<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: CIBC Introduces an iPhone Banking App</title>
	<atom:link href="http://www.sync-blog.com/sync/2010/02/cibc-introduces-an-iphone-banking-app.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.sync-blog.com/sync/2010/02/cibc-introduces-an-iphone-banking-app.html</link>
	<description></description>
	<lastBuildDate>Thu, 09 Feb 2012 11:01:58 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Bradley</title>
		<link>http://www.sync-blog.com/sync/2010/02/cibc-introduces-an-iphone-banking-app.html/comment-page-1#comment-38940</link>
		<dc:creator>Bradley</dc:creator>
		<pubDate>Tue, 12 Oct 2010 02:50:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.sync-blog.com/?p=7051#comment-38940</guid>
		<description>There is never a guarantee of online security. No matter what the bank promises.</description>
		<content:encoded><![CDATA[<p>There is never a guarantee of online security. No matter what the bank promises.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeremy Phan</title>
		<link>http://www.sync-blog.com/sync/2010/02/cibc-introduces-an-iphone-banking-app.html/comment-page-1#comment-26731</link>
		<dc:creator>Jeremy Phan</dc:creator>
		<pubDate>Tue, 09 Feb 2010 16:33:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.sync-blog.com/?p=7051#comment-26731</guid>
		<description>Worse comes to worst, just don&#039;t save your info. It&#039;s a hassle to input, but using the .mobi site, you&#039;re only allowed to save your Convenience Card # and not the password. If your browser has a password manager, that&#039;s separate and encrypted.

Lastly, physical security is key. i.e. don&#039;t lose it. Apple has the MobileMe appliccation and there are tons of stories of people recovering and even assisting police catch the thieves of their iPhones. My Xperia locks automatically after 10m of idle and deletes all the data after 3 wrong attempts.</description>
		<content:encoded><![CDATA[<p>Worse comes to worst, just don&#8217;t save your info. It&#8217;s a hassle to input, but using the .mobi site, you&#8217;re only allowed to save your Convenience Card # and not the password. If your browser has a password manager, that&#8217;s separate and encrypted.</p>
<p>Lastly, physical security is key. i.e. don&#8217;t lose it. Apple has the MobileMe appliccation and there are tons of stories of people recovering and even assisting police catch the thieves of their iPhones. My Xperia locks automatically after 10m of idle and deletes all the data after 3 wrong attempts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frank</title>
		<link>http://www.sync-blog.com/sync/2010/02/cibc-introduces-an-iphone-banking-app.html/comment-page-1#comment-26729</link>
		<dc:creator>Frank</dc:creator>
		<pubDate>Tue, 09 Feb 2010 16:24:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.sync-blog.com/?p=7051#comment-26729</guid>
		<description>Hi Jeremy,

Thanks for the comments.  I&#039;ll just have to wait for the details of the application before trying it out.  I am interested in using it. It would be very convenient.  I just want to check it out before I do. 

I imagine that there will be other similar type of apps coming out in the near future for various purposes.  Here&#039;s hoping that security best practices are built into their designs.

Thanks,

Frank</description>
		<content:encoded><![CDATA[<p>Hi Jeremy,</p>
<p>Thanks for the comments.  I&#8217;ll just have to wait for the details of the application before trying it out.  I am interested in using it. It would be very convenient.  I just want to check it out before I do. </p>
<p>I imagine that there will be other similar type of apps coming out in the near future for various purposes.  Here&#8217;s hoping that security best practices are built into their designs.</p>
<p>Thanks,</p>
<p>Frank</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeremy Phan</title>
		<link>http://www.sync-blog.com/sync/2010/02/cibc-introduces-an-iphone-banking-app.html/comment-page-1#comment-26703</link>
		<dc:creator>Jeremy Phan</dc:creator>
		<pubDate>Tue, 09 Feb 2010 00:26:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.sync-blog.com/?p=7051#comment-26703</guid>
		<description>I would hope if it&#039;s stored locally that it&#039;s encrypted. There are a multitude of password storage programs on the various smartphone platforms (BlackBerry&#039;s Password Keeper, Windows Mobile SplashData, etc.) and they&#039;re all encrypted.

