Live data from Hacker News

Ask HN: A major USA bank is storing passwords in cleartext – what to do?

news.ycombinator.com

201–210 of 328 posts

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#201
post #96

Since it seems this is PNC, I am one of those who now needs to find a new bank. Any recommendations? I used PNC for my checking/credit but already use an american express high yield savings. I was thinking maybe Capital One?

no no no that’s just switching from Coke to Pepsi I’ve been using USAA for over ten years now, it's magical. Contrary to popular belief, you don't have to be a service member for it. If I couldn't have USAA I'd look into local credit unions.

If you see my other comment, I don't think I am going to switch right now but it is good to check out alternatives. I am from the DMV area and capital one is huge here and pushes the narrative that they are an elite tech company VERY hard around here with recruiting.

I figured they would have the most secure systems out there with the army of SWEs they recruit in this area

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#202

As someone who works in finance/banking, I can assure you that this is not uncommon. Almost everyone is engaging in not-so-best practices with password storage if they are using any 3rd party vendors. Only the institutions with the resources to rebuild in-house systems with modern security standards are the exception to this rule. There are only a handful of these. Ultimately, it's not some malicious intent or incomp…

"For some strange reason when a bank calls the FBI things move with a high level of expediency."

Is this really true? AFAIK illegal account accesses such as phishing etc is fairly commonplace. Criminals steal low value from lots of accounts, and also the way they steal is not really traceable, not at least easily. How would they even know where to send the guns? And also I'm not really convinced that FBI priorizes bank cases, they probably prioritize all cases based on monetary value and maybe some harm factors, but I dont think banks get special treatment on principle. Sounds like bullshit to me to be frank.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#203
post #128

Earlier quoted context omitted.

Lol it's been that way for at least 20 years. Same with chase (well at least the bank one half of it). It seems remarkably stupid, but it's way cheaper for them to refund any losses and/or pay for lifetime credit monitoring than it is to deal with customer service calls from people getting locked out because they can't figure out how to deal with uppercase and lowercase letters.

It's funny that my small-ish credit union is not only more technologically advanced, but also way more ethical (looking at you, Wells Fargo) and convenient, and has top notch customer service. Seriously, I've never interacted with more pleasant customer service reps than my CU. Why are people giving their money to big banks again? Is it just advertising pressure?

Well, 25 years ago, when I opened at $BigBank the CU I use now didn't exist, and $BigBank offered services and availability that CU didn't (in 1995). Then, for the very long time I tied so many things to that account at $BigBank that it took almost three years for me to migrate all the accounts, business and personal and loans, etc to the new CU.

So, to why: legacy and stickiness

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#204

As someone who works in finance/banking, I can assure you that this is not uncommon. Almost everyone is engaging in not-so-best practices with password storage if they are using any 3rd party vendors. Only the institutions with the resources to rebuild in-house systems with modern security standards are the exception to this rule. There are only a handful of these. Ultimately, it's not some malicious intent or incomp…

Honestly, this is bananas to me. I work for an IoT company with contracts to places like gas stations and chain restaurants. Freakin Wendy's and places like that absolutely don't want our product on their network and we have a base station connected to cell network along with our own local wireless network. (fwiw I agree, I think its best we aren't on their network)

I know this is an apples to oranges comparison, but I just find it weird that payment processors (not the banks, I know I know) are the main driver behind these restaurant IT security measures, but other financial institutions have things like this that they do.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#205

As someone who works in finance/banking, I can assure you that this is not uncommon. Almost everyone is engaging in not-so-best practices with password storage if they are using any 3rd party vendors. Only the institutions with the resources to rebuild in-house systems with modern security standards are the exception to this rule. There are only a handful of these. Ultimately, it's not some malicious intent or incomp…

I don't even know where to begin.. you store customer passwords in plaintext because everyone else does it and that's okay because the FBI will handle it?

What. The. Fuck?

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#206
post #140
post #123

Earlier quoted context omitted.

