Live data from Hacker News

Schwab password policies and two factor authentication

jeremytunnell.com

31–40 of 127 posts

Re: Schwab password policies and two factor authentication

#31
post #9

Earlier quoted context omitted.

Are there benefits to append the token to the end of the password over adding a field for it in the form?

Convenience for the user (no need to move to a different field) and UI advantages (no need for an third field which might make the form look complicated and confuse users who don't have 2FA activated. Not saying that this is a good idea, but there are some benefits for appending the token.

If they're going for "less complicated" then what they've done hasn't achieved it :)

Re: Schwab password policies and two factor authentication

#33
post #11

Banks aren't technology companies. Someday a technology company will become a bank.

http://www.businessinsider.com/bank-it-spending-2012-12 The banking system functions largely on the choice, application and integration of technology, and banking is more of a technology business than just about any other. And let's be fair here - Schwab is not a bank, and even among investment firms is an outlier with the noted bad practices.

> banking is more of a technology business than just about any other.

They don't behave like Google or Facebook. Their DNA is not technical.

Re: Schwab password policies and two factor authentication

#34

I've been using Schwab for almost 5 years and haven't noticed the password limitation until about 2 years ago. My password is pretty lengthy, so when I mistyped the last letter and pressed enter, I expected an error message. Instead, Schwab logged me in. I investigated a bit and ended up contacting Schwab about the "vulnerability". I remember someone quite high up responding saying they were aware of the length limit…

I had a similar experience with Southwest Airlines. They limit their passwords to something absurdly short, and it turned out I'd never noticed - I always typed what I thought was the password, but it was actually ignoring all of it but the first 8 characters even though I typed more in every time. I don't think it's quite as bad as Schwab, but I don't understand why doing passwords so wrong is so widespread.

Re: Schwab password policies and two factor authentication

#35
post #11

Earlier quoted context omitted.

http://www.businessinsider.com/bank-it-spending-2012-12 The banking system functions largely on the choice, application and integration of technology, and banking is more of a technology business than just about any other. And let's be fair here - Schwab is not a bank, and even among investment firms is an outlier with the noted bad practices.

> banking is more of a technology business than just about any other. They don't behave like Google or Facebook. Their DNA is not technical.

Yet they behave like Microsoft, or IBM, or HP. And those are unquestionably technology businesses.

Re: Schwab password policies and two factor authentication

#37
why did you remove the headline part about their policies being CRIMINALLY TERRIBLE. yes, "comedic" might not be completely correct, it did describe the tone of the article: NOT GOOD.

anyone with money in a schwab account schould schip all their schillings home, and tell schwab to schuck it.

Re: Schwab password policies and two factor authentication

#38
post #4

Thanks for posting, I've passed this on to my contact at Schwab to see if it can get fixed properly ;)

It appears a lot of people have already warned Schwab about this. Sadly, I expect it will change only if there was some embarrassing large scale attack that is subsequently publicized.

How would such large scale attack be perpetrated? The worst you could do would be to lock out a lot of accounts.

Re: Schwab password policies and two factor authentication

#40
post #29

8 digits password... It sound like DES encryption stored directly in the database. (This is pure speculation of course) This alone is a huge red flag. Adding the fact that the 2 factor auth. is broken is not a good news.

How about the case insensitivity on the passwords? How does that fit with DES encryption, or any kind of encryption at all?
Post reply on HN