It would be _really_ stupid to store it in plaintext. Another method would be to use something like a one-way hash (e.g. MD5) and store &amp; transmit that string instead of the actual password. (How most online forums, content management systems, etc. store their information in their databases: each time a user logs in, the submitted password is sent through the hash and the resulting string [which can&#039;t be decrypted back to plaintext] is compared to the one stored on the server.)</description>
		<content:encoded><![CDATA[<p>I would hope if it&#8217;s stored locally that it&#8217;s encrypted. There are a multitude of password storage programs on the various smartphone platforms (BlackBerry&#8217;s Password Keeper, Windows Mobile SplashData, etc.) and they&#8217;re all encrypted.</p>
<p>It would be _really_ stupid to store it in plaintext. Another method would be to use something like a one-way hash (e.g. MD5) and store &#038; transmit that string instead of the actual password. (How most online forums, content management systems, etc. store their information in their databases: each time a user logs in, the submitted password is sent through the hash and the resulting string [which can't be decrypted back to plaintext] is compared to the one stored on the server.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frank</title>
		<link>http://www.sync-blog.com/sync/2010/02/cibc-introduces-an-iphone-banking-app.html/comment-page-1#comment-26688</link>
		<dc:creator>Frank</dc:creator>
		<pubDate>Mon, 08 Feb 2010 23:26:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.sync-blog.com/?p=7051#comment-26688</guid>
		<description>http://www.h-online.com/security/news/item/iPhone-OS-3-1-3-fixes-vulnerabilities-920756.html

&quot;...Other vulnerabilities include a possible disclosure of information issue that could allow a person with physical access to a locked device to bypass the lock screen and gain access to a user&#039;s data...&quot;</description>
		<content:encoded><![CDATA[<p><a href="http://www.h-online.com/security/news/item/iPhone-OS-3-1-3-fixes-vulnerabilities-920756.html" rel="nofollow">http://www.h-online.com/security/news/item/iPhone-OS-3-1-3-fixes-vulnerabilities-920756.html</a></p>
<p>&#8220;&#8230;Other vulnerabilities include a possible disclosure of information issue that could allow a person with physical access to a locked device to bypass the lock screen and gain access to a user&#8217;s data&#8230;&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frank</title>
		<link>http://www.sync-blog.com/sync/2010/02/cibc-introduces-an-iphone-banking-app.html/comment-page-1#comment-26685</link>
		<dc:creator>Frank</dc:creator>
		<pubDate>Mon, 08 Feb 2010 23:18:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.sync-blog.com/?p=7051#comment-26685</guid>
		<description>What I am wondering is how the application itself makes use of the userid and password.  Yes, https will encrypt the conversation between the device and the server, but are the userid and password stored locally on the hand held device itself?  

If the userid/password are stored on the iPhone, it is possible that someone could hack the iphone and extract that information.  Recently, a vulnerability has been reported (and patched) where information could be extracted from a locked iphone.  The iphone needs to be physically accessed though.  So losing your iphone would could put it into the hands of someone capable of hacking into it.  To mitigate this risk, any userid/passwords stored on an iphone should be encrypted locally as well.

