Live data from Hacker News

Schwab password policies and two factor authentication

jeremytunnell.com

1–10 of 127 posts

Re: Schwab password policies and two factor authentication

#3
I've been using Schwab for almost 5 years and haven't noticed the password limitation until about 2 years ago. My password is pretty lengthy, so when I mistyped the last letter and pressed enter, I expected an error message. Instead, Schwab logged me in. I investigated a bit and ended up contacting Schwab about the "vulnerability". I remember someone quite high up responding saying they were aware of the length limit but that they lock you out after 3 failed password attempts. I didn't validate the claim, but I felt content and moved on.

Re: Schwab password policies and two factor authentication

#5
Quite shameful. Fortunately, I only use Schwab because of their awesome checking account that covers ATM fees. Definitely won't put more of my assets in there until they get their act together.

I may be wrong, but I think user IDs can be longer than 8 characters too which makes this all even worse.

LinkedIn did something similar with having to append your auth token to the end of your password, but they actually checked the token AFAIK.

Re: Schwab password policies and two factor authentication

#7

Quite shameful. Fortunately, I only use Schwab because of their awesome checking account that covers ATM fees. Definitely won't put more of my assets in there until they get their act together. I may be wrong, but I think user IDs can be longer than 8 characters too which makes this all even worse. LinkedIn did something similar with having to append your auth token to the end of your password, but they actually chec…

Are there benefits to append the token to the end of the password over adding a field for it in the form?

Re: Schwab password policies and two factor authentication

#8
I filed a support ticket about the password length. They told me it was due to "government standards" and they would reevaluate after a new standard came out. I didn't inquire further into this obvious BS. They provide a good service otherwise so it's strange that they have this blind spot.

Re: Schwab password policies and two factor authentication

#9

Quite shameful. Fortunately, I only use Schwab because of their awesome checking account that covers ATM fees. Definitely won't put more of my assets in there until they get their act together. I may be wrong, but I think user IDs can be longer than 8 characters too which makes this all even worse. LinkedIn did something similar with having to append your auth token to the end of your password, but they actually chec…

Are there benefits to append the token to the end of the password over adding a field for it in the form?

Convenience for the user (no need to move to a different field) and UI advantages (no need for an third field which might make the form look complicated and confuse users who don't have 2FA activated.

Not saying that this is a good idea, but there are some benefits for appending the token.

Post reply on HN