Live data from Hacker News

Ask HN: A major USA bank is storing passwords in cleartext – what to do?

news.ycombinator.com

1–10 of 328 posts

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#2
Wow. Did they repeat your password or some hint you typed in a long time ago?

FWIW I have seen two companies that store passwords properly in a one way hash with salt but store statistics on every password like number of case changes and count of numbers and total length. I personally think that practice is infinitely stupid but can explain why they can say it has 3 numbers in it. One major marketing firm I did work for did that until we showed them why it was so dangerous. They were just trying to make users life easier but that wasn’t a smart trade off.

Personally I would like to know which bank. I have accounts at a number of major US banks and if one I use is doing this I’ll move everything out of them immediately.

Edit: to answer your question I’d hand the info to a major investigative news source and let them dig more. The FTC and banking regulators I don’t think will get involved unless there was damage.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#3
Move your money to a different bank.

Now that banks aren't paying useful interest rates they are mostly only tolerable for security and convenient access to your money. If they can't do those two then... what exactly are they for? Likely nothing.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#4

Move your money to a different bank. Now that banks aren't paying useful interest rates they are mostly only tolerable for security and convenient access to your money. If they can't do those two then... what exactly are they for? Likely nothing.

It's for an auto loan.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#5

Wow. Did they repeat your password or some hint you typed in a long time ago? FWIW I have seen two companies that store passwords properly in a one way hash with salt but store statistics on every password like number of case changes and count of numbers and total length. I personally think that practice is infinitely stupid but can explain why they can say it has 3 numbers in it. One major marketing firm I did work…

They're a three letter acronym that starts with P and ends with C.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#6
You should report to proper authorities about the severity of the issue. Reach out to their security or technical higher up department of the bank.

In your case, they may or may not be storing the password in cleartext. They might be using the two way encryption instead of one-way hash. Passwords should be hashed (with salt) and it is irreversible.

For a financial institution, revealing your password by a customer service rep is a big red flag. I would reach out to concerned authorities and do a proper disclosure.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#7

Move your money to a different bank. Now that banks aren't paying useful interest rates they are mostly only tolerable for security and convenient access to your money. If they can't do those two then... what exactly are they for? Likely nothing.

It's for an auto loan.

You may be able to refinance it.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#8

You should report to proper authorities about the severity of the issue. Reach out to their security or technical higher up department of the bank. In your case, they may or may not be storing the password in cleartext. They might be using the two way encryption instead of one-way hash. Passwords should be hashed (with salt) and it is irreversible. For a financial institution, revealing your password by a customer se…

> You should report to proper authorities about the severity of the issue. Reach out to their security or technical higher up department of the bank.

Switch your bank.

Do not reach out to the bank's security/technical! There's a non-zero chance that the response from the bank would be to reach out to the FBI and claim that you are the "hacker". It will create an enormous headache for you.

If you are going to reach out to anyone, reach out to the OCC.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#9

You should report to proper authorities about the severity of the issue. Reach out to their security or technical higher up department of the bank. In your case, they may or may not be storing the password in cleartext. They might be using the two way encryption instead of one-way hash. Passwords should be hashed (with salt) and it is irreversible. For a financial institution, revealing your password by a customer se…

> You should report to proper authorities about the severity of the issue. Reach out to their security or technical higher up department of the bank. Switch your bank. Do not reach out to the bank's security/technical! There's a non-zero chance that the response from the bank would be to reach out to the FBI and claim that you are the "hacker". It will create an enormous headache for you. If you are going to reach ou…

Thanks for clarification. Wasn't aware of OCC.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#10

Wow. Did they repeat your password or some hint you typed in a long time ago? FWIW I have seen two companies that store passwords properly in a one way hash with salt but store statistics on every password like number of case changes and count of numbers and total length. I personally think that practice is infinitely stupid but can explain why they can say it has 3 numbers in it. One major marketing firm I did work…

They're a three letter acronym that starts with P and ends with C.

Holy smokes. See if you can get in touch with someone in the financial press (such as the Wall Street Journal).
Post reply on HN