Since I was main subject of the interview, I believe I misspoke during the call. Indeed XSS (to my knowledge) played no part in the Citibank story. I meant to say PayPal. I already contacted the writer with the correction and reference.
And the mistake is already fixed. Ain't the interweb great that way?
I'm not going to be at Black Hat, but I'm looking forward to reading the presentation.
Regards, Brian