Live data from Hacker News

Schwab password policies and two factor authentication

jeremytunnell.com

71–80 of 127 posts

Re: Schwab password policies and two factor authentication

#71
post #61

Earlier quoted context omitted.

You are factually incorrect that the passwords are case insensitive.

Verified, mine is case-insensitive. If phone-keypad-password-entry is a requirement, then that makes sense.

Im confused, are you verifying that the passwords are or are not case sensitive? Mine is certainly case sensitive (watch me get hacked now, 8 characers, one is capital!)

Re: Schwab password policies and two factor authentication

#72
post #45
post #29

8 digits password... It sound like DES encryption stored directly in the database. (This is pure speculation of course) This alone is a huge red flag. Adding the fact that the 2 factor auth. is broken is not a good news.

I think you mean DES based crypt and not DES encryption.

Yes that's what I meant, thanks.

Re: Schwab password policies and two factor authentication

#74

After receiving unsatisfactory responses from my local Schwab rep here in New York and the customer service staff, I complained to Schwab's CISO, Bashar Abouseido , on September 1. He never replied.

Ahh, but he only reads the first eight letters, so all he got from your email was "Greeting"

it was either GREETING or greeting since it's case-insensitive

Re: Schwab password policies and two factor authentication

#75
I pointed this out to them over a year ago: http://norcie.com/2013/09/01/schwab-unsafe/

I went to far as to get in contact with senior staff members at Schwab to alert them to the issue, and got a pretty condescending response.

I mentioned it to a friend at a burrito truck outside the Mozilla office, and soon found out it was a top post on /r/personalfinance.

I got a call from Schwab shortly after that. But the rep I talked to just said they were "working on" allowing more characters in the password.

I must say though, this post does a great job detailing their 2F solution. I never set it up since it seemed like wearing a fishnet condom given the rest of their security, so I never got to see how bad it is.

Re: Schwab password policies and two factor authentication

#76
post #63

> I've never, ever seen this "append stuff onto your password" approach being used. Then he doesn't have an eBay or PayPal token, because they both do it. Or rather, it is an option to do it that way, in order to skip over the "submit, enter token, submit" workflow. https://www.paypal.com/us/webapps/helpcenter/helphub/article...

It's worth noting that some of the two-factor systems that integrate with RADIUS also use this same method, where you can't control how the end system prompts users to authenticate.

Re: Schwab password policies and two factor authentication

#77

I just called Schwab about this, and hand to whatever deity you believe in, this is what he told me: Representative: "One of the things we were trying to do with these passwords was make them different from other providers. So we know that they allow multiple character types, and are case-sensitive, so we decided to make them different. That way, you can't use the same password you've used elsewhere and it kind of fo…

"you can enter any arbitrary text afterwards is so that if someone is looking over you shoulder they can't tell that it only accepts 8"

Except it is public knowledge that there is an 8-character limit. Very basic footprinting would make it clear to only pay attention to the first 8 characters.

Re: Schwab password policies and two factor authentication

#78

I just called Schwab about this, and hand to whatever deity you believe in, this is what he told me: Representative: "One of the things we were trying to do with these passwords was make them different from other providers. So we know that they allow multiple character types, and are case-sensitive, so we decided to make them different. That way, you can't use the same password you've used elsewhere and it kind of fo…

I love the arbitrary restrictions that all these sites come up with that ultimately make them less safe. Yesterday I was setting up some stuff for somebody who knows nothing about tech. IIRC it went like this: * Google: no restrictions, as far as I could tell. * Apple: password not accepted because it MUST contain at least one uppercase letter. Of course, simply knowing that one of the characters MUST be an uppercase…

Let's not get crazy here: knowing that one of a variable number of characters is uppercase does decrease the keyspace, but it's definitely not a "significant" reduction.

The main problem with restrictions like that is that it complicates the UX by requiring somebody to tweak their password manager's generator or its output to match the bogus restriction.

Re: Schwab password policies and two factor authentication

#79

Quite shameful. Fortunately, I only use Schwab because of their awesome checking account that covers ATM fees. Definitely won't put more of my assets in there until they get their act together. I may be wrong, but I think user IDs can be longer than 8 characters too which makes this all even worse. LinkedIn did something similar with having to append your auth token to the end of your password, but they actually chec…

I also only keep a bit in it for travel. The rest is in a different account. When I want to deposit funds, I write myself a check from my credit union, or deposit a reimbursement check.

(I travel a lot for work so I get reimbursement checks frequently)

Re: Schwab password policies and two factor authentication

#80
I had pretty much the same experience with Virgin Mobile last year (passwords limited to 6 digits, no brute force protection). I finally told the guy I got escalated to that if they didn't do anything I'd call the NY Times, Consumerist, Gawker, CNET, Ars, etc and tell them about it.

They didn't do anything, so I sent around the article and pretty much every publication I sent it to ran with it. After that they took down the login page for about nine hours and brought it back up with brute force protection.

https://kev.inburke.com/kevin/open-season-on-virgin-mobile-c...

Post reply on HN