7 ms·
I called my bank the other day and they asked over the phone for my password. This isn't a bank I often use, I only currently have a loan through them so I've n
by jordonias 11y ago
I called my bank the other day and they asked over the phone for my password. This isn't a bank I often use, I only currently have a loan through them so I've never used the login on the website. I said I don't remember setting a password. They gave me a hint about the characters in the password and I was able to remember the password based on their hint. I verbally said the password character by character and they confirmed it. This is an example of how to not handle passwords in 2016.
- nostromo 11y agoName and shame.
- deleted 11y ago[deleted]
- gist 11y agoI don't think you should out them publicly. Are you interested in having them improve their security model [1] or do you want to have what they have they done out in the open so that others can try to social engineer them and their customers might suffer the consequences? [1] If so, tell them about this in a way that will get their attention without causing their customers or them any harm.
- jordonias 11y agoYou're correct. I'll contact them.
- AstralStorm 11y agoAlways have a reasonable response deadline. For a security issue, above 1 month is unreasonable for a small deployment, above 3 months in a huge deployment in my opinion.
- deleted 11y ago[deleted]
- rms_returns 11y agoI once had to call my bank a few years ago to disable my debit card. The reason was that I inserted it in an ATM and the ATM had chosen that exact moment to malfunction and shut down! The operator on the line asked me a ton of questions starting from my user-id (but not password), date of birth, full name, father's name, place of birth, type of account and many others that I don't remember now. Only after I correctly answered all these questions, did he start acting on my instructions.
- herbst 11y agoMy bank always asks me for: Birthday, Address and last time i got how much money. The first 2 details can be easy (in my country there is a website which shows this for most people who dont know how to stop them), the third one can be easy if you stalk me a day or two. But if i tell them to not make it that easy, i cant manage my shit over the phone anymore :/
- nkrisc 11y agoI don't know much about what sort of security compliance banks must implement, but surely that's in violation of something? What country?
- jordonias 11y agoUnited States
- jensvdh 11y agoPlaintextoffenders!
- aram 11y agoI experienced this too many times with UK/US providers (e.g. Hostgator and Fasthosts). They often ask for server root password or email/password combo for the client portal, even after you verify account ownership. Seems that they don't have any other way to grant the technicians access to the server/my account, which is absolutely ridiculous.
- darkstar999 11y agoSame thing happened to me, my local credit union emailed me my password. They ensured me that they use "bank-level encryption". Of course I didn't get into the difference between one- and two-way encryption with the teller, or that email isn't secure. We live in an age where this should be unacceptable. Why aren't there financial security laws yet?
- deleted 11y ago[deleted]
- CydeWeys 11y agoIt's so infuriating because I've worked at companies doing digital commerce before, and PCI compliance and certification is quite onerous. But at the end of the day credit card numbers still aren't as sensitive as bank logins, yet there are no security standards on bank logins! It's crazy.
- scruple 11y agoPCI compliance is pretty interesting. It's been many years since I worked in an e-commerce shop but I seem to remember that it even described physical security layers i.e., dictating the placement of door hinges to server rooms.
- rtpg 11y agoGoes to show that when money is at stake for the stakeholders then things get done. I don't think banks actually care about individual user login security too much. Credit Cards reallllly suffer from security breaches though
- JadeNB 11y ago> I don't think banks actually care about individual user login security too much. Credit Cards reallllly suffer from security breaches though But the only reason that banks care so much about credit-card security breaches is that the law forces them to do so. If the law didn't make credit card fraud the bank's responsibility, then they'd be just as lackluster about preventing it as they currently are about securing login credentials.
- dheera 11y agoI also hate the stupid security questions used to identify you which they always claim "add security". In almost all cases they decrease security. Where did you spend your honeymoon? What was the name of your first pet? What is the name of the street where you grew up? For any given person, a LOT of people know the answer to these kind of questions. Also, I hate it when people use date of birth to verify identity. Medical people love doing this. Um, just check the person's Facebook and see when everyone wishes them a happy birthday, then go access their medical records?
- paulddraper 11y agoI'm not saying I disagree, but how would you verify identity over the phone?
- noisy_boy 11y agoBy allowing people to set their own questions and answers instead of a) using a pre-defined list of questions b) forming questions from information about the customer that friends/acquaintances usually know or information that can be found via a Google search.
- ecoffey 11y agoYou can still have the question. But my answer is a random 32 character string of alphanumerics :)
- dheera 11y agoI algorithmically generate the answers to the security questions with: answer = PBKDF2(hmacsha1, password + question, "", 100000, 16) This is also incidentally the basis for how I generate unique passwords for every service except banks, communication, and other sensitive things. I want a different password on every website and don't want to trust any password-remembering software I didn't write. The same function works fine for generating answers to secret questions.
- 11y ago
- mhw 11y agoBear in mind that giving the password over the phone has a different threat model to sending the password over a TLS-secured connection from your browser to a bank-run web server. Specifically there is a human in the call centre who is transcribing what you say. Using a partial password (give me letters X, Y and Z) is a way of mitigating the risk of call centre staff being able to harvest meaningful amounts of security credentials. This does mean that you need to be able to check subsets of the characters in the password, which rules out hashing the whole password in this case.
- JadeNB 11y ago> This does mean that you need to be able to check subsets of the characters in the password, which rules out hashing the whole password in this case. As you implicitly point out, however, it doesn't require any portion of the password ever to be visible to the call-centre employee; one can just supplement an individual hash by a collection of hashes of appropriate character subsets, and then (say) randomly pick among the available subsets.
- Vendan 11y agonote though, that this means you have a collection of hashes for the password that are each 3 characters or whatever long, which can be brute forced in essentially no time at all. Crack em all, lay them out according to what letters the hash is for, put it all together and you are done. Even just having 1 subset reduces your passwords security by that many letters, if not more (you can filter out dictionary guesses that don't match those letters and such)
- JadeNB 11y agoGood point. Would salting them obviate the problem?
- Vendan 11y agonope. Salt is good for eliminating rainbow tables and similar vectors. At this level, let's just say you go after uppercase, lowercase, digits and 20 different symbols, (a total of 82 letters) you'll wind up with 551,368 possible combinations. The only way to make it "safe" would be to get a hash method that would take multiple seconds to run on good hardware. (as a comparison, I crack raw NTLM at something on the order of billions of hashes per second)
- LordKano 11y agoBack from 2009-2010, I did work as a web developer on an ecommerce site. A month or so in, I discovered that they kept all of the user password unencrypted in a database. I went to my boss and explained that we can't do that. It's inviting exploitation. He responded to me that we had to keep them in plain text, in the database so that we could send them to users who forgot. If they can't login, they won't order product. I have heard similar stories from other IT professionals. It's amazing that these operations aren't getting pwn3d twice a week.
- majewsky 11y agoUnhashed passwords don't get you pwned. They only become a problem after you've been pwned.