<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: 1.6 million records stolen from monster.com</title>
	<atom:link href="http://www.cheezhead.com/2007/08/20/monster-trojan-horse/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cheezhead.com/2007/08/20/monster-trojan-horse/</link>
	<description>Insight and opinion from the world of employment.</description>
	<lastBuildDate>Fri, 13 Nov 2009 04:01:22 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: youtuber</title>
		<link>http://www.cheezhead.com/2007/08/20/monster-trojan-horse/comment-page-1/#comment-114719</link>
		<dc:creator>youtuber</dc:creator>
		<pubDate>Tue, 26 Aug 2008 12:26:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.cheezhead.com/2007/08/20/monster-trojan-horse/#comment-114719</guid>
		<description>1.6m is certainly not a small number... hope im not in there somewhere</description>
		<content:encoded><![CDATA[<p>1.6m is certainly not a small number&#8230; hope im not in there somewhere</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: naughty3232</title>
		<link>http://www.cheezhead.com/2007/08/20/monster-trojan-horse/comment-page-1/#comment-75972</link>
		<dc:creator>naughty3232</dc:creator>
		<pubDate>Fri, 11 Jan 2008 16:29:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.cheezhead.com/2007/08/20/monster-trojan-horse/#comment-75972</guid>
		<description>I get an average of 20 emails a day from Monster. Hopefully, this will be fixed</description>
		<content:encoded><![CDATA[<p>I get an average of 20 emails a day from Monster. Hopefully, this will be fixed</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fel3232</title>
		<link>http://www.cheezhead.com/2007/08/20/monster-trojan-horse/comment-page-1/#comment-58124</link>
		<dc:creator>fel3232</dc:creator>
		<pubDate>Sat, 27 Oct 2007 17:50:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.cheezhead.com/2007/08/20/monster-trojan-horse/#comment-58124</guid>
		<description>Me too, I get a lot of garbage from Monster, it&#039;s a shame.</description>
		<content:encoded><![CDATA[<p>Me too, I get a lot of garbage from Monster, it&#8217;s a shame.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Donnie</title>
		<link>http://www.cheezhead.com/2007/08/20/monster-trojan-horse/comment-page-1/#comment-47921</link>
		<dc:creator>Donnie</dc:creator>
		<pubDate>Fri, 07 Sep 2007 10:03:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.cheezhead.com/2007/08/20/monster-trojan-horse/#comment-47921</guid>
		<description>How much do you think was paid to Mr Behind-the-Scenes for this information?  How many companies have just accidently lost information, and how long are we as a society going to keep giving out our personal data to these shysters?  

These data security issues seem to be more a cash-in of customer trust than an actual incident.  They get a list of a million active names, addresses, work history, salary information, phone numbers...  they sell it to the highest bidder, download it and when the phishing starts, Monster claims SECURITY BREACH!!!!

Ya I believe it......</description>
		<content:encoded><![CDATA[<p>How much do you think was paid to Mr Behind-the-Scenes for this information?  How many companies have just accidently lost information, and how long are we as a society going to keep giving out our personal data to these shysters?  </p>
<p>These data security issues seem to be more a cash-in of customer trust than an actual incident.  They get a list of a million active names, addresses, work history, salary information, phone numbers&#8230;  they sell it to the highest bidder, download it and when the phishing starts, Monster claims SECURITY BREACH!!!!</p>
<p>Ya I believe it&#8230;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bug_girl</title>
		<link>http://www.cheezhead.com/2007/08/20/monster-trojan-horse/comment-page-1/#comment-46731</link>
		<dc:creator>bug_girl</dc:creator>
		<pubDate>Fri, 31 Aug 2007 12:56:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.cheezhead.com/2007/08/20/monster-trojan-horse/#comment-46731</guid>
		<description>I just got a disturbing notice from USAjobs, which uses monster software, that the breach extended into their website as well.

http://www.usajobs.gov/securityNotice.asp</description>
		<content:encoded><![CDATA[<p>I just got a disturbing notice from USAjobs, which uses monster software, that the breach extended into their website as well.</p>
<p><a href="http://www.usajobs.gov/securityNotice.asp" rel="nofollow">http://www.usajobs.gov/securityNotice.asp</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe Stubblebine</title>
		<link>http://www.cheezhead.com/2007/08/20/monster-trojan-horse/comment-page-1/#comment-45496</link>
		<dc:creator>Joe Stubblebine</dc:creator>
		<pubDate>Fri, 24 Aug 2007 19:02:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.cheezhead.com/2007/08/20/monster-trojan-horse/#comment-45496</guid>
		<description>This is a big problem, but it happens all the time.  There&#039;s a software tool called InfoGist that allows any recruiter to suck tens of thousands of contact records from major job boards.</description>
		<content:encoded><![CDATA[<p>This is a big problem, but it happens all the time.  There&#8217;s a software tool called InfoGist that allows any recruiter to suck tens of thousands of contact records from major job boards.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: karen m</title>
		<link>http://www.cheezhead.com/2007/08/20/monster-trojan-horse/comment-page-1/#comment-45475</link>
		<dc:creator>karen m</dc:creator>
		<pubDate>Fri, 24 Aug 2007 14:48:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.cheezhead.com/2007/08/20/monster-trojan-horse/#comment-45475</guid>
		<description>Should I ask for forgiveness for what I will say here? Nah, Shoot, there seems to be a bit of hypocrisy going on here..  Monster gets a major breach, and Wow, this is such a Controversy, YET RECRUITERS every day will utilize programs - IE Jigsaw, that has the potential for as much harm as this attack did, and -- Yet, this is what get&#039;s a raised Eyebrow?

