Live data from Hacker News

Ask HN: A major USA bank is storing passwords in cleartext – what to do?

news.ycombinator.com

21–30 of 328 posts

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#21
Something similar happened to me once. An e-commerce platform gave my wife my plaintext password. It was my "low security" password, the same one I used in dozens of sites. That's when I started using a password manager so now every site gets a different random password.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#22
post #19
post #16

Earlier quoted context omitted.

I feel the bank should be liable for stolen funds or information in the case of a security breach.

Yes, I expect the bank to protect my money. What I'm saying is how they actually do it, clear text pwd or whatever is not really my concern. Why should I ?

This the most intelligent thing I've heard on this thread.

So long as I'm not holding the bag should my account with them go haywire, I don't care. This is why shared passwords are bad.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#23
post #19
post #16

Earlier quoted context omitted.

I feel the bank should be liable for stolen funds or information in the case of a security breach.

Yes, I expect the bank to protect my money. What I'm saying is how they actually do it, clear text pwd or whatever is not really my concern. Why should I ?

Sounds like they are open to social engineering attacks, if you can get a rep to describe the password to you... Meaning I could pretend to be you and get your money.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#24
post #15

Is there actual damage? At the end of day, as a customer,all I care is my money is available (not stolen) and I can access it when I need it. Why should I care about implementation details ?

Oblivious, while also utterly disregarding your own self interests. Reminds me of real life, have an upvote!

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#25
post #19

Earlier quoted context omitted.

Yes, I expect the bank to protect my money. What I'm saying is how they actually do it, clear text pwd or whatever is not really my concern. Why should I ?

Sounds like they are open to social engineering attacks, if you can get a rep to describe the password to you... Meaning I could pretend to be you and get your money.

Maybe but that is their problem. Its still the bank responsibility to deal with that.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#26
post #20

Genuinely curious, why not name the bank here? It certainly isn't going to be news to the bank itself, so there aren't responsible disclosure concerns here. And since the top advice here is to leave the bank, wouldn't the best thing you can do be to alert the public, so others can protect themselves as well?

Looks like it’s PNC. Everyone here, move your money now.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#27

Wow. Did they repeat your password or some hint you typed in a long time ago? FWIW I have seen two companies that store passwords properly in a one way hash with salt but store statistics on every password like number of case changes and count of numbers and total length. I personally think that practice is infinitely stupid but can explain why they can say it has 3 numbers in it. One major marketing firm I did work…

They're a three letter acronym that starts with P and ends with C.

That's about run of the mill for them (assuming we're thinking of the same bank). I called about my mortgage and they started reading off someone else's information. They also wanted me to confirm personal information over email...

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#28
post #20

Genuinely curious, why not name the bank here? It certainly isn't going to be news to the bank itself, so there aren't responsible disclosure concerns here. And since the top advice here is to leave the bank, wouldn't the best thing you can do be to alert the public, so others can protect themselves as well?

One weak argument:

Finance is between 20 and 50 years behind the curve in terms of fundamental/top-down security common sense, notwithstanding the handful of specific exceptions strictly necessary to ensure accounts are not actually made off with on a regular basis.

There are likely a good handful of hair-raising security issues (known and unknown) impacting your account(s) right now, that would cause you to scream and run were to learn of any single one of them (let alone the full list).

In this light, cargo-culting specifically [only] avoiding environments that store passwords in plain text feels like premature optimization.

With the above being said, I do agree with the sentiment raised elsewhere of contacting annoying persistent organizations that will follow up - apparently in this case that's investigative journalists and the OCC.

Just don't forget the bigger picture.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#30

You should report to proper authorities about the severity of the issue. Reach out to their security or technical higher up department of the bank. In your case, they may or may not be storing the password in cleartext. They might be using the two way encryption instead of one-way hash. Passwords should be hashed (with salt) and it is irreversible. For a financial institution, revealing your password by a customer se…

Spoiler alert.

No one in a position to care understands why this matters.

Nothing gets done.

Major vulnerability occurs.

Customers get screwed.

Some low on the totem pole techie gets blamed and loses their job.

Executives get bonuses.

Film at 11.

Post reply on HN