<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>archGFX &#187; paypal</title>
	<atom:link href="http://archgfx.net/tag/paypal/feed" rel="self" type="application/rss+xml" />
	<link>http://archgfx.net</link>
	<description>Austin web designer - Adam Freetly</description>
	<lastBuildDate>Sun, 03 May 2009 17:54:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Shame on me</title>
		<link>http://archgfx.net/blog/2007/geek/shame-on-me</link>
		<comments>http://archgfx.net/blog/2007/geek/shame-on-me#comments</comments>
		<pubDate>Mon, 12 Nov 2007 13:59:25 +0000</pubDate>
		<dc:creator>adam</dc:creator>
				<category><![CDATA[geekery]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[paypal]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://archgfx.net/blog/2007/geek/shame-on-me</guid>
		<description><![CDATA[I've been lax in my personal security. Until last week, I only had 5 or so passwords. 1 for bank-grade security sites that required a strong password, 1 for physical computers, a few old ones, and the kicker, 1 for everything on the internet. Evidently I either signed up for something not so safe, or [...]]]></description>
			<content:encoded><![CDATA[<p>I've been lax in my personal security.  Until last week, I only had 5 or so passwords.  1 for bank-grade security sites that required a strong password, 1 for physical computers, a few old ones, and the kicker, 1 for everything on the internet.  Evidently I either signed up for something not so safe, or authenticated in plain text somewhere unsafe.  Or my "everything password" wasn't that secure.</p>
<p>Either way, someone guessed, stole, or cracked their way to my paypal account, and bought a couple hundred dollars worth of shareware via SWReg.org.  The funds came from a savings account so my first warning actually came from paypal, who placed restrictions on my account after the first couple login attempts failed.</p>
<p>I called up to report the fraudulent charges, and while the woman did helpfully explain that I could have done this all without taking my fingers off the keyboard, it was a good thing.  Besides being incredibly nice to someone asking questions from the <acronym title='Frequently Asked Questions'><span class='caps'>FAQ</span></acronym>, She also gave me a little shpiel about their new security keys, and offered to send me one.  Given my love of 1) free shit 2) security (present idiocy notwithstanding) 3) gadgets, I think you can guess my answer.</p>
<p><a href="http://paypal.com/securitykey"><img src="http://archgfx.net/wp-content/uploads/2007/11/spot_ppsecuritykeyfront_240x134.gif" alt="VIP token" /></a></p>
<p>It's a <a href="http://www.verisign.com/products-services/security-services/identity-protection/index.html">VIP token</a>, a pretty badass little toy.  You push a button and it generates a 6-digit number that's good for 30 seconds or so, which you use when you sign into your paypal + ebay accounts.  Not only that, but since it's made by verisign, you can add it to your <a href="http://pip.verisignlabs.com/">PIP openID</a> as well.  Now, in addition to having changed all my internet passwords, I've got ridiculously strong security on anything that I sign into with OpenID.  I'm using it for this site with <a href="http://wordpress.org/extend/plugins/openid/">openID+</a> v2.0(<a href="http://willnorris.com/2007/11/wp-openid-20-released">released friday</a>), although the previous versions have <a href="http://archgfx.net/blog/2007/geek/blogging/thirtieth#comment-22959">been glitchy</a>.</p>
<p>Unfortunately, I still haven't finished with paypal yet.  I have a premier account, which at some point required a land line.  I no longer have a home phone, so they have to <em>physically mail me something</em>, to restore my account.  That's just for the restrictions, though. They've already refunded the fraudulent charges.</p>
]]></content:encoded>
			<wfw:commentRss>http://archgfx.net/blog/2007/geek/shame-on-me/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>
