Live data from Hacker News

We'd lose our security certificate if we allowed pasting

twitter.com

151–160 of 225 posts

Re: We'd lose our security certificate if we allowed pasting

#151
post #40

It always concerns me when big companies like this do weird things when it comes to passwords. Why do banks for instance have stupid password requirements; max lengths, disallowing certain characters, etc. Surely if they are hashing the passwords in any form then it doesn't matter how long the password is or what characters it contains. I understand perhaps the view is some people are not good at remembering password…

> ... stupid password requirements; max lengths ... > ... if they are hashing the passwords in any form then it doesn't matter how long the password is ... Max lengths aren't inherently stupid. Presumably no one thinks 250MB password submissions should be handled, so you will be picking some number (possibly imposed on you by your stack).

English has at least ~0.6 bits of entropy per character, probably (much) more, depending. (Got that from Wikipedia, so don't know how accurate that is)

So even if you are using an English passphrase, the logical upper bound for a max password length is ~1.7x the length of the hash you use.

Re: We'd lose our security certificate if we allowed pasting

#152
post #85

So, this is just someone on the BritishGas twitter account. We do not know if that person is repeating accurately what they've been told or just making stuff up. Assuming they asked the correct people in BG website accounts security, and those people said "it's to prevent brute force attacks" we do not know if that's the real reason they do it or if it's just what they say to people who ask. What is really frustratin…

Thank you! I get amazed every time the internet freaks out because XYZ Company confirms "blah", when in reality, it's just a single service rep, who probably just wants to get you off of the phone.

Its way worse with the advent of social media consultants/reps because their stupid explanation gets saved for the entire world to see, even if its about a section of a multi-billion dollar company they have no idea about. Low level reps have never had such an impact on companies as they do on social media.

Re: We'd lose our security certificate if we allowed pasting

#154

Earlier quoted context omitted.

Americans don't do wire transfers, they write checks. The level of kidding in the previous sentence is extremely low.

Wire transfers tend to have a $35-$50 fee and require you to schlep down to the bank during business hours and fill out annoying paperwork. So, yeah, we don't use them except in emergencies.

Do we have a misunderstanding of the meaning of "wire transfer" here? Surely you can just send money to someone else's account through the bank's internet banking website?

How else do you pay for stuff like rent, and, well, anything, really?

Re: We'd lose our security certificate if we allowed pasting

#155
post #29

They probably hired the same security consultant as my bank, which requires your online password to be exactly six characters long. My hypothesis is that this is a technical limitation due to the password being stored as a char(6) in their database.

My bank enforces a six character limit and the passwords aren't even case sensitive. But, brace yourself to feel safe - they make me answer a security question (in this case, "What high school did you go to?"

They made a (record) four billion dollar profit last year, so this strikes me as security designed by someone with an MBA and a spreadsheet. I'd be upset, but, I've been stupid enough to keep doing business with them...

Re: We'd lose our security certificate if we allowed pasting

#156
post #121

Earlier quoted context omitted.

Americans don't do wire transfers, they write checks. The level of kidding in the previous sentence is extremely low.

I believe you're a UK but no offense intended if you're not. As an actual american I only write about three or four checks per year, everything else is online. We do pull and push. Pulls are an unholy PITA to set up where you give them all kinds of personally identifiable information which they hopefully won't lose, then they make multiple couple cent deposits to your account, then you tell them what the amounts were…

Wow, this sounds insane. Here in the UK they have recently improved the electronic transfer system so that money appears in the other account (clears) in 2 hours or less (practically instantly for accounts at the same Bank). I do not know whether large bank transfers using BACS or CHAPS incur a fee but most people happily send money to other people electronically as few people have cheques anymore. The banks seem to have stopped issuing cheque books, and no shop that I know of will accept them, so it effectively killed cheques. The older generation probably struggle without them.

They have recently pushed out the mobile payment system called PAYM (someone obviously got paid a fortune to think of pay + mobile, eg. pay + m ... . . paym) where you can send money to anyone else with their mobile number. They need to have registered their mobile number with their bank for this to work (and not all banks have signed up to the system) but it should make sending money really easy.

People seem to use Paypal a lot for sending money around but they're greedy with fees so I am keen for this PAYM system.

Re: We'd lose our security certificate if we allowed pasting

#157
post #12

Earlier quoted context omitted.

Unless you buy online, in which case you just need the "last 3 digits on the back of your card".

That's different to the PIN. CVV is for cardholder not present transactions, PIN is for one's where you're there. Also CVV needs the 16 digit card number, card holder name and expiry as well.. I'd almost guarantee that trying to brute-force a CVV number will get your card blocked real fast.

I got an email from my credit card after a single CVV failure, because the guy at the Apple store entered it wrong.

Re: We'd lose our security certificate if we allowed pasting

#158
post #96
post #84

Earlier quoted context omitted.

6 characters for a bank password?! Get a better bank! It's unbelievable how bad the password policies of some banks are. Mine doesn't allow special characters, for example. Fortunately it does allow longer passwords at least.

That's nothing, mine's a 5 digit pin code which they only validate 3 of in a random order (to annoy keyloggers, I assume) plus the last 4 digits of my phone number. Edit: This feels like the scene where Mel Gibson and Rene Russo compare scars in Lethal Weapon 3.

"This feels like the scene where Mel Gibson and Rene Russo compare scars in Lethal Weapon 3."

You might also refer to the scene from Jaws(1975) where Hooper and Quint compare scars: http://www.rowthree.com/2011/10/18/finite-focus-competitive-...

Re: We'd lose our security certificate if we allowed pasting

#159
post #74
post #66

Earlier quoted context omitted.

It's pretty standard in the UK

None of my personal accounts in the UK use two factor authentication. Same goes for the majority of friends and family. Only one (former) account ever done this, and it was own used when adding a new payee records. It used EMV CAP ( http://en.wikipedia.org/wiki/Chip_Authentication_Program ) with a separate smartcard (not my EMV compliant debit card). All of my business accounts offer two factor authentication, recent…

Barclays bank uses two-factor authentication for logging into their online banking (using your card, so that you have to enter you PIN for your card on the little authentication machine to get a code to log in), although you can also set up a PIN to log in without it (I haven't bothered - it's safer not to, right?!). You also need your membership number and a memorable word AND a number as far as I can remember (I do it automatically now)

They also require this authentication step to be carried out for sending money to someone else online for the first time. They also require you to enter your PIN against your card using the same mechanism when you go into a branch, as they cannot access details about your account without you doing it. I suspect it stopped people mugging others and they walking as saying "Can I withdraw £100 on this account here please?" with the card they'd just pinched.

The Barclays one is called PINSentry and they've had it for nearly 10 years I think? My device still hasn't ran out of battery (it gets switched on when you insert your card).

My wife is with Natwest I think and she needs the little card device for setting up new payments but logging in does not need it.

Re: We'd lose our security certificate if we allowed pasting

#160
post #16

Earlier quoted context omitted.

I have had quite a few sites block my account for three bad password attempts and I had to actually call the company to unlock the account (this was always a financial services company). It's quite annoying as none of the sites warned me about the impending account block after the first or second try. I guess it's an inconvenience that is worth it for the extra anti-brute-force security. Being locked out due to someo…

It's always annoyed me how people set the lockout after n attempts value to ~3 or 4. Why not 100? It makes almost no difference in your chances at brute forcing a password, but means that the real user trying all the passwords they might have used won't get locked out mid way.

> It makes almost no difference in your chances at brute forcing a password

Depends on how many people use a password in the top 100 most common vs. how many use one in the top 3. I would think it would be a sizeable difference.

Post reply on HN