:33 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1714155);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1714155');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I use a mac for all my web browsing, including online banking.  No problems that I know of with malignant software installing itself on here.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1714155, 'samurailynn')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1714281\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">gundark    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1714281\"><abbr class=\"published\" title=\"2007-06-22T05:05:22-05:00\">June 22, 2007  5:05 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1714281);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1714281');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Nweaver: I trust it enough to bet you cant cite even one example of anyone having a \"potentially malignant program\" cause problems with anyone's online banking on a Mac. </p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1714281, 'gundark')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1714384\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=66152\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=66152\">endless</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1714384\"><abbr class=\"published\" title=\"2007-06-22T05:48:42-05:00\">June 22, 2007  5:48 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1714384);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1714384');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>nweaver:</p><p>Ive used unsecured PCs for years, this mac should be  many steps ahead of that. Especially considering the mac will be on a light load as the majority of my surfing will still be done on the PC.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1714384, 'endless')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1715170\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=3187\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=3187\">nweaver</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1715170\"><abbr class=\"published\" title=\"2007-06-22T12:16:33-05:00\">June 22, 2007 12:16 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1715170);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1715170');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>THe mac's strength is primarily from \"minority platform\" effects, with a secondary strength from a bit better isolation model/better legacy (the Unix legacy rather than the DOS legacy).  There have been tons of nasty holes on Mac systems, which the attackers simply haven't bothered attacking.  As Apple's market and mindshare increases, this \"protection\" could easily vanish.</p><p>I look at the number of reported 0-days in Safari for Windows, and go \"all those bugs probably also exist in the Mac version\", and as a result I don't have faith in the overall Mac system.  Also looking at the number of \"security\" updates on Apple's updater.</p><p>It is better than Windows, and I feel very comfortable using a Mac for day to day activities.  </p><p>But at the cost of a serious breach of my financial accounts?  No.<br /></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1715170, 'nweaver')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1715247\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=101080\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-101080-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=101080\">anatak</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1715247\"><abbr class=\"published\" title=\"2007-06-22T12:46:17-05:00\">June 22, 2007 12:46 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1715247);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1715247');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c1713800\" rel=\"nofollow\">stopNgoBeau</a>: <br />Thats what you get for banking with Capitol One.  I've never had an issue getting fraudulent charges reversed, its never taken more than 5 minutes, and I've never ever had to email or fax anything in just so that they can pull the old \"we never got it\" stunt.</p><p>Whats in your wallet?  Cash, sucker!</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1715247, 'anatak')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1715283\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=19751\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-19751-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=19751\">lemur</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1715283\"><abbr class=\"published\" title=\"2007-06-22T12:52:16-05:00\">June 22, 2007 12:52 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1715283);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1715283');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c1713237\" rel=\"nofollow\">Fuzz</a>: A virtual machine is the next best thing to rebooting to an OS stored on trusted media but it is not as good.</p><p>For instance, if you run Linux in a virtual machine in Windows and there's a keylogger on the Windows host, you're screwed.  It is true the keylogger would not be able to do a targeted logging but it could record everything and let the evil guy sort it out later.</p><p>(What I mean by targeted logging is a method that takes advantage of context to separate interesting input from uninteresting stuff.  For instance, a keylogger that would attach to your browser could easily find out which fields are used for logging in and could record only what is entered in those fields.)<br /></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1715283, 'lemur')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1715290\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">sporesdeezeez    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1715290\"><abbr class=\"published\" title=\"2007-06-22T12:53:21-05:00\">June 22, 2007 12:53 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1715290);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1715290');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Way up at the top, <a href=\"#c1713237\" rel=\"nofollow\">Fuzz</a> mentioned virtual machines. This is a good point and should not be overlooked.</p><p>While I'm not sure if they offer a version for Macs, VMWare does offer their <a href=\"http://www.vmware.com/products/player/\" rel=\"nofollow\">free VMPlayer</a> for other platforms - I've personally used it for Windows and Linux (Ubuntu). It's pretty simple, and the virtual machine is self-contained and awkward to hack. The steps from their website say it all:<br /><blockquote><br />   1. Download VMware Player.<br />   2. Try the pre-built Browser Appliance virtual machine, configured for secure internet browsing.<br />   3. Visit Virtual Appliances at VMTN to download other free, pre-configured virtual machines from industry-leading ISV partners, open source partners and the VMware community.