Live data from Hacker News

Ask HN: A major USA bank is storing passwords in cleartext – what to do?

news.ycombinator.com

11–20 of 328 posts

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#11

Move your money to a different bank. Now that banks aren't paying useful interest rates they are mostly only tolerable for security and convenient access to your money. If they can't do those two then... what exactly are they for? Likely nothing.

It's for an auto loan.

Hopefully you did not set up ACH to withdraw money from your real account.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#12

Wow. Did they repeat your password or some hint you typed in a long time ago? FWIW I have seen two companies that store passwords properly in a one way hash with salt but store statistics on every password like number of case changes and count of numbers and total length. I personally think that practice is infinitely stupid but can explain why they can say it has 3 numbers in it. One major marketing firm I did work…

They're a three letter acronym that starts with P and ends with C.

[deleted]

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#14

Wow. Did they repeat your password or some hint you typed in a long time ago? FWIW I have seen two companies that store passwords properly in a one way hash with salt but store statistics on every password like number of case changes and count of numbers and total length. I personally think that practice is infinitely stupid but can explain why they can say it has 3 numbers in it. One major marketing firm I did work…

They're a three letter acronym that starts with P and ends with C.

Pnc ?

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#16
post #15

Is there actual damage? At the end of day, as a customer,all I care is my money is available (not stolen) and I can access it when I need it. Why should I care about implementation details ?

I feel the bank should be liable for stolen funds or information in the case of a security breach.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#17

Wow. Did they repeat your password or some hint you typed in a long time ago? FWIW I have seen two companies that store passwords properly in a one way hash with salt but store statistics on every password like number of case changes and count of numbers and total length. I personally think that practice is infinitely stupid but can explain why they can say it has 3 numbers in it. One major marketing firm I did work…

They're a three letter acronym that starts with P and ends with C.

Wow, they should know better. That’s really mediocre if true. Call the OCC consumer hotline which is listed at the following link https://www.occ.treas.gov/topics/supervision-and-examination...

Tell them you’d like to file an “Official Complaint” regarding a serious cyber security issue at that bank, and to transfer you to whoever handles official consumer complaints regarding cyber security. Regulators are sensitive to the word “complaint” (specific wording matters) and typically require that complaints are stored, prioritized, and handled in a prescribed way.

Ask them if they can get back to you with any resolution and leave your contact information. Update HN if you’re comfortable with that. Good luck.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#18
post #16
post #15

Is there actual damage? At the end of day, as a customer,all I care is my money is available (not stolen) and I can access it when I need it. Why should I care about implementation details ?

I feel the bank should be liable for stolen funds or information in the case of a security breach.

They are... there's also multiple levels of insurance to cover it.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#19
post #16
post #15

Is there actual damage? At the end of day, as a customer,all I care is my money is available (not stolen) and I can access it when I need it. Why should I care about implementation details ?

I feel the bank should be liable for stolen funds or information in the case of a security breach.

Yes, I expect the bank to protect my money. What I'm saying is how they actually do it, clear text pwd or whatever is not really my concern. Why should I ?

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#20
Genuinely curious, why not name the bank here?

It certainly isn't going to be news to the bank itself, so there aren't responsible disclosure concerns here.

And since the top advice here is to leave the bank, wouldn't the best thing you can do be to alert the public, so others can protect themselves as well?

Post reply on HN