Live data from Hacker News

Tesco Bank halts online payments after money was taken from 20K accounts

bbc.co.uk

91–100 of 174 posts

Re: Tesco Bank halts online payments after money was taken from 20K accounts

#91
post #60
post #42

Earlier quoted context omitted.

3% minus inflation of 0.6% that would be 2.4% of £3000, which is £72 a year, which gives £6 a month. Is it worth the hassle?

With Brexit uncertainty the current GBP inflation is over 20%. 3% is a drop in an ocean on that.

If the UK is in as much trouble as the naysayers seem to think, that 3% counts for more than ever, since cash will be tight.

Re: Tesco Bank halts online payments after money was taken from 20K accounts

#92
post #78
post #72

Earlier quoted context omitted.

This is pretty standard for UK banks. They'd do a hash of each character of the password (in Lloyds' case, your "memorable word" combo), to compare your entries to.

Wait, that's still awful! It allows you to crack each character individually. For instance, a 10-letter password requires 26^10 ~= 1.4e14 attempts to test every option if you only have a hash of the full password, but only 10*26 = 260 attempts to test every option for every individual character.

I have to use two passwords to login to Lloyds bank. One conventional password (which is presumably stored salted and hashed) and one where I have to enter characters from three positions they choose. The latter is intended to mitigate the risk of using your account from a vulnerable computer. The former takes care of vulnerabilities on their end (as far as any password can).

Re: Tesco Bank halts online payments after money was taken from 20K accounts

#93
post #48

Earlier quoted context omitted.

I don't understand why you're subtracting inflation. Yes I know doing so gives you the 'real terms' increase in value, but if you stuff £3,000 in a mattress and pull it out after a year you don't notionally add inflation to it's value when comparing it to the value of savings. The savings in that account would still be 3% more than your mattress money, not 2.4% more. Unless you're comparing it to spending all the mon…

He's probably subtracting inflation to make the interest rate of Tesco relative to the rest of the economy. Stuffing money in a mattress is a pretty poor idea when it should be very easy to find an investment scheme that covers inflation.

When you're storing small sums of money (less than 10k €/$), the amount you lose from inflation from stuffing money in a mattress over a year is negligible.

Re: Tesco Bank halts online payments after money was taken from 20K accounts

#94
post #64

it seems to be money transferred from accounts (£600 mentioned as an amount). But to set up 20,000 new transfers, and extract money from them, without 2FA, and without tripping any number of alarms is a terrible failure in security. This will massively affect their provider fiserv, their internal team will almost certainly have to be replaced and I would be surprised if they don't throw their hands up and go back to…

> Gov will enforce GPG level encryption for every bank interaction - 2FA with Time based OTP for example I don't think that's going to happen just yet. UK bank regulation is famously light touch and the government is extremely preoccupied at the moment. (The loss applies to the bank, not the customers, so they've got plenty of incentive to fix this. And it's quite possible it's a backend hack from the sound of some o…

What's surprised me in moving to the US from the UK is just how effective the light touch approach has been for the UK from a consumer perspective. In effect, banks are told to get in a room and ensure they're not worlds apart technically. The outcome of that has been Faster Payments and the SMS transfers that followed it, and soon a read and write open banking API.

In the US I still get charged for withdrawing from my Wells account at a Chase ATM.

Re: Tesco Bank halts online payments after money was taken from 20K accounts

#95
post #40

Earlier quoted context omitted.

I don't think this is at all true. Customers at just about every bank are hit by fraud, a lot of it through no fault of the customer, and yet banks don't seem to spend much time tracking down the criminals. It must be far cheaper for the banks to reimburse customers rather than to patch all the security weaknesses of their financial systems. This strongly suggests that the reputational cost of hacking and fraud just…

> banks don't seem to spend much time tracking down the criminals I am curious how you come to this conclusion, given that banks are extremely reticent to discuss what security measure they take and to avoid any publicity about security breaches (even publicity about how they caught someone brings the problem back to the public's mind). So if they WERE being effective in tracking down the criminals, how would you kno…

There are plenty of reports of people who, after getting refunded for a fraudulent transaction, get told that the bank won't investigate it, and that they should report it to the police themselves if they want to get someone to investigate. That doesn't strike me as banks caring too much.