Hopefully CIBC has implemented the application correctly so that it does not store any userid/password locally or if it does store it locally, it is not stored in plain text.</description>
		<content:encoded><![CDATA[<p>What I am wondering is how the application itself makes use of the userid and password.  Yes, https will encrypt the conversation between the device and the server, but are the userid and password stored locally on the hand held device itself?  </p>
<p>If the userid/password are stored on the iPhone, it is possible that someone could hack the iphone and extract that information.  Recently, a vulnerability has been reported (and patched) where information could be extracted from a locked iphone.  The iphone needs to be physically accessed though.  So losing your iphone would could put it into the hands of someone capable of hacking into it.  To mitigate this risk, any userid/passwords stored on an iphone should be encrypted locally as well.</p>
<p>Hopefully CIBC has implemented the application correctly so that it does not store any userid/password locally or if it does store it locally, it is not stored in plain text.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeremy Phan</title>
		<link>http://www.sync-blog.com/sync/2010/02/cibc-introduces-an-iphone-banking-app.html/comment-page-1#comment-26646</link>
		<dc:creator>Jeremy Phan</dc:creator>
		<pubDate>Sat, 06 Feb 2010 21:32:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.sync-blog.com/?p=7051#comment-26646</guid>
		<description>Online banking is secure. All traffic is encrypted.

In a regular browser, you&#039;ll see &quot;https://&quot; instead of &quot;http://&quot; indicating that it is &quot;S&quot;ecure.

CIBC, like all other banks, guarantees online security. You will not be held liable for unauthorized access to your online account (granted you haven&#039;t given out your password, etc.)

Online banking guarantees:
CIBC: http://www.cibc.com/ca/legal/online-banking-guarantee.html
BMO: http://www4.bmo.com/bmo/portal/cda/popup_template/0,2284,35649_38681369,00.html
TD: http://www.td.com/privacyandsecurity/guarantee.jsp
Royal: http://www.rbcroyalbank.com/online/rbcguarantee.html
Scotia: http://www.scotiabank.com/guarantee
VanCity: https://www.vancity.com/ContactUs/WaystoBank/OnlineBanking/</description>
		<content:encoded><![CDATA[<p>Online banking is secure. All traffic is encrypted.</p>
<p>In a regular browser, you&#8217;ll see &#8220;https://&#8221; instead of &#8220;http://&#8221; indicating that it is &#8220;S&#8221;ecure.</p>
<p>CIBC, like all other banks, guarantees online security. You will not be held liable for unauthorized access to your online account (granted you haven&#8217;t given out your password, etc.)</p>
<p>Online banking guarantees:<br />
CIBC: <a href="http://www.cibc.com/ca/legal/online-banking-guarantee.html" rel="nofollow">http://www.cibc.com/ca/legal/online-banking-guarantee.html</a><br />
BMO: <a href="http://www4.bmo.com/bmo/portal/cda/popup_template/0,2284,35649_38681369,00.html" rel="nofollow">http://www4.bmo.com/bmo/portal/cda/popup_template/0,2284,35649_38681369,00.html</a><br />
TD: <a href="http://www.td.com/privacyandsecurity/guarantee.jsp" rel="nofollow">http://www.td.com/privacyandsecurity/guarantee.jsp</a><br />
Royal: <a href="http://www.rbcroyalbank.com/online/rbcguarantee.html" rel="nofollow">http://www.rbcroyalbank.com/online/rbcguarantee.html</a><br />
Scotia: <a href="http://www.scotiabank.com/guarantee" rel="nofollow">http://www.scotiabank.com/guarantee</a><br />
VanCity: <a href="https://www.vancity.com/ContactUs/WaystoBank/OnlineBanking/" rel="nofollow">https://www.vancity.com/ContactUs/WaystoBank/OnlineBanking/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ralph</title>
		<link>http://www.sync-blog.com/sync/2010/02/cibc-introduces-an-iphone-banking-app.html/comment-page-1#comment-26645</link>
		<dc:creator>Ralph</dc:creator>
		<pubDate>Sat, 06 Feb 2010 21:14:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.sync-blog.com/?p=7051#comment-26645</guid>
		<description>Hello all, I have down loaded this app and tested it.  It works fine, just the same as logging on from my browser but more readable on my iPod touch.

