Live data from Hacker News

HTTPS on Your Landing Page Is Important

troyhunt.com

221–230 of 307 posts

Re: HTTPS on Your Landing Page Is Important

#221
post #216

NatWest is also guilty of storing passwords in plain text: their login page says 'enter the 5th, 8th and 12th character of your password'

To be fair we can't be 100% sure of that. It is possible they simply hash all the combinations they are going to show you. Could also be stored in an HSM making it a bit more secure.

Re: HTTPS on Your Landing Page Is Important

#222

It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.

Guess what! If your financial service restricts your password to letters and numbers, it's most likely because they want you to be able to enter your password on the phone. So the passwords 'abc' 'ABC' and '222' are treated as equivalent. Try it out for fun!

[deleted]

Re: HTTPS on Your Landing Page Is Important

#223

Earlier quoted context omitted.

Microsoft's sign in is a real mess, I think in part due to having to make your hotmail login that you made 15 years ago still work, along with the dozens of other services that MS has acquired or integrated. I've had a real shitter of a time trying to login before, with redirect loops, or getting automatically signed out as soon as I sign in. Or accounts being a "games for Windows" account, but not an MS account, or…

Speaking of Microsoft's signin, I can no longer access my decade-old-held Skype since their SSO integration. I've tried over and over and over and tried every route possible. It is some edge case where the email was previously a microsoft account and the password cannot be reset. I'm not the only one with the issue. Shocking something like this doesnt get resolved for years on.

Authentication in Skype is awful. At one point, for reasons beyond me, I ended up having two accounts:

* One account required me to log in with a username, and was associated with my main email address. * The other account required me to log in with my main email address.

In a way, they were both related to the same email, but different accounts. This shouldn't even have been possible, but it seems that one was an old MS account, and the other was an old Skype account. My roster ended up being split half and half between the two.

Re: HTTPS on Your Landing Page Is Important

#224
post #138

Earlier quoted context omitted.

My citibank credit card redirects me to "cardservicesdirect.com.au" -- which reads like a phishing site if I've ever seen one. I confirmed over the phone with their support that was indeed the correct site before typing anything into it.

But did you call the support phone number shown on the dodgy domain?

T-Mobile called me back one time instead of me waiting on hold. This was after I went through the song and dance of giving the automated system my details. The first thing this representative wanted to do was, again, confirm I am who I said I was.

I said think about what you're asking for a second. Should I answer your questions? Couldn't get them to understand. Wound up hanging up and calling again and waiting on hold.

Re: HTTPS on Your Landing Page Is Important

#225
post #98

Earlier quoted context omitted.

You didn't click on a search result, you clicked on an advertisement.

A good reason to use at the very least adblock.

And to avoid Microsoft edge. Why do I have to open Windows store for an add-on to my browser? Why can't I do it from the browser like in Mozilla Firefox or in Google Chrome?

Re: HTTPS on Your Landing Page Is Important

#226

It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.

Guess what! If your financial service restricts your password to letters and numbers, it's most likely because they want you to be able to enter your password on the phone. So the passwords 'abc' 'ABC' and '222' are treated as equivalent. Try it out for fun!

I don't want to enter my password on the phone, I have fingerprint or pin in mobile banking app.

Re: HTTPS on Your Landing Page Is Important

#227
post #59
post #42

Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…

Citi has some really bad security practices, when I talked with them about it they mentioned some future changes they were planning that were even worse.

Citi just had a terrible IT team. Their website is always broken and their back end computer systems, until recently, were filled with reward loopholes.

Re: HTTPS on Your Landing Page Is Important

#228

Earlier quoted context omitted.

But did you call the support phone number shown on the dodgy domain?

T-Mobile called me back one time instead of me waiting on hold. This was after I went through the song and dance of giving the automated system my details. The first thing this representative wanted to do was, again, confirm I am who I said I was. I said think about what you're asking for a second. Should I answer your questions? Couldn't get them to understand. Wound up hanging up and calling again and waiting on ho…

Ha, same thing happened to me with Vodafone. Some guy called having some nice upgrade to my account. For some reason, to check something, he said, I need your online password. I said, wait, you call _me_ and want my password too? If I call you, tell I am from your bank and I need your PIN, would give it? Well no, came the reply. Then...

Obviously I terminated the conversation.

Re: HTTPS on Your Landing Page Is Important

#229
post #205
post #32

I'm not really surprised, UK banks are absolutely terrible in terms of their product and even worse in supporting clients having valid points. Another example would be MetroBank that recently changed password prompt to a masked password prompt (in addition to already existing masked PIN alongside) ignoring the research proving its a horrible user experience and in fact lowers the security or (not a bank, but still ma…

When I was with Three they had a phone password which was not the same password as my online account password. I have nothing informed to say on the security of this approach, other than that asking customers for their online account password would be completely unacceptable in all circumstances, and shouldn't even be helpful because as we all know passwords should not be stored in a reversible format.

Giving them the benefit of the doubt, if they're asking for a phone password, hopefully they're just keying it into their systems for verification against a hash, not manually comparing to a plaintext copy.

Re: HTTPS on Your Landing Page Is Important

#230

It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.

Your bank password is probably not even case sensitive: http://www.zdnet.com/article/surprise-online-bank-passwords-...

Offenders: Wells Fargo, Chase, American Express, Fidelity, ....

Post reply on HN