Live data from Hacker News

Ask HN: A major USA bank is storing passwords in cleartext – what to do?

news.ycombinator.com

161–170 of 328 posts

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#161

There's a similar issue with Wells Fargo. I think it has to do with banks they acquired (in my case Wachovia). My passwords are not case sensitive.

Wells Fargo isn't really Wells Fargo. It was a massive bank in the midwest called Norwest (based in MN, but offices all over midwest). Norwest acquired WF primarily for the superior name recognition. The merger with Wachovia happened after that.

for the longest time they you could set your password to be anything, but they only checked the first 8 characters and it wasn't case sensitive. Just chalk it up to shit being written in the 80s.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#162

Name and shame. I'll start: American Express passwords are not case sensitive. It is possible that they UPPER(...) the password before hashing it and then compare against that when you log in. This explanation would only be a little dumb because it reduces the domain of the password space. It also strains credulity.

Strains credulity? What do you mean by that?

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#163
post #96

Since it seems this is PNC, I am one of those who now needs to find a new bank. Any recommendations? I used PNC for my checking/credit but already use an american express high yield savings. I was thinking maybe Capital One?

no no no that’s just switching from Coke to Pepsi

I’ve been using USAA for over ten years now, it's magical. Contrary to popular belief, you don't have to be a service member for it.

If I couldn't have USAA I'd look into local credit unions.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#164

Wow. Did they repeat your password or some hint you typed in a long time ago? FWIW I have seen two companies that store passwords properly in a one way hash with salt but store statistics on every password like number of case changes and count of numbers and total length. I personally think that practice is infinitely stupid but can explain why they can say it has 3 numbers in it. One major marketing firm I did work…

I know a bank (I forget which, in EU) that asked me for the 3rd and 5th letter to my password when I called them. Their thinkkng was probably that way the customer support on the other end would only see 2 letters of said password.

My main bank does this all the time.

To be honest, while I'm aware it's not the best of practices, I don't care much. To me, the most important thing about bank security is that if there are fraudulent operations in my account, I can call and have them undone without much fuss. In this respect, my bank has behaved well in the past when random charges from an exotic country appeared in my credit card, in fact they noticed before I did, gave me a call and everything was fixed immediately.

For this reason, I think I'm OK with banks not having too strict security practices. If at some point they start being really paranoid about security, they might feel tempted to conclude that if there is fraudulent activity, it must surely be the client's fault, because their systems are unbreachable. I'd rather have the current situation in which I don't have much responsibility about security, problems happen but the bank responds.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#165

Wow. Did they repeat your password or some hint you typed in a long time ago? FWIW I have seen two companies that store passwords properly in a one way hash with salt but store statistics on every password like number of case changes and count of numbers and total length. I personally think that practice is infinitely stupid but can explain why they can say it has 3 numbers in it. One major marketing firm I did work…

I know a bank (I forget which, in EU) that asked me for the 3rd and 5th letter to my password when I called them. Their thinkkng was probably that way the customer support on the other end would only see 2 letters of said password.

My UK bank has a "memorable word" which is separate from the login mechanism (which uses a physical TOTP pad). Authorising online transactions requires you to give "3rd, 6th & 10th letters" eg of your memorable word.

Are you thinking of that?

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#166

As someone who works in finance/banking, I can assure you that this is not uncommon. Almost everyone is engaging in not-so-best practices with password storage if they are using any 3rd party vendors. Only the institutions with the resources to rebuild in-house systems with modern security standards are the exception to this rule. There are only a handful of these. Ultimately, it's not some malicious intent or incomp…

> For many banks and other financial institutions, going down for even 1 hour is a complete catastrophe. Are you joking? It's a common trope for bank websites to go down for "scheduled maintenance". Not to mention real-world bank branches keep bizarre hours and close for random holidays like Presidents' Day and Veterans' Day. Why do banks and credit card companies need to perform "scheduled maintenance" during which…

Even though websites are really important, I think they mean other business critical services going down for an hour.

Imagine if all credit cards with a company failed to process transactions for an hour, or depositing/withdrawing money didn't make a change to your balance. Those types of issues are much more severe than a customer not being able to log in to the website.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#167

As someone who works in finance/banking, I can assure you that this is not uncommon. Almost everyone is engaging in not-so-best practices with password storage if they are using any 3rd party vendors. Only the institutions with the resources to rebuild in-house systems with modern security standards are the exception to this rule. There are only a handful of these. Ultimately, it's not some malicious intent or incomp…

> As someone who works in finance/banking, I can assure you that this is not uncommon.

Your assurance is not reassuring.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#168

Earlier quoted context omitted.

>How much ripping would HN impose on one of these institutions if they attempted a 100% best practices secure password upgrade and then subsequently had a complete IT disaster unfold (I can certainly link articles). I'm definitely interested in examples of this

Here is one recent example I just dug up: https://www.itnews.com.au/news/massive-cba-outage-traced-to-... Not specifically related to password security upgrade, but it illustrates the impact of a bank's IT systems going down. Being able to run a credit card transaction and receive your paycheck is fundamental to the fabric of our society. When these processes are disrupted, people get very anxious and things start to…

On the other hand, malicious actors have been remotely draining banks, especially small banks, remotely due to their poor IT practices.

So a bank system that is "up but insecure" is only a recipe to be horribly hacked later.

I rather my bank be down for a few hours and come back online with my money intact than be hacked and drained and but online.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#169
(Throwaway for obvious reasons)

Proud of my bank in India (State Bank of India) which is crazy over security. Secure password requirements for login. Another completely different password for managing my banking profile and adding bank transfer beneficiaries. OTP for each money transfer related activities I do from the bank.

Re: Ask HN: A major USA bank is storing passwords in cleartext – what to do?

#170
post #155

Fidelity's passwords map to characters on the phone keymap, e.g. the characters "j,k,l,J,K,L,5" can all be represented by the number 5 on the phone. Holy entropy, Batman!

I can attest to this. When you call in you just have to type in your alphanumeric password completely using the 10 digit phone pad. Just like in the 90s. On the other hand Fidelity has the best customer service I have ever experienced so I guess everyone has competencies.
Post reply on HN