A word of warning however, I am using this app behind my own router/firewall and so I am not to concerned about safety and security.  Using any financial wireless app. in the wild however has risks associated with it.</description>
		<content:encoded><![CDATA[<p>Hello all, I have down loaded this app and tested it.  It works fine, just the same as logging on from my browser but more readable on my iPod touch.</p>
<p>A word of warning however, I am using this app behind my own router/firewall and so I am not to concerned about safety and security.  Using any financial wireless app. in the wild however has risks associated with it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dat Trinh</title>
		<link>http://www.sync-blog.com/sync/2010/02/cibc-introduces-an-iphone-banking-app.html/comment-page-1#comment-26628</link>
		<dc:creator>Dat Trinh</dc:creator>
		<pubDate>Fri, 05 Feb 2010 20:58:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.sync-blog.com/?p=7051#comment-26628</guid>
		<description>I agree with Phil. With consideration of your comment regarding an increase in staff, in my opinion, it&#039;s because they charge us for all kinds of fees, and so need more staff to help manage all the money that leaked from our accounts. Just because the &quot;fee&quot; doesn&#039;t specify a particular name, doesn&#039;t mean that it&#039;s not there. Banks are so busy poking holes in our accounts, they have to create distractions to cover up all the banging noise while they&#039;re hard at work.

Hang on to your two cents tight, the bankers are lurching...!</description>
		<content:encoded><![CDATA[<p>I agree with Phil. With consideration of your comment regarding an increase in staff, in my opinion, it&#8217;s because they charge us for all kinds of fees, and so need more staff to help manage all the money that leaked from our accounts. Just because the &#8220;fee&#8221; doesn&#8217;t specify a particular name, doesn&#8217;t mean that it&#8217;s not there. Banks are so busy poking holes in our accounts, they have to create distractions to cover up all the banging noise while they&#8217;re hard at work.</p>
<p>Hang on to your two cents tight, the bankers are lurching&#8230;!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Edward Walsh</title>
		<link>http://www.sync-blog.com/sync/2010/02/cibc-introduces-an-iphone-banking-app.html/comment-page-1#comment-26624</link>
		<dc:creator>Edward Walsh</dc:creator>
		<pubDate>Fri, 05 Feb 2010 19:28:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.sync-blog.com/?p=7051#comment-26624</guid>
		<description>Thank you for  your article on CIBC Online Banking App for the iPhone.  While I do not personally bank with CIBC I am impressed by their first effort (1.0) for the iPhone App.  I have downloaded both Scotiabank and BMO since I deal with both, but their 1.0 App doesn&#039;t even come, sadly, close to the CIBC one.  For actual online banking the Scotiabank App takes you to the Safari browser whereas from the looks of it the CIBC one allows you to bank from within the App itself!  I hope that both Scotibank and BMO sit up and take note of this and release a 1.1 Version soon incorporating these ideas!

As regard to Phil&#039;s comment.  From personal experience I can only say since the banks have become more automated making it easier for people to do banking on our terms and not theirs I haven&#039;t seen a decrease in staff at our local bank (Scotiabank).  In fact, it seems just the opposite as more paperwork is generated and staff are required to keep on top of it.

Just my two cents worth........</description>
		<content:encoded><![CDATA[<p>Thank you for  your article on CIBC Online Banking App for the iPhone.  While I do not personally bank with CIBC I am impressed by their first effort (1.0) for the iPhone App.  I have downloaded both Scotiabank and BMO since I deal with both, but their 1.0 App doesn&#8217;t even come, sadly, close to the CIBC one.  For actual online banking the Scotiabank App takes you to the Safari browser whereas from the looks of it the CIBC one allows you to bank from within the App itself!  I hope that both Scotibank and BMO sit up and take note of this and release a 1.1 Version soon incorporating these ideas!</p>
<p>As regard to Phil&#8217;s comment.  From personal experience I can only say since the banks have become more automated making it easier for people to do banking on our terms and not theirs I haven&#8217;t seen a decrease in staff at our local bank (Scotiabank).  In fact, it seems just the opposite as more paperwork is generated and staff are required to keep on top of it.</p>
<p>Just my two cents worth&#8230;&#8230;..</p>
]]></content:encoded>
	</item>
</channel>
</rss>

