Live data from Hacker News

Schwab password policies and two factor authentication

jeremytunnell.com

41–50 of 127 posts

Re: Schwab password policies and two factor authentication

#41

Schwab does let you enter your token code on a separate screen. If you enter your username and password (without appended token code), you'll get this screen: https://www.flickr.com/photos/paul/16079572151/

You're correct, but that doesn't fix the first activation, which is what I wrote the post about. The real problem is that I thought I had two factor activated for months when I didn't.

Re: Schwab password policies and two factor authentication

#42
post #8

I filed a support ticket about the password length. They told me it was due to "government standards" and they would reevaluate after a new standard came out. I didn't inquire further into this obvious BS. They provide a good service otherwise so it's strange that they have this blind spot.

The modern government standard for classified systems is 15 characters minimum.

Re: Schwab password policies and two factor authentication

#43
It may be much worse than you think. Another large brokerage company I know of has similar password requirements. They also have a phone banking system, to use it you have to touch tone in your password. On a whim I tried entering the keypad version of my password on the website and surprise! it worked. Luckily for me there is zero customer liability for fraud on their retirement accounts.

Re: Schwab password policies and two factor authentication

#44
"Like probably millions of people I have a Schwab brokerage account, and that account holds a good portion of my savings for retirement."

OpSec 101: replace that sentence with "Like probably millions of people I have a Schwab brokerage account, and that account holds just a few bucks of play money to try out trading strategies."

Re: Schwab password policies and two factor authentication

#45
post #29

8 digits password... It sound like DES encryption stored directly in the database. (This is pure speculation of course) This alone is a huge red flag. Adding the fact that the 2 factor auth. is broken is not a good news.

I think you mean DES based crypt and not DES encryption.

Re: Schwab password policies and two factor authentication

#46
post #41

Schwab does let you enter your token code on a separate screen. If you enter your username and password (without appended token code), you'll get this screen: https://www.flickr.com/photos/paul/16079572151/

You're correct, but that doesn't fix the first activation, which is what I wrote the post about. The real problem is that I thought I had two factor activated for months when I didn't.

True. I was so confused when I got my token — it didn't come with instructions, and there was no activation link on the site.

I ended up calling support to figure out how to set things up.

Re: Schwab password policies and two factor authentication

#48
I just called Schwab about this, and hand to whatever deity you believe in, this is what he told me:

Representative: "One of the things we were trying to do with these passwords was make them different from other providers. So we know that they allow multiple character types, and are case-sensitive, so we decided to make them different. That way, you can't use the same password you've used elsewhere and it kind of forces you to come up with a new one."

Me: "...that is... I can't even explain how terrible that is."

Representative: "Well, Schwab does care about your security and as far as the 8-character limitation goes, the reason you can enter any arbitrary text afterwards is so that if someone is looking over you shoulder they can't tell that it only accepts 8."

Points for thinking on his feet?

Re: Schwab password policies and two factor authentication

#49

I've been using Schwab for almost 5 years and haven't noticed the password limitation until about 2 years ago. My password is pretty lengthy, so when I mistyped the last letter and pressed enter, I expected an error message. Instead, Schwab logged me in. I investigated a bit and ended up contacting Schwab about the "vulnerability". I remember someone quite high up responding saying they were aware of the length limit…

It's the same for Wells Fargo. I can type random characters after the password and still login.

Re: Schwab password policies and two factor authentication

#50
post #20

I complained to Schwab about their password policies numerous times over the 3 years I was a bank/brokerage customer. A few months ago I finally moved my accounts to TD. Schwab's standard response was 1) to assure me that they had "intelligent" fraud monitoring systems on their backend and 2) to offer me a hard token, which would have been a pain and may have caused issues with Mint.

My response to fraud monitoring: "I have an alarm on my car, but I still lock the doors."
Post reply on HN