Live data from Hacker News

Ask HN: A major USA bank is storing passwords in cleartext – what to do?

news.ycombinator.com

181–190 of 328 posts

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#181

As someone who works in finance/banking, I can assure you that this is not uncommon. Almost everyone is engaging in not-so-best practices with password storage if they are using any 3rd party vendors. Only the institutions with the resources to rebuild in-house systems with modern security standards are the exception to this rule. There are only a handful of these. Ultimately, it's not some malicious intent or incomp…

>These assets are already implicitly protected by a massive apparatus extending as far as Ohio Class nuclear submarines patrolling the Pacific ocean.

A lot of good they will do you when a clever hacker from an unknown country logs in to your account, takes some money, and disappears untraceably because the bank's poor IT practices didn't involve enough logging! The bank might not even realize they need to call the FBI. The only practical security solution is to stop the money from being stolen in the first place: law enforcement rarely recovers all of the stolen assets.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#182

Earlier quoted context omitted.

See https://news.ycombinator.com/item?id=22356101

Unfortunately, they are still non-committal on what is required. They advise that passwords should be hashed, but there is nothing that makes that a binding requirement. The gist is still "do what you think is appropriate". The ICO talks about balancing risks and convenience, and the banks will argue that their systems are secure overall, and don't make the consumer liable anyway. Under the ICO's guidance, an organis…

Are you sure? What about the fines they're already giving? https://news.ycombinator.com/item?id=18531588

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#184
post #123

Earlier quoted context omitted.

> Your security as a bank customer hinges on more than just one password, it's also about monitoring patterns of behavior, being aware of what's coming and going from your account, and protection mechanisms like the bank's insurance. Some banks do this better than others from past experience. For example, I definitely have Bank of America notify me when I do something out of the ordinary. I had gone to a gas station…

> I definitely have Bank of America notify me when I do something out of the ordinary. -And such routines are incredibly efficient; while commissioning one of our deliveries (heavy engineering equipment) in Namibia a few years ago, I found that the local power electronics distributor hadn't heard of my employer, and were (reasonably so) reluctant to hand over parts for $13,000 or so and send an invoice to Norway. VIS…

USAA will just decline first and ask questions later. (I'm not saying this is a good thing; it sucks as a customer.)

I tried to order from a German e-retailer with my USAA card. First time, rejected; I got a text asking if it was me. I replied "YES". Second time, rejected again, got another text... I had to use another (Chase?) card eventually. Still got a text, but this one was prompt and I was able to respond before the transaction was rejected.

These are all automated; no CS rep is sending these texts (or rejections) by hand.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#185
My bank just changed from a 6-number password (literally no option for more or less characters nor anything but digits) to rational passwords this month. I don't know how my WoW account 10 years ago needed an authenticator but the people managing my retirement savings didn't light a fire under asses to get that done.

Legislation should have and likely still should be put in place.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#186

Earlier quoted context omitted.

So they can add columns for 2FA but strengthened password storage is not doable? This was forgivable 30 years ago. It was bad practice 20 years ago. Someone could have demonstrated leadership and developed a ten year plan to fix their legacy problem then.

> developed a ten year plan to fix their legacy problem then They did. And Pi factor came in. And budget was cut because those pesky fintech are a threat, and clearly money was better spent on a more modern offer than on those "security" concerns. And yes, it's possible to add 2FA to the front layer. However, the remnants of COBOL code running on the mainframe for the last 25 years weren't designed to handle password…

That COBOL layer that underlies almost all of our infrastructure.

It was written when the cost/benefit calculation of writing it involved "downsizing" thousands of clerks who were doing the job manually.

It can't be replaced because the cost/benefit calculation of replacing it does not involve anything like those kinds of numbers. The benefits of avoiding even a major security incident just don't compare to the costs.

Y2K taught me this. Nothing has changed since.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#187

As someone who works in finance/banking, I can assure you that this is not uncommon. Almost everyone is engaging in not-so-best practices with password storage if they are using any 3rd party vendors. Only the institutions with the resources to rebuild in-house systems with modern security standards are the exception to this rule. There are only a handful of these. Ultimately, it's not some malicious intent or incomp…

> These banks' IT systems are storing things that many of us would argue are much more valuable than your passwords. A bank's core system also represents the actual monetary value of every customer's account. We are talking about password security in a system domain where there are arguably far more valuable assets to secure.

The password is what secures the more valuable things inside the account (the money). In fact, in nearly every case a password is used, no one really cares much about the password itself, but what's inside. That's why services require password in the first place.

EDIT: Also, don't be so sure that passwords are not useful. If you can compromise a password in one service, there is a significant chance that the user in question is re-using the same password on other (or all?) services. If your password is "joe123" on somewebsite.com, if I can crack that, I can try to use that information to guess your login on somebank.com, somedoctor.com and somegovernmentservice.gov. The more things become "cloud"-based, the higher the value of cracking a password.

I think the bigger consideration is actually how to exfiltrate money from an account that you compromise: If you initiate a wire transfer to some account you control, that leaves a paper trail, and typically has a lag time, during which the institution/customer have a chance to react. This is also why scam centers in India ask you to send them cash equivalents: gift card codes they can redeem/resell.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#188

One bank that has astoundingly bad password requirements is Westpac Australia. Usernames are an 8 digit customer ID, and passwords have to be exactly 6 characters long(!) consisting only of numbers and uppercase letters. Try it for yourself, note that the login form only allows you to enter 8 characters for the username and 6 characters for the password: https://banking.westpac.com.au/ I complained to them about this…

Expect this to keep happening until we put the full and entire cost of identify theft onto the companies who are defrauded by the thief.

It's not identity theft, it's just fraud. Calling it identity theft is an attempt to put the cost and responsibility for ordinary fraud on the victims.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#189
post #128

Name and shame. I'll start: American Express passwords are not case sensitive. It is possible that they UPPER(...) the password before hashing it and then compare against that when you log in. This explanation would only be a little dumb because it reduces the domain of the password space. It also strains credulity.

Lol it's been that way for at least 20 years. Same with chase (well at least the bank one half of it). It seems remarkably stupid, but it's way cheaper for them to refund any losses and/or pay for lifetime credit monitoring than it is to deal with customer service calls from people getting locked out because they can't figure out how to deal with uppercase and lowercase letters.

It's funny that my small-ish credit union is not only more technologically advanced, but also way more ethical (looking at you, Wells Fargo) and convenient, and has top notch customer service. Seriously, I've never interacted with more pleasant customer service reps than my CU.

Why are people giving their money to big banks again? Is it just advertising pressure?

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#190
post #93

One bank that has astoundingly bad password requirements is Westpac Australia. Usernames are an 8 digit customer ID, and passwords have to be exactly 6 characters long(!) consisting only of numbers and uppercase letters. Try it for yourself, note that the login form only allows you to enter 8 characters for the username and 6 characters for the password: https://banking.westpac.com.au/ I complained to them about this…

A company that my retirement plan used to be with was worse than that. The password could only be numbers and letters, and they would silently truncate your password to 8 characters. The worst part though, is the password was stored in a way that it could be entered on a touch tone phone. So case was silently ignored for letters, and the characters "2abcABC" were all stored as the number 2, and so on for the rest of…

Oh, I see you've had a Fidelity account too.
Post reply on HN