No mention of Recruiters sending Resumes w/o permission from the Candidates to jobs that may not exist, and compromising their own efforts? No mention of Selling Data on Programs without permission from that individual? 

Ah, sorry, I guess, another Rant and Rage about this VERY topic from Karen Mattonen.. It is amazing what will stir the hornets nest, but it is my personal opinion that there is not much difference to what Some Recruiters may and will do Intentionally - compared to the breach of Monster&#039;s database.

Karen Mattonen..</description>
		<content:encoded><![CDATA[<p>Should I ask for forgiveness for what I will say here? Nah, Shoot, there seems to be a bit of hypocrisy going on here..  Monster gets a major breach, and Wow, this is such a Controversy, YET RECRUITERS every day will utilize programs &#8211; IE Jigsaw, that has the potential for as much harm as this attack did, and &#8212; Yet, this is what get&#8217;s a raised Eyebrow?</p>
<p>No mention of Recruiters sending Resumes w/o permission from the Candidates to jobs that may not exist, and compromising their own efforts? No mention of Selling Data on Programs without permission from that individual? </p>
<p>Ah, sorry, I guess, another Rant and Rage about this VERY topic from Karen Mattonen.. It is amazing what will stir the hornets nest, but it is my personal opinion that there is not much difference to what Some Recruiters may and will do Intentionally &#8211; compared to the breach of Monster&#8217;s database.</p>
<p>Karen Mattonen..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Trumpasaurus</title>
		<link>http://www.cheezhead.com/2007/08/20/monster-trojan-horse/comment-page-1/#comment-45365</link>
		<dc:creator>The Trumpasaurus</dc:creator>
		<pubDate>Thu, 23 Aug 2007 11:47:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.cheezhead.com/2007/08/20/monster-trojan-horse/#comment-45365</guid>
		<description>Masses, listen up!

I represent the International Brotherhood of Trumpasaurai (of which there are one, frequently seen at trade shows.)

I am extremely displeased with you all. You have not lain down and accepted the word of my master (monster.com) as golden.

How dare you. 

Let me set the record straight, right here, right now.

1. It is not *our* fault that we lost all of those candidate records to bad people who want to steal nice human identities. It&#039;s yours. You dumb clients better stop messing up our nice resume database by catching viruses. 

2. If my master says that he has no direct knowledge that a virus even exists, and that identity theft exists, you will listen to our repudiation of objective reality. You will accept monster-reality. 

3. Even if viruses do exist, they only downloaded information found in a phone book. That is why we charge so much money for access to the resume database. It takes many phone books to store this information. You should see master&#039;s closet. It&#039;s just shoes and phone books.

4. I had a dream last night that master couldn&#039;t tell the difference between a human downloading a resume vs. a machine (like the Monster Partner program). That would mean that all of those nice humans that designed the Monster partner program and gave it to ATSes exposed a gaping flaw in their security. Then I woke up though and forgot all about that.

4. I expect two things from my master&#039;s clients:

* Pay your invoices like good humans and don&#039;t complain about increased rates.

* Stop questionining master. You are too simple to question the mind of his greatness. 


If you would like to respond to me via human mail, I can be found at:

