<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.4" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: TreasuryDirect refuses to confirm transactions</title>
	<link>http://www.savings-bond-advisor.com/treasurydirect-refuses-to-confirm-transactions/</link>
	<description></description>
	<pubDate>Fri, 29 Aug 2008 20:59:12 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.4</generator>

	<item>
		<title>by: TreasuryDirect enhances security features: US Savings Bonds</title>
		<link>http://www.savings-bond-advisor.com/treasurydirect-refuses-to-confirm-transactions/#comment-704</link>
		<pubDate>Fri, 11 Aug 2006 16:36:12 +0000</pubDate>
		<guid>http://www.savings-bond-advisor.com/treasurydirect-refuses-to-confirm-transactions/#comment-704</guid>
					<description>There's a follow-up to this article today at &lt;a href="http://www.savings-bond-advisor.com/treasurydirect-enhances-security-features/" rel="nofollow"&gt;TreasuryDirect enhances security features&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>There's a follow-up to this article today at <a href="http://www.savings-bond-advisor.com/treasurydirect-enhances-security-features/" rel="nofollow">TreasuryDirect enhances security features</a>
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Wall Street Journal questions TreasuryDirect security: US Savings Bonds</title>
		<link>http://www.savings-bond-advisor.com/treasurydirect-refuses-to-confirm-transactions/#comment-522</link>
		<pubDate>Mon, 10 Jul 2006 18:53:07 +0000</pubDate>
		<guid>http://www.savings-bond-advisor.com/treasurydirect-refuses-to-confirm-transactions/#comment-522</guid>
					<description>[...] The article refers to our March 18 article TreasuryDirect refuses to confirm transactions., as well as discussions on Morningstar.com forums. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] The article refers to our March 18 article TreasuryDirect refuses to confirm transactions., as well as discussions on Morningstar.com forums. [&#8230;]
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: tom</title>
		<link>http://www.savings-bond-advisor.com/treasurydirect-refuses-to-confirm-transactions/#comment-493</link>
		<pubDate>Fri, 30 Jun 2006 22:40:42 +0000</pubDate>
		<guid>http://www.savings-bond-advisor.com/treasurydirect-refuses-to-confirm-transactions/#comment-493</guid>
					<description>Has anyone tried changing the bank info to a account that is not yours (like a family member) to see if they will flag it as an error?

Also, if a burglar got your password, he will change your email so you wont get a warning.  He'll  also change the password so you cant get in.</description>
		<content:encoded><![CDATA[<p>Has anyone tried changing the bank info to a account that is not yours (like a family member) to see if they will flag it as an error?</p>
<p>Also, if a burglar got your password, he will change your email so you wont get a warning.  He'll  also change the password so you cant get in.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Tom Adams</title>
		<link>http://www.savings-bond-advisor.com/treasurydirect-refuses-to-confirm-transactions/#comment-261</link>
		<pubDate>Wed, 05 Apr 2006 22:58:01 +0000</pubDate>
		<guid>http://www.savings-bond-advisor.com/treasurydirect-refuses-to-confirm-transactions/#comment-261</guid>
					<description>Followup - After further thought, it seems to me that doing things randomly can be a valid security procedure in that it prevents attackers from knowing what response to expect. Random responses can increase security and lower risk for the Treasury.

However, the Treasury puts all the risk of a password attack on the investor and takes none itself anyhow. From the investor's point of view, password security is increased and risk is reduced by at least having the option to receive notification of any changes to the account.

The people running TreasuryDirect want it to be the best possible system. They're making continuous improvements. Hearing the customer viewpoint is helpful to them.</description>
		<content:encoded><![CDATA[<p>Followup - After further thought, it seems to me that doing things randomly can be a valid security procedure in that it prevents attackers from knowing what response to expect. Random responses can increase security and lower risk for the Treasury.</p>
<p>However, the Treasury puts all the risk of a password attack on the investor and takes none itself anyhow. From the investor's point of view, password security is increased and risk is reduced by at least having the option to receive notification of any changes to the account.</p>
<p>The people running TreasuryDirect want it to be the best possible system. They're making continuous improvements. Hearing the customer viewpoint is helpful to them.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Tom Adams</title>
		<link>http://www.savings-bond-advisor.com/treasurydirect-refuses-to-confirm-transactions/#comment-240</link>
		<pubDate>Tue, 28 Mar 2006 22:05:40 +0000</pubDate>
		<guid>http://www.savings-bond-advisor.com/treasurydirect-refuses-to-confirm-transactions/#comment-240</guid>
					<description>Followup - as a test, I recently changed my own email address on TreasuryDirect. I did not receive an email confirmation.

The same day I used the &lt;i&gt;Contact Us&lt;/i&gt; button within TreasuryDirect to ask whether confirmations are sent for a variety of transactions types. The answer I received was:

&lt;i&gt;To verify that the TreasuryDirect account holder made the changes E-mails are sent for randomly selected accounts that have had information changes.&lt;/i&gt;

Security by random selection? That's one I've never heard of before.</description>
		<content:encoded><![CDATA[<p>Followup - as a test, I recently changed my own email address on TreasuryDirect. I did not receive an email confirmation.</p>
<p>The same day I used the <i>Contact Us</i> button within TreasuryDirect to ask whether confirmations are sent for a variety of transactions types. The answer I received was:</p>
<p><i>To verify that the TreasuryDirect account holder made the changes E-mails are sent for randomly selected accounts that have had information changes.</i></p>
<p>Security by random selection? That's one I've never heard of before.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Tom Adams</title>
		<link>http://www.savings-bond-advisor.com/treasurydirect-refuses-to-confirm-transactions/#comment-227</link>
		<pubDate>Sat, 18 Mar 2006 02:24:45 +0000</pubDate>
		<guid>http://www.savings-bond-advisor.com/treasurydirect-refuses-to-confirm-transactions/#comment-227</guid>
					<description>NOYB and Dan - I'm really happy to hear that TreasuryDirect has started confirming bank account changes by email. My information was based on prior experience. 

However, I did ask the Savings Bonds public relations team about this issue a few days before publishing this information but I guess they didn't know it had already been fixed.

Mario - I don't know about Legacy Treasury Direct but I'll see what I can find out.</description>
		<content:encoded><![CDATA[<p>NOYB and Dan - I'm really happy to hear that TreasuryDirect has started confirming bank account changes by email. My information was based on prior experience. </p>
<p>However, I did ask the Savings Bonds public relations team about this issue a few days before publishing this information but I guess they didn't know it had already been fixed.</p>
<p>Mario - I don't know about Legacy Treasury Direct but I'll see what I can find out.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
