Because of this I finally decided to complain to my (Australian) bank about their max 6 character (alphanumeric) no symbol password policy... And lack of MFA for personal accounts... And continuing to only offer OTP via SMS to authorise transactions. Well, I tried to complain... for you see after going through multiple pages/steps in the UI, when it came time to review and submit, after you press submit you are told…
> max 6 character (alphanumeric) no symbol password policy You forgot to add case isn't significant. Still, even such small passwords can be secure if managed right. It's been that way for many years, and I don't recall seeing anything about it being broken, so I guess it must be work ok. I doubt the ombudsman would care. On the other hand, every 10 or 20 logins, after logging in it doesn't display the internet banki…
Also if they aren’t able to accept other characters, I wonder what happens when you try?
I’ve worked “across” core payments(not banking) systems with the card schemes, westpac, St George etc. So I would say I’ve seen how bad things can get but your bank sounds like something next level.