Live data from Hacker News

Schwab password policies and two factor authentication

jeremytunnell.com

121–127 of 127 posts

Re: Schwab password policies and two factor authentication

#122

I just called Schwab about this, and hand to whatever deity you believe in, this is what he told me: Representative: "One of the things we were trying to do with these passwords was make them different from other providers. So we know that they allow multiple character types, and are case-sensitive, so we decided to make them different. That way, you can't use the same password you've used elsewhere and it kind of fo…

I love the arbitrary restrictions that all these sites come up with that ultimately make them less safe. Yesterday I was setting up some stuff for somebody who knows nothing about tech. IIRC it went like this: * Google: no restrictions, as far as I could tell. * Apple: password not accepted because it MUST contain at least one uppercase letter. Of course, simply knowing that one of the characters MUST be an uppercase…

when I worked at Barclays (it was >10yrs ago now to be fair) the enforced password policy for our internal system was "4 ascii letters + 1 symbol + 4 digits" in that arrangement (ie: abcd!1234)

you know, for security.

Re: Schwab password policies and two factor authentication

#124
post #16

Banks aren't technology companies. Someday a technology company will become a bank.

Isn't that what Simple advertised themselves as? http://simple.com

I created an account a while ago, added the requisite $1, and promptly never used it again, largely because they didn't offer savings accounts (and still don't seem to).

Do you have any informed opinions on Simple?

Re: Schwab password policies and two factor authentication

#125
post #58

Earlier quoted context omitted.

Probably mainframes that they can't get rid of, or systems emulating / used to working with them.

I presume they "can't" because it's too expensive? How expensive is too expensive for some of the richest companies in the world?

When it costs more than the perceived value of benefits.

"Acceptable risk" is the usual term, I believe.

Re: Schwab password policies and two factor authentication

#126

I just called Schwab about this, and hand to whatever deity you believe in, this is what he told me: Representative: "One of the things we were trying to do with these passwords was make them different from other providers. So we know that they allow multiple character types, and are case-sensitive, so we decided to make them different. That way, you can't use the same password you've used elsewhere and it kind of fo…

I love the arbitrary restrictions that all these sites come up with that ultimately make them less safe. Yesterday I was setting up some stuff for somebody who knows nothing about tech. IIRC it went like this: * Google: no restrictions, as far as I could tell. * Apple: password not accepted because it MUST contain at least one uppercase letter. Of course, simply knowing that one of the characters MUST be an uppercase…

What actually matters is not the key space when it is so vast. Without these requirements: number, special char etc, the passwords used in practice would often just be dictionary words, and a dictionary is a much smaller key space.

Maybe the best countermeasure would be to match users passwords against a dictionary,

Post reply on HN