Earlier quoted context omitted.
Are there benefits to append the token to the end of the password over adding a field for it in the form?
Convenience for the user (no need to move to a different field) and UI advantages (no need for an third field which might make the form look complicated and confuse users who don't have 2FA activated. Not saying that this is a good idea, but there are some benefits for appending the token.
Schwab password policies and two factor authentication
31–40 of 127 posts
Re: Schwab password policies and two factor authentication
#32Re: Schwab password policies and two factor authentication
#33Banks aren't technology companies. Someday a technology company will become a bank.
http://www.businessinsider.com/bank-it-spending-2012-12 The banking system functions largely on the choice, application and integration of technology, and banking is more of a technology business than just about any other. And let's be fair here - Schwab is not a bank, and even among investment firms is an outlier with the noted bad practices.
They don't behave like Google or Facebook. Their DNA is not technical.
Re: Schwab password policies and two factor authentication
#34I've been using Schwab for almost 5 years and haven't noticed the password limitation until about 2 years ago. My password is pretty lengthy, so when I mistyped the last letter and pressed enter, I expected an error message. Instead, Schwab logged me in. I investigated a bit and ended up contacting Schwab about the "vulnerability". I remember someone quite high up responding saying they were aware of the length limit…
Re: Schwab password policies and two factor authentication
#35Earlier quoted context omitted.
http://www.businessinsider.com/bank-it-spending-2012-12 The banking system functions largely on the choice, application and integration of technology, and banking is more of a technology business than just about any other. And let's be fair here - Schwab is not a bank, and even among investment firms is an outlier with the noted bad practices.
> banking is more of a technology business than just about any other. They don't behave like Google or Facebook. Their DNA is not technical.
Re: Schwab password policies and two factor authentication
#36He never replied.
Re: Schwab password policies and two factor authentication
#37anyone with money in a schwab account schould schip all their schillings home, and tell schwab to schuck it.
Re: Schwab password policies and two factor authentication
#38Thanks for posting, I've passed this on to my contact at Schwab to see if it can get fixed properly ;)
It appears a lot of people have already warned Schwab about this. Sadly, I expect it will change only if there was some embarrassing large scale attack that is subsequently publicized.
Re: Schwab password policies and two factor authentication
#39Re: Schwab password policies and two factor authentication
#408 digits password... It sound like DES encryption stored directly in the database. (This is pure speculation of course) This alone is a huge red flag. Adding the fact that the 2 factor auth. is broken is not a good news.