> I definitely have Bank of America notify me when I do something out of the ordinary. -And such routines are incredibly efficient; while commissioning one of our deliveries (heavy engineering equipment) in Namibia a few years ago, I found that the local power electronics distributor hadn't heard of my employer, and were (reasonably so) reluctant to hand over parts for $13,000 or so and send an invoice to Norway. VIS…

I have one question We have all these stories of how our feudal lords have been nice and helpful But why not get the notifications yourself on your own devices? You can set up your own policies for approving transactions or whatever. I understand that the chargebacks can be done up to 60 days, which means “seller beware” in the current financial system as opposed to “buyer beware” in the crypto one. But in the crypto…

-I can, to some extent, do this in my phone banking app; I can update region/type of transaction/maximum amount; my bank even lets me have whitelists ('No card-not-present transactions outside EU, except renewal of magazine subscription such-and-such from the US', for instance).

Changes are immediate.

However, I have the impression that the VISA/MC/AMEX fraud detection override my preference.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#207

Name and shame. I'll start: American Express passwords are not case sensitive. It is possible that they UPPER(...) the password before hashing it and then compare against that when you log in. This explanation would only be a little dumb because it reduces the domain of the password space. It also strains credulity.

You can use letters in your password? Luxury! I only get 0-9. Not an American bank though (BNP Paribas in France).

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#208
Use a generated unique password for every site, preferably with a password manager. Along with the absolutely most important thing you can possible do for banking security, which is to check your statements/transactions promptly every 30 days. Beyond that it's not really your worry, besides having to possibly attend to helping them clean up any messes.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#209

As someone who works in finance/banking, I can assure you that this is not uncommon. Almost everyone is engaging in not-so-best practices with password storage if they are using any 3rd party vendors. Only the institutions with the resources to rebuild in-house systems with modern security standards are the exception to this rule. There are only a handful of these. Ultimately, it's not some malicious intent or incomp…

> These banks' IT systems are storing things that many of us would argue are much more valuable than your passwords. A bank's core system also represents the actual monetary value of every customer's account. We are talking about password security in a system domain where there are arguably far more valuable assets to secure. The password is what secures the more valuable things inside the account (the money). In fac…

> The password is what secures the more valuable things inside the account (the money).

I think the broader point of the parent is that in banks, there is actually a lot more than just the password securing the money in the bank. There is careful surveillance of the activity of accounts at the bank--separate from the website login system, and backed by regulatory accountability and ultimately the police.

Unlike a modern service like Facebook or Google, your bank's website is not the same thing as the entire bank. When you log into your bank's website or app, you're logging into a public-facing system that in turn interacts with the "real" systems that the bank uses to manage money. Those "real" systems are secured in various ways too, and not just based on the web password.

I once attended a talk by Bruce Schneier talking about the resilience of the financial system. Beyond the prevention of bad actions (for example by authentication), he emphasized that the financial system is highly engineered to make it possible to recover from bad actions. That includes some technical means, but also methods of accounting, and insurance.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#210

Earlier quoted context omitted.

> For many banks and other financial institutions, going down for even 1 hour is a complete catastrophe. Are you joking? It's a common trope for bank websites to go down for "scheduled maintenance". Not to mention real-world bank branches keep bizarre hours and close for random holidays like Presidents' Day and Veterans' Day. Why do banks and credit card companies need to perform "scheduled maintenance" during which…

The Canadian Revenue Agency website is down from 3am to 6am every single day for maintenance. They are also scheduled to be down for days at a time. https://www.canada.ca/en/revenue-agency/services/e-services/... This site is used for everything. Reviewing your taxes, reading mail and notifications you've received from the government, filing returns, making payments, etc.

That sounds amazing... as an admin, I mean. Can you imagine being allowed to have scheduled downtime every day? It does suck a bit for users, although honestly putting it at 3-6AM mitigates a lot of my concerns with that.
Post reply on HN