NatWest is also guilty of storing passwords in plain text: their login page says 'enter the 5th, 8th and 12th character of your password'
HTTPS on Your Landing Page Is Important
221–230 of 307 posts
Re: HTTPS on Your Landing Page Is Important
#222It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.
Guess what! If your financial service restricts your password to letters and numbers, it's most likely because they want you to be able to enter your password on the phone. So the passwords 'abc' 'ABC' and '222' are treated as equivalent. Try it out for fun!
Re: HTTPS on Your Landing Page Is Important
#223Earlier quoted context omitted.
Microsoft's sign in is a real mess, I think in part due to having to make your hotmail login that you made 15 years ago still work, along with the dozens of other services that MS has acquired or integrated. I've had a real shitter of a time trying to login before, with redirect loops, or getting automatically signed out as soon as I sign in. Or accounts being a "games for Windows" account, but not an MS account, or…
Speaking of Microsoft's signin, I can no longer access my decade-old-held Skype since their SSO integration. I've tried over and over and over and tried every route possible. It is some edge case where the email was previously a microsoft account and the password cannot be reset. I'm not the only one with the issue. Shocking something like this doesnt get resolved for years on.
* One account required me to log in with a username, and was associated with my main email address. * The other account required me to log in with my main email address.
In a way, they were both related to the same email, but different accounts. This shouldn't even have been possible, but it seems that one was an old MS account, and the other was an old Skype account. My roster ended up being split half and half between the two.
Re: HTTPS on Your Landing Page Is Important
#224Earlier quoted context omitted.
My citibank credit card redirects me to "cardservicesdirect.com.au" -- which reads like a phishing site if I've ever seen one. I confirmed over the phone with their support that was indeed the correct site before typing anything into it.
But did you call the support phone number shown on the dodgy domain?
I said think about what you're asking for a second. Should I answer your questions? Couldn't get them to understand. Wound up hanging up and calling again and waiting on hold.
Re: HTTPS on Your Landing Page Is Important
#225Earlier quoted context omitted.
You didn't click on a search result, you clicked on an advertisement.
A good reason to use at the very least adblock.
Re: HTTPS on Your Landing Page Is Important
#226It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.
Guess what! If your financial service restricts your password to letters and numbers, it's most likely because they want you to be able to enter your password on the phone. So the passwords 'abc' 'ABC' and '222' are treated as equivalent. Try it out for fun!
Re: HTTPS on Your Landing Page Is Important
#227Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…
Citi has some really bad security practices, when I talked with them about it they mentioned some future changes they were planning that were even worse.
Re: HTTPS on Your Landing Page Is Important
#228Earlier quoted context omitted.
But did you call the support phone number shown on the dodgy domain?
T-Mobile called me back one time instead of me waiting on hold. This was after I went through the song and dance of giving the automated system my details. The first thing this representative wanted to do was, again, confirm I am who I said I was. I said think about what you're asking for a second. Should I answer your questions? Couldn't get them to understand. Wound up hanging up and calling again and waiting on ho…
Obviously I terminated the conversation.
Re: HTTPS on Your Landing Page Is Important
#229I'm not really surprised, UK banks are absolutely terrible in terms of their product and even worse in supporting clients having valid points. Another example would be MetroBank that recently changed password prompt to a masked password prompt (in addition to already existing masked PIN alongside) ignoring the research proving its a horrible user experience and in fact lowers the security or (not a bank, but still ma…
When I was with Three they had a phone password which was not the same password as my online account password. I have nothing informed to say on the security of this approach, other than that asking customers for their online account password would be completely unacceptable in all circumstances, and shouldn't even be helpful because as we all know passwords should not be stored in a reversible format.
Re: HTTPS on Your Landing Page Is Important
#230It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.
Offenders: Wells Fargo, Chase, American Express, Fidelity, ....