Live data from Hacker News

Schwab password policies and two factor authentication

jeremytunnell.com

21–30 of 127 posts

Re: Schwab password policies and two factor authentication

#22
post #9

Earlier quoted context omitted.

Are there benefits to append the token to the end of the password over adding a field for it in the form?

Convenience for the user (no need to move to a different field) and UI advantages (no need for an third field which might make the form look complicated and confuse users who don't have 2FA activated. Not saying that this is a good idea, but there are some benefits for appending the token.

I might buy it if two factor activation wasn't a one time operation.

As it stands, there's no need to confuse existing users. You just need a separate pathway to activate the token.

THEN you just ask for the token as a step two in the login process. That's actually how Schwab handles things right now.

Re: Schwab password policies and two factor authentication

#23
Not that this is an excuse, but keep in mind that Schwab probably has had the mentality that a compromise of a user's online account, while bad, is not the end of the world.

They have been frustratingly slow in implementing features like linking external bank accounts using trial deposits instead of mailing them a voided check from the external account.

Their slowness to adopt these new features has meant that if you got access to the online account, there wasn't much you could do as a third party that moved money out of the already linked accounts of the victim. You could cause headaches or buy/sell securities but not access the money easily. And if you did link an account or add a biller the victim would get an email.

Things have probably changed recently since I think you can link external accounts now, and there's probably a way to send yourself a check as a bill payment.

Totally not an excuse though.

Note:

I was fooled by the password length as well. Sometimes I would hit what I thought was the wrong last few letters on my phone keyboard yet the password would still work somehow. Turns out you can just type the first eight and be done.

Re: Schwab password policies and two factor authentication

#24

Quite shameful. Fortunately, I only use Schwab because of their awesome checking account that covers ATM fees. Definitely won't put more of my assets in there until they get their act together. I may be wrong, but I think user IDs can be longer than 8 characters too which makes this all even worse. LinkedIn did something similar with having to append your auth token to the end of your password, but they actually chec…

Are there benefits to append the token to the end of the password over adding a field for it in the form?

It saves client engineers some small amount of time from implementing it on their end, but building these screens shouldn't take more than a few days.

It's a terrible UX though. I wrote a blog post with some images about it if you want to see what it looks like: http://mark.gg/2013/07/17/linkedin-2.5-factor-authentication...

Re: Schwab password policies and two factor authentication

#25
Some of their competitors are just as bad. I remember I started to sign up for a TD Ameritrade account a few years ago, but when the password "requirements" came up (which were very similar), it was clear that they were probably storing passwords as plaintext, so I stopped.

Then I got phone calls from them asking why I hadn't finished, so I had to explain to a person that clearly wasn't technical (not his fault, of course), that his company had no idea what they were doing security wise.

Maybe they finally fixed it though. I can only hope.

Re: Schwab password policies and two factor authentication

#26
post #9

Earlier quoted context omitted.

Are there benefits to append the token to the end of the password over adding a field for it in the form?

Convenience for the user (no need to move to a different field) and UI advantages (no need for an third field which might make the form look complicated and confuse users who don't have 2FA activated. Not saying that this is a good idea, but there are some benefits for appending the token.

Definitely not more convenient for users in all cases. LinkedIn did something similar. When they told me to append my code to the end of my password and I click on the password field, my password would be wiped away so I'd have to type in my password AGAIN and then add the security token to the end of it.

You don't need a third field. On mobile, if you pass the password auth, you go to a new screen and bring up a number pad and ask the user to wait for the text message. It's pretty smooth. Much smoother than the LinkedIn flow I described above. If you don't have 2-factor auth after passing the password auth, you just go right to the app.

I documented my frustrations here in case you want to see: http://mark.gg/2013/07/17/linkedin-2.5-factor-authentication...

LinkedIn already fixed this, but it's quite shameful they even let this out into the wild. :/

Re: Schwab password policies and two factor authentication

#27
post #4

Thanks for posting, I've passed this on to my contact at Schwab to see if it can get fixed properly ;)

This has been a problem for years that they refuse to fix. The legacy password thing (Strike one) is bullshit, they could just force everyone to update their passwords when they implement a properly designed system. I would be even more disheartened if customer complaints and an article in Ars can't get this fixed, but someone "passing it on to a contact" could. It's disgusting that this is how they've handled it. I…

I understand your frustration, but let's see how 'passing it on to a contact' will (or will not) work in this case.

Re: Schwab password policies and two factor authentication

#28
post #22
post #9

Earlier quoted context omitted.

Convenience for the user (no need to move to a different field) and UI advantages (no need for an third field which might make the form look complicated and confuse users who don't have 2FA activated. Not saying that this is a good idea, but there are some benefits for appending the token.

I might buy it if two factor activation wasn't a one time operation. As it stands, there's no need to confuse existing users. You just need a separate pathway to activate the token. THEN you just ask for the token as a step two in the login process. That's actually how Schwab handles things right now.

For some shitty services, like PayPal that don't give you a long-lived auth token, it is an every-time process. :|

As expected, Schwab isn't the only perpetrator of bad two-factor auth. I think PayPal still DOES NOT support two-factor auth on their mobile clients.

Shameless plug of my blog posts about Paypal's terrible two factor auth:

http://mark.gg/2014/10/22/paypal-and-delusions-of-grandeur/

http://mark.gg/2014/06/04/kicking-the-tires-with-paypal/

Re: Schwab password policies and two factor authentication

#30

Quite shameful. Fortunately, I only use Schwab because of their awesome checking account that covers ATM fees. Definitely won't put more of my assets in there until they get their act together. I may be wrong, but I think user IDs can be longer than 8 characters too which makes this all even worse. LinkedIn did something similar with having to append your auth token to the end of your password, but they actually chec…

There are other banks that offer accounts with similar benefits plus the benefit of having physical branches. TD premier checking is one, if you're fine with keeping a minimum balance.
Post reply on HN