Office of the Trumpasaurus
Monster.com
Maynard, MA 54678
ATTN: Garbage Pile 


Sincerely,

The Trumpasaurus</description>
		<content:encoded><![CDATA[<p>Masses, listen up!</p>
<p>I represent the International Brotherhood of Trumpasaurai (of which there are one, frequently seen at trade shows.)</p>
<p>I am extremely displeased with you all. You have not lain down and accepted the word of my master (monster.com) as golden.</p>
<p>How dare you. </p>
<p>Let me set the record straight, right here, right now.</p>
<p>1. It is not *our* fault that we lost all of those candidate records to bad people who want to steal nice human identities. It&#8217;s yours. You dumb clients better stop messing up our nice resume database by catching viruses. </p>
<p>2. If my master says that he has no direct knowledge that a virus even exists, and that identity theft exists, you will listen to our repudiation of objective reality. You will accept monster-reality. </p>
<p>3. Even if viruses do exist, they only downloaded information found in a phone book. That is why we charge so much money for access to the resume database. It takes many phone books to store this information. You should see master&#8217;s closet. It&#8217;s just shoes and phone books.</p>
<p>4. I had a dream last night that master couldn&#8217;t tell the difference between a human downloading a resume vs. a machine (like the Monster Partner program). That would mean that all of those nice humans that designed the Monster partner program and gave it to ATSes exposed a gaping flaw in their security. Then I woke up though and forgot all about that.</p>
<p>4. I expect two things from my master&#8217;s clients:</p>
<p>* Pay your invoices like good humans and don&#8217;t complain about increased rates.</p>
<p>* Stop questionining master. You are too simple to question the mind of his greatness. </p>
<p>If you would like to respond to me via human mail, I can be found at:</p>
<p>Office of the Trumpasaurus<br />
Monster.com<br />
Maynard, MA 54678<br />
ATTN: Garbage Pile </p>
<p>Sincerely,</p>
<p>The Trumpasaurus</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Recruiting Fly Guy</title>
		<link>http://www.cheezhead.com/2007/08/20/monster-trojan-horse/comment-page-1/#comment-45326</link>
		<dc:creator>Recruiting Fly Guy</dc:creator>
		<pubDate>Thu, 23 Aug 2007 02:17:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.cheezhead.com/2007/08/20/monster-trojan-horse/#comment-45326</guid>
		<description>For the past few years the Monster site has reminded me more of a lead generation tool for their advertisers rather than a place for people to find jobs. This trojan horse issue can directly be attributed to the overall strategies set in place by their management. The &#039;new&#039; management is not off to a good start here. The problem in my mind still lies in the fact that their ultimate customer is the shareholder, thus their growth must come from squeezing every available dollar from the poor job seeker to maintain growth. With this model the job seeker always loses.</description>
		<content:encoded><![CDATA[<p>For the past few years the Monster site has reminded me more of a lead generation tool for their advertisers rather than a place for people to find jobs. This trojan horse issue can directly be attributed to the overall strategies set in place by their management. The &#8216;new&#8217; management is not off to a good start here. The problem in my mind still lies in the fact that their ultimate customer is the shareholder, thus their growth must come from squeezing every available dollar from the poor job seeker to maintain growth. With this model the job seeker always loses.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lean B.</title>
		<link>http://www.cheezhead.com/2007/08/20/monster-trojan-horse/comment-page-1/#comment-45312</link>
		<dc:creator>Lean B.</dc:creator>
		<pubDate>Wed, 22 Aug 2007 23:30:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.cheezhead.com/2007/08/20/monster-trojan-horse/#comment-45312</guid>
		<description>So, since Monster.com can&#039;t tell programmatic access to its site from direct access nor do they secure their own site from &quot;talking to itself&quot;, based on their responses in these articles:

http://www.pcworld.com/article/id,136154-pg,1/article.html

and here:

http://www.forbes.com/technology/2007/08/20/symantec-monster-research-tech-cx_0820darkreading.html

This compounded with the fact that their alliances program apparently further extends this lack of security to third parties (see here):

http://info.monster.com/alliances/hrvendor.asp

with no basic checks and balances is just lazy and poor management of private information.  And don&#039;t try and tell me that resume information isn&#039;t “private”... I&#039;m assured multiple times throughout the account creation process that my information is both private and secure.  

What&#039;s worse is that their &quot;security model&quot; seems to cross all their offerings including those that provide companies with their own career web sites, so are those using Monster.com for that compromised or at least at risk?  I know that our company let&#039;s those with Monster.com profiles &quot;push&quot; those into our systems and that Monster requires that you have an account on Monster before you can easily get to our jobs.

All I can say is no thanks... Lot&#039;s of sites can drive candidate traffic and at least some of them seem to care about the fact that they sit between my jobs and my potential future employees&#039; privacy.</description>
		<content:encoded><![CDATA[<p>So, since Monster.com can&#8217;t tell programmatic access to its site from direct access nor do they secure their own site from &#8220;talking to itself&#8221;, based on their responses in these articles:</p>
<p><a href="http://www.pcworld.com/article/id,136154-pg,1/article.html" rel="nofollow">http://www.pcworld.com/article/id,136154-pg,1/article.html</a></p>
<p>and here:</p>
<p><a href="http://www.forbes.com/technology/2007/08/20/symantec-monster-research-tech-cx_0820darkreading.html" rel="nofollow">http://www.forbes.com/technology/2007/08/20/symantec-monster-research-tech-cx_0820darkreading.html</a></p>
<p>This compounded with the fact that their alliances program apparently further extends this lack of security to third parties (see here):</p>
<p><a href="http://info.monster.com/alliances/hrvendor.asp" rel="nofollow">http://info.monster.com/alliances/hrvendor.asp</a></p>
<p>with no basic checks and balances is just lazy and poor management of private information.  And don&#8217;t try and tell me that resume information isn&#8217;t “private”&#8230; I&#8217;m assured multiple times throughout the account creation process that my information is both private and secure.  </p>
<p>What&#8217;s worse is that their &#8220;security model&#8221; seems to cross all their offerings including those that provide companies with their own career web sites, so are those using Monster.com for that compromised or at least at risk?  I know that our company let&#8217;s those with Monster.com profiles &#8220;push&#8221; those into our systems and that Monster requires that you have an account on Monster before you can easily get to our jobs.</p>
<p>All I can say is no thanks&#8230; Lot&#8217;s of sites can drive candidate traffic and at least some of them seem to care about the fact that they sit between my jobs and my potential future employees&#8217; privacy.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.700 seconds -->
