<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mobile Security &#187; iban</title>
	<atom:link href="https://blog.m-sec.net/tag/iban/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.m-sec.net</link>
	<description>When security is not enough</description>
	<lastBuildDate>Tue, 13 Nov 2012 20:58:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.2</generator>
		<item>
		<title>About privacy and data protection (II)</title>
		<link>https://blog.m-sec.net/2011/about-privacy-and-data-protection-ii/</link>
		<comments>https://blog.m-sec.net/2011/about-privacy-and-data-protection-ii/#comments</comments>
		<pubDate>Sat, 06 Aug 2011 22:16:05 +0000</pubDate>
		<dc:creator>m-sec.net</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[bank]]></category>
		<category><![CDATA[CNP]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[iban]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[SSN]]></category>

		<guid isPermaLink="false">http://blog.m-sec.net/?p=37</guid>
		<description><![CDATA[As stated in my previous post, there are other legal ways you can find some special private data about someone else. 1. You call yourself &#8220;Carrefour&#8220;, you put up a marketing campaign and ask your customers to fill in a form where one of the fields is the Numerical Personal Code. Of course, you are [...]]]></description>
			<content:encoded><![CDATA[<p>As stated in my previous post, there are other legal ways you can find some special private data about someone else.</p>
<p>1. You call yourself &#8220;<em>Carrefour</em>&#8220;, you put up a marketing campaign and ask your customers to fill in a form where one of the fields is the <a title="CNP Romania" href="http://en.wikipedia.org/wiki/Romanian_identity_card" target="_blank">Numerical Personal Code</a>. Of course, you are not registered as a company who deals with private data (according to <a title="Data protection Romania" href="http://www.dataprotection.ro/" target="_blank">ANSPDCP</a>&#8216;s website). There are a lot of people out there that give their personal information just to get 10$.  I really wonder if it was to give their credit card info and PIN, would they really give it?</p>
<p>2. What about if you are <em>a bank</em>? Or a customer of a bank? Theoretically your private details like bank account, <a title="Romanian CNP" href="http://en.wikipedia.org/wiki/Romanian_identity_card" target="_blank">CNP</a>, address, etc should be safe. Well&#8230;that&#8217;s the theory. There is one bank out there (you&#8217;ll discover the name below) that allows you to find protected info about any of its customers. Let&#8217;s say you have an i-banking account with them and you get the <a title="IBAN details" href="http://en.wikipedia.org/wiki/International_Bank_Account_Number" target="_blank">IBAN</a> account of one of their customers. As soon as you try to make a money transfer to that person, you will get that person&#8217;s name. What&#8217;s wrong with that you will say. Well, you can just play around with the IBAN account and discover other valid accounts along with the holder&#8217;s name. Ok, I agree, maybe that&#8217;s not a serious security problem. Once you continue with the money transfer, you can see more: in the details of the transfer <strong>you also get the CNP of that someone</strong>. And yes, the bank is registered as a private company who deals with confidential data and obeys the law. Right!</p>
<p>See a demo for yourself. I have blurred some details, but that&#8217;s the only edit on the video.<br />
<iframe src="http://player.vimeo.com/video/27367161?title=0&amp;byline=0&amp;portrait=0" frameborder="0" width="500" height="400"></iframe></p>
<div id="tweetbutton37" class="tw_button" style=""><a href="http://twitter.com/share?url=https%3A%2F%2Fblog.m-sec.net%2F2011%2Fabout-privacy-and-data-protection-ii%2F&amp;via=msecnet&amp;text=About%20privacy%20and%20data%20protection%20%28II%29&amp;related=&amp;lang=en&amp;count=horizontal&amp;counturl=https%3A%2F%2Fblog.m-sec.net%2F2011%2Fabout-privacy-and-data-protection-ii%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('https://blog.m-sec.net/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;">Tweet</a></div>]]></content:encoded>
			<wfw:commentRss>https://blog.m-sec.net/2011/about-privacy-and-data-protection-ii/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
