Live data from Hacker News

Schwab password policies and two factor authentication

jeremytunnell.com

51–60 of 127 posts

Re: Schwab password policies and two factor authentication

#51

Earlier quoted context omitted.

It appears a lot of people have already warned Schwab about this. Sadly, I expect it will change only if there was some embarrassing large scale attack that is subsequently publicized.

How would such large scale attack be perpetrated? The worst you could do would be to lock out a lot of accounts.

If someone managed to steal a database of credentials from Schwab, they could possibly decrypt the passwords (all these limitations clearly point to them not hashing properly).

If someone stole a database from a provider that implements passwords correctly, the best they could do is get some low-hanging fruit passwords.

Re: Schwab password policies and two factor authentication

#52

After receiving unsatisfactory responses from my local Schwab rep here in New York and the customer service staff, I complained to Schwab's CISO, Bashar Abouseido , on September 1. He never replied.

Ahh, but he only reads the first eight letters, so all he got from your email was "Greeting"

Re: Schwab password policies and two factor authentication

#53
Offers little consolation...

Schwab has "...a system which locks you out if you guess the [username,password] combination incorrectly more than twice.."

Schwab can improve your security via Verisign and verbal passwords, but you have to ask for it: "... Schwab has several additional (optional) verification methods."

http://www.marottaonmoney.com/schwab-verisign-security-measu...

Re: Schwab password policies and two factor authentication

#55

I just called Schwab about this, and hand to whatever deity you believe in, this is what he told me: Representative: "One of the things we were trying to do with these passwords was make them different from other providers. So we know that they allow multiple character types, and are case-sensitive, so we decided to make them different. That way, you can't use the same password you've used elsewhere and it kind of fo…

I love the arbitrary restrictions that all these sites come up with that ultimately make them less safe. Yesterday I was setting up some stuff for somebody who knows nothing about tech. IIRC it went like this:

* Google: no restrictions, as far as I could tell.

* Apple: password not accepted because it MUST contain at least one uppercase letter.

Of course, simply knowing that one of the characters MUST be an uppercase letter significantly decreases the number of combinations available

Re: Schwab password policies and two factor authentication

#56

Quite shameful. Fortunately, I only use Schwab because of their awesome checking account that covers ATM fees. Definitely won't put more of my assets in there until they get their act together. I may be wrong, but I think user IDs can be longer than 8 characters too which makes this all even worse. LinkedIn did something similar with having to append your auth token to the end of your password, but they actually chec…

I use Alliant Credit Union, and last month they started refunding ATM fees as well (limit 8 in a month, I believe)

Re: Schwab password policies and two factor authentication

#57

I just called Schwab about this, and hand to whatever deity you believe in, this is what he told me: Representative: "One of the things we were trying to do with these passwords was make them different from other providers. So we know that they allow multiple character types, and are case-sensitive, so we decided to make them different. That way, you can't use the same password you've used elsewhere and it kind of fo…

Oddly, their password field is limited by size, but their username isn't. I have a 30 digit random character username.

Re: Schwab password policies and two factor authentication

#59
Thanks for calling attention to this. I've been frustrated by it. One thing that I did was let LastPass generate 32 random characters for the password but used it to change the username. I depend on LastPass to remember that.

It's not much but it was all I could come up with.

My wife wants to use the Schwab app to deposit checks on her phone but I don't trust their security. One lost phone could lead to our retirement funds being transferred to Belize (or wherever).

Post reply on HN