I'm not saying the banks care nothing for security, and I am sure that they don't want to lose money if they had a choice, but their actions often give an outward impression of not being too bothered about individual losses.

Re: Tesco Bank halts online payments after money was taken from 20K accounts

#96
post #2

I wonder what the security flaw was? It is interesting that all the customers are still allowed to use their cards for cash withdrawals and payments, and they can all still log in to their online accounts. There doesn't seem to be any mention of a system-wide password reset. So... it sounds like there wasn't a widespread theft of account credentials, and that the attack was some kind of weakness in the bank's online…

Disclaimer : I don't use Tesco Bank so this is just speculation and some observations. The types of 2FA vary dramatically between banks. Some use an SMS OTP but as we know phone numbers aren't secure [0]. Most use a card reader but they often do this differently. Some use the 'identify' function to log on and the 'sign' function for payments (as designed) but others use the 'respond' function for everything. The dang…

Welp, just because you get to have Verizon give up your phone number because someone asked nicely doesn't mean it is universally a bad idea

Hell, I can't even get authenticated with my provider half the time because the simcard comes with it's ID/PIN/password that is printed on your contract. You need that to do any changes on your account.

I personally think cell phones can be made secure enough and are the most convenient. If somebody really wants to fuck with you, they will anyway, for most people there is not much point to it anyway

Re: Tesco Bank halts online payments after money was taken from 20K accounts

#97
post #74

Earlier quoted context omitted.

Right, but until that insurance pays out you're maybe faced with a bill you cannot pay in the meantime.

I'm sure the creditors would be lenient if you can prove this incident complicated things for you.

Can't tell if this is sarcasm.

Then again, maybe I am overly cynical. UK utilities at least do seem to have a more positive approach towards people struggling to pay than other countries.

Re: Tesco Bank halts online payments after money was taken from 20K accounts

#98

Earlier quoted context omitted.

OK while I am a big fan of multiple bank accounts (I have three, all for different purposes) this advice is total overkill and inappropriate for anyone who isn't financially stable, which unfortunately, is half of Americans. Two different countries? No thanks, I'm not screwing with that nightmare. I'd like to keep my money in the form of US dollars, I have no need for foreign currency and I don't want to waste money…

Perhaps the suggestion was made from an European standpoint? Two accounts in Euros within the SEPA area [1] means no costs for currency conversions or bank transfers between your accounts. [1] https://en.wikipedia.org/wiki/Single_Euro_Payments_Area

Even so, the vast, vast majority of Europeans have income and expenses in a single currency, in a single country.

If they don't, then within the Eurozone they still don't necessarily need two accounts. It might be convenient, if it enables using local systems to pay utility bills on two properties, for example.

If currencies are being changed, SEPA doesn't help.

Re: Tesco Bank halts online payments after money was taken from 20K accounts

#99
post #43
post #35

Earlier quoted context omitted.

> ideally in at least two different countries Is it generally easy to open accounts in countries you are not resident in?

Yes. You can open a bank account in Estonia online, without ever going to that country. https://1office.co/estonia/blog/opening-estonian-bank-accoun...

You actually mean no -- Estonia making it easier is exceptional, and only happened in June.

For example, I considered opening this Tesco account, since I need to keep about £1500 in my British account for student loan payments. Tesco offer 3% interest on the balance, but I should have opened the account before I emigrated.

Re: Tesco Bank halts online payments after money was taken from 20K accounts

#100
post #92
post #78

Earlier quoted context omitted.

Wait, that's still awful! It allows you to crack each character individually. For instance, a 10-letter password requires 26^10 ~= 1.4e14 attempts to test every option if you only have a hash of the full password, but only 10*26 = 260 attempts to test every option for every individual character.

I have to use two passwords to login to Lloyds bank. One conventional password (which is presumably stored salted and hashed) and one where I have to enter characters from three positions they choose. The latter is intended to mitigate the risk of using your account from a vulnerable computer. The former takes care of vulnerabilities on their end (as far as any password can).

Could they implement something like:

Password: money

Secret word: ABCD

If they're going to ask for two characters from the secret word, they could then hash

  saltmoneyAB
  saltmoneyAC
  saltmoneyAD
  saltmoneyBC
  saltmoneyBD
  saltmoneyCD
and check against the relevant one.
Post reply on HN