Live data from Hacker News

Schwab password policies and two factor authentication

jeremytunnell.com

11–20 of 127 posts

Re: Schwab password policies and two factor authentication

#11

Banks aren't technology companies. Someday a technology company will become a bank.

http://www.businessinsider.com/bank-it-spending-2012-12

The banking system functions largely on the choice, application and integration of technology, and banking is more of a technology business than just about any other. And let's be fair here - Schwab is not a bank, and even among investment firms is an outlier with the noted bad practices.

Re: Schwab password policies and two factor authentication

#12
post #4

Thanks for posting, I've passed this on to my contact at Schwab to see if it can get fixed properly ;)

It appears a lot of people have already warned Schwab about this.

Sadly, I expect it will change only if there was some embarrassing large scale attack that is subsequently publicized.

Re: Schwab password policies and two factor authentication

#13
I have called and complained many times about their password policies.

They let you choose a random user id, as in, change the user id whenever you want. I bet you the security guys over at Schwab are using that as a reason to not improve password options. I can see the argument being - "The idiotic password limitations are not a big deal because of the random userids".

Re: Schwab password policies and two factor authentication

#14
post #10

I did report this a while ago to Schwab both over the phone and on Twitter and I have been equally ignores. Thanks for writing a blog post about it. Edit: forgot to mention that the passwords are case insensitive!!!!!!

Here's the tweet https://twitter.com/stefpac/status/455132477724852224

Re: Schwab password policies and two factor authentication

#17
post #13

I have called and complained many times about their password policies. They let you choose a random user id, as in, change the user id whenever you want. I bet you the security guys over at Schwab are using that as a reason to not improve password options. I can see the argument being - "The idiotic password limitations are not a big deal because of the random userids".

Apparently they insure you against someone breaking into your account, but this is clearly the case of a bunch of old boys who don't understand tech being in charge.

Re: Schwab password policies and two factor authentication

#18
To activate my newly received token, I was instructed to go to the homepage and append the six digit token code onto the end of my password during a login attempt.

This sounds like a symptom of the multilayered bureaucracy that often goes on in banks and similar institutions - a change to the UI to add something as simple as an extra field for the token code, and the changes required to hook it up to the backend, might have been accompanied by so much "enterprisey" management red-tape cruft (specification writing, approval documents, approval meetings, meetings for scheduling meetings - I wish I was joking, etc.) that it made the programmers find creative ways around the system.

At the least, if I were forced to concatenate fields, I'd use a separator that couldn't occur in either one, like a comma or something else that their password policy didn't allow... but then again, I wouldn't be surprised if something else in their system would reject that.

Re: Schwab password policies and two factor authentication

#19
post #4

Thanks for posting, I've passed this on to my contact at Schwab to see if it can get fixed properly ;)

This has been a problem for years that they refuse to fix. The legacy password thing (Strike one) is bullshit, they could just force everyone to update their passwords when they implement a properly designed system.

I would be even more disheartened if customer complaints and an article in Ars can't get this fixed, but someone "passing it on to a contact" could. It's disgusting that this is how they've handled it. I minimize how much money I keep with them and will be closing the account when I get back to the States.

Re: Schwab password policies and two factor authentication

#20
I complained to Schwab about their password policies numerous times over the 3 years I was a bank/brokerage customer. A few months ago I finally moved my accounts to TD.

Schwab's standard response was 1) to assure me that they had "intelligent" fraud monitoring systems on their backend and 2) to offer me a hard token, which would have been a pain and may have caused issues with Mint.

Post reply on HN