</blockquote></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1715290, 'sporesdeezeez')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1715294\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=1196\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-1196-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=1196\">MeOhMy</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1715294\"><abbr class=\"published\" title=\"2007-06-22T12:53:57-05:00\">June 22, 2007 12:53 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1715294);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1715294');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c1714107\" rel=\"nofollow\">nweaver</a>: <blockquote>Notice I said my ATM card is ATM only, and NEVER used outside bank branches. I refuse to use a \"check\" card. I think I need to make it clearer why I do this.</blockquote></p><p>Me too!  I specifically requested a non-\"check card\" when I switched bank accounts.  Apparently some banks are actually charging EXTRA for this.</p><p>The check card hits your bank account directly.  Sure, a PIN isn't the most secure thing in the world, but it's a lot better than the nothing that a check card has.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1715294, 'MeOhMy')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1715305\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=67910\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=67910\">virgilstar</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1715305\"><abbr class=\"published\" title=\"2007-06-22T12:56:36-05:00\">June 22, 2007 12:56 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1715305);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1715305');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Seriously, unless you're clicking links in phishing e-mails, and surfing for pron, then I really fail to see what the risk is.  If you have a windows PC, all the relevant updates, running the latest version of Firefox, running a good antivirus (CA) plus spybot S&D every week, emptying the browser cache every session, not storing any forms information, and only typing in addresses to the browser, not following links or even using bookmarks, then I just cannot see what the risk is.  I also run MSConfig every week or so, to check for startup/background tasks, and I know the registry on my PC inside-out, so can spot anny unwanted keys.</p><p>@nweaver - \"I happily let Amazon store my credit card details\".   Experience should tell you that a LARGE number  of identity theft issues come from a screw-up at a company's site, where a hard disk with X-bajillion numbers is stolen (Google \"ABN-AMRO security\" if you want more details on a classic example).   No matter what my personal security measures are, I for one will NEVER let any company store my card details, just for the convenience of one-click shopping.</p><p>The exception is PayPal, but I got the key-chain widget and absolutely refuse to \"verify\" my account by giving them my bank account number in addition to my card details.  I just deal with the inconvenience of not having a \"verified\" account.  I'm not an eBay seller so it's not a big deal.</p><p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1715305, 'virgilstar')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1715329\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=67910\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=67910\">virgilstar</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1715329\"><abbr class=\"published\" title=\"2007-06-22T13:00:03-05:00\">June 22, 2007  1:00 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1715329);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1715329');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>On the topic of keyloggers - only if you're stupid enough to actually enter personal information (SSNs, card #s) IN THE CORRECT ORDER does this become a risk.   I make a habit of using the keyboard and mouse in combination, to enter the card # in a random order.</p><p>e.g. if the card is 12345678 then I would enter 3456, then click on the left to enter 12, then click on the right to enter 78.   That way, any key-logger would get the numbers, but they would be in randomized order and therefore useless.</p><p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1715329, 'virgilstar')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1715345\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=88050\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=88050\">kenclunk</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1715345\"><abbr class=\"published\" title=\"2007-06-22T13:03:12-05:00\">June 22, 2007  1:03 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1715345);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1715345');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Another option is to stay at home and keep cash in a locked safe hidden in a secret spot under your matress. Then have security come when you are going to get the $10.00 out for a movie that night.</p><p>Seriously, rebooting your computer, or having a second computer just to access online banking???</p><p>I realize that there are some things that should be cautioned but I refuse to live in fear that some one will take over all of my accounts. </p><p>I'll save all of my energy by not worring and have more energy to deal with it when it happens.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1715345, 'kenclunk')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1715348\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">sporesdeezeez    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1715348\"><abbr class=\"published\" title=\"2007-06-22T13:03:52-05:00\">June 22, 2007  1:03 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1715348);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1715348');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c1715290\" rel=\"nofollow\">sporesdeezeez</a>: Good point about the keylogger. I agree, if the host machine is seriously compromised, you will not avoid that problem with a VM.</p><p>That said, I think we could agree that if you start with a clean, firewalled OS for the host machine, any assorted malware you come across while browsing in the VM will be very unlikely to cross into the host. That means that you have to use the VM for all browsing, not just the banking. You may want a separate high-security browsing VM to use as distinct from the everyday browsing VM.</p><p>For now this is a good trick that will foil most of the black hats out there. Eventually, if this catches on, I am sure that hackers will learn how to get past the virtual machine. There are already white hats who have devised a VM <a href=\"http://en.wikipedia.org/wiki/Blue_Pill_%28malware%29\" rel=\"nofollow\">\"blue pill\"</a> attack that promises to be quite devious if it's ever implemented.