Schwab password policies and two factor authentication
21–30 of 127 posts
Re: Schwab password policies and two factor authentication
#22Earlier quoted context omitted.
Are there benefits to append the token to the end of the password over adding a field for it in the form?
Convenience for the user (no need to move to a different field) and UI advantages (no need for an third field which might make the form look complicated and confuse users who don't have 2FA activated. Not saying that this is a good idea, but there are some benefits for appending the token.
As it stands, there's no need to confuse existing users. You just need a separate pathway to activate the token.
THEN you just ask for the token as a step two in the login process. That's actually how Schwab handles things right now.
Re: Schwab password policies and two factor authentication
#23They have been frustratingly slow in implementing features like linking external bank accounts using trial deposits instead of mailing them a voided check from the external account.
Their slowness to adopt these new features has meant that if you got access to the online account, there wasn't much you could do as a third party that moved money out of the already linked accounts of the victim. You could cause headaches or buy/sell securities but not access the money easily. And if you did link an account or add a biller the victim would get an email.
Things have probably changed recently since I think you can link external accounts now, and there's probably a way to send yourself a check as a bill payment.
Totally not an excuse though.
Note:
I was fooled by the password length as well. Sometimes I would hit what I thought was the wrong last few letters on my phone keyboard yet the password would still work somehow. Turns out you can just type the first eight and be done.
Re: Schwab password policies and two factor authentication
#24Quite shameful. Fortunately, I only use Schwab because of their awesome checking account that covers ATM fees. Definitely won't put more of my assets in there until they get their act together. I may be wrong, but I think user IDs can be longer than 8 characters too which makes this all even worse. LinkedIn did something similar with having to append your auth token to the end of your password, but they actually chec…
Are there benefits to append the token to the end of the password over adding a field for it in the form?
It's a terrible UX though. I wrote a blog post with some images about it if you want to see what it looks like: http://mark.gg/2013/07/17/linkedin-2.5-factor-authentication...
Re: Schwab password policies and two factor authentication
#25Then I got phone calls from them asking why I hadn't finished, so I had to explain to a person that clearly wasn't technical (not his fault, of course), that his company had no idea what they were doing security wise.
Maybe they finally fixed it though. I can only hope.
Re: Schwab password policies and two factor authentication
#26Earlier quoted context omitted.
Are there benefits to append the token to the end of the password over adding a field for it in the form?
Convenience for the user (no need to move to a different field) and UI advantages (no need for an third field which might make the form look complicated and confuse users who don't have 2FA activated. Not saying that this is a good idea, but there are some benefits for appending the token.
You don't need a third field. On mobile, if you pass the password auth, you go to a new screen and bring up a number pad and ask the user to wait for the text message. It's pretty smooth. Much smoother than the LinkedIn flow I described above. If you don't have 2-factor auth after passing the password auth, you just go right to the app.
I documented my frustrations here in case you want to see: http://mark.gg/2013/07/17/linkedin-2.5-factor-authentication...
LinkedIn already fixed this, but it's quite shameful they even let this out into the wild. :/
Re: Schwab password policies and two factor authentication
#27Thanks for posting, I've passed this on to my contact at Schwab to see if it can get fixed properly ;)
This has been a problem for years that they refuse to fix. The legacy password thing (Strike one) is bullshit, they could just force everyone to update their passwords when they implement a properly designed system. I would be even more disheartened if customer complaints and an article in Ars can't get this fixed, but someone "passing it on to a contact" could. It's disgusting that this is how they've handled it. I…
Re: Schwab password policies and two factor authentication
#28Earlier quoted context omitted.
Convenience for the user (no need to move to a different field) and UI advantages (no need for an third field which might make the form look complicated and confuse users who don't have 2FA activated. Not saying that this is a good idea, but there are some benefits for appending the token.
I might buy it if two factor activation wasn't a one time operation. As it stands, there's no need to confuse existing users. You just need a separate pathway to activate the token. THEN you just ask for the token as a step two in the login process. That's actually how Schwab handles things right now.
As expected, Schwab isn't the only perpetrator of bad two-factor auth. I think PayPal still DOES NOT support two-factor auth on their mobile clients.
Shameless plug of my blog posts about Paypal's terrible two factor auth:
Re: Schwab password policies and two factor authentication
#29It sound like DES encryption stored directly in the database. (This is pure speculation of course) This alone is a huge red flag. Adding the fact that the 2 factor auth. is broken is not a good news.
Re: Schwab password policies and two factor authentication
#30Quite shameful. Fortunately, I only use Schwab because of their awesome checking account that covers ATM fees. Definitely won't put more of my assets in there until they get their act together. I may be wrong, but I think user IDs can be longer than 8 characters too which makes this all even worse. LinkedIn did something similar with having to append your auth token to the end of your password, but they actually chec…