Earlier quoted context omitted.
I know a bank (I forget which, in EU) that asked me for the 3rd and 5th letter to my password when I called them. Their thinkkng was probably that way the customer support on the other end would only see 2 letters of said password.
Reminds me of TSB (UK bank) that asks, in addition to username and password, for three characters of a string when you sign in. Which is stupid because you can’t do it in your head easily. You actually need to see it written down somewhere when they ask for the 3rd, 11th and 15th character of that “memorable information”.
Ask HN: A major USA bank is storing passwords in cleartext – what to do?
81–90 of 328 posts
Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?
#82Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?
#83One bank that has astoundingly bad password requirements is Westpac Australia. Usernames are an 8 digit customer ID, and passwords have to be exactly 6 characters long(!) consisting only of numbers and uppercase letters. Try it for yourself, note that the login form only allows you to enter 8 characters for the username and 6 characters for the password: https://banking.westpac.com.au/ I complained to them about this…
Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?
#84> The service rep proceeded to (accurately) describe my own password to me. Wait, that alone doesn't necessarily indicate that they're storing clear text passwords. I notice you didn't say that they just repeated your password to you-- why do you think they store the whole thing in clear text? HN readers are apt to demand hardcore passphrases, salting, 2FA, etc. But the reality is that banks have to deal with all kin…
In Europe GDPR covers that, many big websites started hashing after it
Edit: could somebody explain the downvotes? The comments seem to agree with me
Obviously GDPR is not a law about plain text passwords, but as the comments say it forces "the use of an appropriate hashing algorithm to store your passwords, protecting the means by which users enter their passwords, defending against common attacks and the use of two-factor authentication." etc.
Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?
#85Do you really think the only thing the bank does to log people on is to check the username and password? Banks are way more sophisticated than this and it goes well beyond merely string-matching credentials; there's all sorts of other environment, behavioral and heuristic patterns used to establish legitimacy. Even if you rose this issue with the bank, they'll hardly change their modes of operation, and you certainly…
Fallacy much?
Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?
#86One bank that has astoundingly bad password requirements is Westpac Australia. Usernames are an 8 digit customer ID, and passwords have to be exactly 6 characters long(!) consisting only of numbers and uppercase letters. Try it for yourself, note that the login form only allows you to enter 8 characters for the username and 6 characters for the password: https://banking.westpac.com.au/ I complained to them about this…
Mainframe it is then.
Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?
#87Santander in the UK does this too. You can tell because they only ask for 3 characters out of your password whenever you log in. What's ironic is that whoever did that propably thought they were being super clever.
Other banks in UK do that as well, shouldn't they all be reported for this?
There is nothing in UK law that says banks have to store your passwords "securely".
Issues like this have been raised in the past, and authorities like the ICO have said no law is being broken. GDPR, for example, does not specify technical mechanisms required to store any form of data.
Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?
#88Earlier quoted context omitted.
I know a bank (I forget which, in EU) that asked me for the 3rd and 5th letter to my password when I called them. Their thinkkng was probably that way the customer support on the other end would only see 2 letters of said password.
Reminds me of TSB (UK bank) that asks, in addition to username and password, for three characters of a string when you sign in. Which is stupid because you can’t do it in your head easily. You actually need to see it written down somewhere when they ask for the 3rd, 11th and 15th character of that “memorable information”.
Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?
#89One bank that has astoundingly bad password requirements is Westpac Australia. Usernames are an 8 digit customer ID, and passwords have to be exactly 6 characters long(!) consisting only of numbers and uppercase letters. Try it for yourself, note that the login form only allows you to enter 8 characters for the username and 6 characters for the password: https://banking.westpac.com.au/ I complained to them about this…
Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?
#90One bank that has astoundingly bad password requirements is Westpac Australia. Usernames are an 8 digit customer ID, and passwords have to be exactly 6 characters long(!) consisting only of numbers and uppercase letters. Try it for yourself, note that the login form only allows you to enter 8 characters for the username and 6 characters for the password: https://banking.westpac.com.au/ I complained to them about this…