Live data from Hacker News

Schwab password policies and two factor authentication

jeremytunnell.com

91–100 of 127 posts

Re: Schwab password policies and two factor authentication

#91
post #20

I complained to Schwab about their password policies numerous times over the 3 years I was a bank/brokerage customer. A few months ago I finally moved my accounts to TD. Schwab's standard response was 1) to assure me that they had "intelligent" fraud monitoring systems on their backend and 2) to offer me a hard token, which would have been a pain and may have caused issues with Mint.

> A few months ago I finally moved my accounts to TD.

You'll be back to Schwab before you know it. TD are beyond awful. Schwab have pretty much the best customer service going.

Re: Schwab password policies and two factor authentication

#93
I'm guessing that if they had a major breach because of this kind of idiocy, they'd find a way to fix it after the fact.

Which sort of implies to me that they should find a way to fix it before they have a big breach.

If nothing else, the fact that they've been warned repeatedly and done nothing could be pretty compelling if there was ever litigation over losses.

For example, I could imagine someone successfully disavowing a trade at Schwab because they don't enforce the password authentication they claim to, and thus can't convincingly claim that the trader was in fact the account owner.

Re: Schwab password policies and two factor authentication

#94
post #71

Earlier quoted context omitted.

Verified, mine is case-insensitive. If phone-keypad-password-entry is a requirement, then that makes sense.

Im confused, are you verifying that the passwords are or are not case sensitive? Mine is certainly case sensitive (watch me get hacked now, 8 characers, one is capital!)

mine is case-insensitive

It is possible there are more than one schwab interfaces that behave differently. I have two entry points. One for just 401k (https://www.schwabplan.com). That one has long case-sensitive passwords.

The brokerage account(https://client.schwab.com) is short and case-insentive

Re: Schwab password policies and two factor authentication

#95

Like many others, I just filed a support ticket as well. I'd like one of two outcomes: 1. A public response and plan from Schwab, or 2. An alternative bank/brokerage company that a) takes security seriously and b) is easy to move to.

Here's how my rep replied to my email today:

"Schwab takes online security very seriously, and all clients are protected against fraud with our SchwabSafe guarantee. This guarantee is available to review online at www.schwab.com/schwabsafe.

"I reviewed the website you referenced in your email, but this is well outside my area of expertise. To discuss these items, I would suggest you contact our Technology Support Group at the Help Desk. Their number is 800-433-9196."

Uh, no. I'm not going to sit on the phone waiting to tell your Help Desk about why they shouldn't store my password in their DB; that's your fuckin job. I'm much more inclined to spend that hour and a half moving my accounts somewhere secure.

Re: Schwab password policies and two factor authentication

#96
post #11

Banks aren't technology companies. Someday a technology company will become a bank.

http://www.businessinsider.com/bank-it-spending-2012-12 The banking system functions largely on the choice, application and integration of technology, and banking is more of a technology business than just about any other. And let's be fair here - Schwab is not a bank, and even among investment firms is an outlier with the noted bad practices.

How about the part of Schwab that's literally called "Charles Schwab Bank"?

Re: Schwab password policies and two factor authentication

#98
I've been coming to an opinion on these issues that may be unpopular with the tech crowd: The big banks have the right idea when it comes to security, and we are misguided at best with our obsession over the minutia of password handling.

Why? All of these big banks and investment houses have holdings in the neighborhood of billions of dollars. Like billions in actual cash. If they are so vulnerable and insecure, why aren't all of the hackers targeting them, with their potential upside of billions of dollars in cash, and instead target little web apps to steal some credit card numbers or user data, worth tens of thousands to maybe a few million on black markets? Think about how much effort we've seen put towards stealing cool Twitter handles and other such trivial things. Does anybody really believe that there aren't many more people working much harder to hack banks, with their billion dollar paydays?

They may not be the greatest on password handling, but the evidence suggests that they have a much more healthy security culture overall than your average internet startup. Apparently, they are worlds better at making their systems secure enough that nobody can steal these user databases in the first place. They most likely also have a pile of fraud detection and validation on account activity, especially anything involving moving significant amounts of money out of the accounts. They are probably in the right on this - what's the point in building a perfect lock for the front door if, once an attacker gets in, they can transfer the whole balance to a Russian bank and nobody will notice? Consider how, with some well-publicized recent hacks, you can apparently do anything at all once you get through that front door at most major tech companies.

I'll happily change my tune if any of these banks get hacked and lose big money. Until then, maybe we should ask these banks how they get it so right overall instead of worrying and hassling them about how long their passwords are and how they're storing them.

Re: Schwab password policies and two factor authentication

#99
post #97

How do the other big consumer trading services compare? i.e. Vanguard, Fidelity, etc?

I used to have my retirement accounts at Fidelity. One day I needed some assistance with something I was seeing on their web UI, so I called them up. The support person said (not an exact quote, but the gist), "in order to see what you're seeing, I'm going to need to log in as you. I need your permission in order to do that. Security precautions prevent me from being able to see your password, so I will need to change your password to a temporary password of '123456fidelity' to proceed. Is this ok?"

I was kind of speechless, but I said, no, that's ok, I've decided I don't need help anymore, and shortly thereafter I closed all of my accounts. I've moved to a smaller firm where I've specifically asked for my accounts to be inaccessible from the internet in any way, and I have a financial advisor assigned. If I need something done, I can call him or his assistant. I can't make big financial moves at the click of a button, which suits me just fine.

Re: Schwab password policies and two factor authentication

#100
post #77

I just called Schwab about this, and hand to whatever deity you believe in, this is what he told me: Representative: "One of the things we were trying to do with these passwords was make them different from other providers. So we know that they allow multiple character types, and are case-sensitive, so we decided to make them different. That way, you can't use the same password you've used elsewhere and it kind of fo…

"you can enter any arbitrary text afterwards is so that if someone is looking over you shoulder they can't tell that it only accepts 8" Except it is public knowledge that there is an 8-character limit. Very basic footprinting would make it clear to only pay attention to the first 8 characters.

Right it would only work if they happen to start looking at you type after you started typing, in which case they wouldn't have your full password any ways.

But in the case they see the full thing, they would write in down, go to try it, maybe type out the whole thing without even noticing there was a restriction, type ok, and bam there in. If they do notice the password could only hold 8 chars, what are the odds they wouldn't try what they have for the hell of it?

The dude must have been talking out of his behind.

Post reply on HN