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1715348, 'sporesdeezeez')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1715650\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=3187\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=3187\">nweaver</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1715650\"><abbr class=\"published\" title=\"2007-06-22T13:56:51-05:00\">June 22, 2007  1:56 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1715650);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1715650');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>On VMs:  VMs are good for your risky websurfing, but they aren't good for your risk-free banking, because if the host is compromised, the VM is compromised.  There are also attacks on the VM infrastructure, but this forces the attacker to do 2x the work, which is often a \"why bother\" for now.</p><p>On keyloggers:  Keyloggers are a SERIOUS problem.  The City of Compton, CA, almost lost $400,000 to a keylogger-based attack, and did lose $50,000 I think.  This isn't just theoretical, its what attackers are really trying to do, and as they get smarter, will become even more critical targets.</p><p>And virgilstar: the identity theft risk from the credit card is low.  It doesn't get SS# (so you can't create NEW accounts), and if the thief uses the card #, I don't care, as see #1: until I write the check, it is not my money.<br /></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1715650, 'nweaver')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1715693\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=112723\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=112723\">jeff303</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1715693\"><abbr class=\"published\" title=\"2007-06-22T14:02:11-05:00\">June 22, 2007  2:02 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1715693);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1715693');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c1715170\" rel=\"nofollow\">nweaver</a>: </p><p>No, the Mac's strength is the architecture.  Mom and pop don't run as root all the time (like on Windows).   The user must enter a password to make \"root level\" changes to the system.  The only flaw that comes to mind is Safari opens downloaded dmgs by default (this can be turned off).</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1715693, 'jeff303')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1716099\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=3187\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=3187\">nweaver</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1716099\"><abbr class=\"published\" title=\"2007-06-22T14:50:36-05:00\">June 22, 2007  2:50 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1716099);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1716099');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Jeff303:  Windows theoretically has the same thing with Vista, they just didn't tune it as well (\"You are coming to a sad realization, cancel or allow\").</p><p>And 0wning the user can almost be as good as 0wning root on a single user machine anwyay.  You can do NASTY things in userspace when running as the user.</p><p>For day to day use, Mac, yeah, no problem.  I love my mac.  But when my life savings are at stake, the Mac is not secure enough for my tastes.<br /></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1716099, 'nweaver')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1716597\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=15848\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=15848\">FLConsumer</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1716597\"><abbr class=\"published\" title=\"2007-06-22T15:39:47-05:00\">June 22, 2007  3:39 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1716597);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1716597');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c1714155\" rel=\"nofollow\">samurailynn</a>: There's plenty of malware and security holes out there for Macs.  You just don't hear about them because they're not going to affect the majority of people.  There are also fewer attempts to exploit these because the payoff is so low.  Why bother spending all of your time & effort on something that'll only affect 5% of the computers out there when you can spend that same time and energy attacking 90% of the computers out there?</p><p>I \"live dangerously\" -- I happily surf with a PC, running a nice custom version of Winblows XP, using Firefox as a browser.  I don't visit pr0n, wArEz, HaXOrZ, nor \"Free Giveaway!!!!!!\" websites, have an enterprise-grade firewall and matching router protecting all of my TCP/IP devices at my home (important when even your light switches and air conditioning understands TCP/IP) and don't have any of the problems others experience. </p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1716597, 'FLConsumer')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-1717377\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=66152\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=66152\">endless</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1717377\"><abbr class=\"published\" title=\"2007-06-22T16:46:02-05:00\">June 22, 2007  4:46 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1717377);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1717377');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>yeah jeff, I am agreeing with weaver here. there have been and will be plenty of exploits for OSX. It at best is marginially more secure than windows for technical reasons.</p><p>the only real advantage it has is that it has a small user base and is therefore not a good target.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1717377, 'endless')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment last\" id=\"comment-1724680\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=7332\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=7332\">Alan Thomas</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2007/06/reader-shares-personal-financial-security-protocols.html#comment-1724680\"><abbr class=\"published\" title=\"2007-06-24T03:08:44-05:00\">June 24, 2007  3:08 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(1724680);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=1724680');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>As an infosecurity analyst with a major financial institution, I *have* encountered evidence of Trojan software on a Mac.</p><p>That experience notwithstanding, I have a good deal of confidence in the Mac, but I also have high hopes for Vista (unless dimwits disable UAC on their systems).</p><p>The majority of people who end up infected with banking Trojans are grossly negligent (not using up-to-date antivirus or neglecting to update their computers).</p><p>The bottom line is: You can do everything right, and still get screwed. As malware evolves, traditional antivirus will be increasingly ineffective against it.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(1724680, 'Alan Thomas')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>");


