18 ms·
HSBC has this really odd system where they only ask for the (e.g.) 1st, 6th, and 7th characters of your password. That implies that they store plaintext or some
by mng2 10y ago
HSBC has this really odd system where they only ask for the (e.g.) 1st, 6th, and 7th characters of your password. That implies that they store plaintext or something reversible...
- elsurudo 10y agoNot necessarily – they could be hash + salting multiple permutations
- Strilanc 10y agoNo amount of salting is going to make a 3-character recognizer secure.
- wlievens 10y agoThe 1, 6, 7 is random
- Retr0spectrum 10y agoThat's irrelevant.
- yk 10y agoThe problem is, if you have a bunch of partial passwords 1, 2, 3; 1, 2, 4; ... you can just brute force three character combinations of the passwords, which just takes something half a second (times the number of rounds) if you write your password cracker in bash. So your complexity goes from 52^n for a n character password consisting of lower and upper case to n/3* 52^3 which is a lot more manageable.
- OJFord 10y agoBut three strikes and your out - out to the physical bank with proof of ID to change it.
- MereInterest 10y agoYou're assuming that the verification is being done by the bank itself. This is under the assumption that there has already been a security breach. The password database has been stolen, and has just been sold to the highest bidder. In that case, there is no lockout.
- coldcode 10y agoNot if they steal the database. No matter how you limit the external access you also have to protect against people with unlimited time with a copy.
- ATsch 10y agoThat is nice and all, but the scenario we are talking about is a db compromise, in which case any rate-limiting is circumvented.
- Dylan16807 10y agoThat defense also works for plaintext passwords. Tell me why plaintext password storage is bad, and you'll defeat your own argument.
- deleted 10y ago[deleted]
- cheatdeath 10y agoPresumably in case someone is watching you type in your details.
- duiker101 10y agoLloyds UK has a system that I quite like, you have your credentials and then to login they ask you 3 random letters of another password that you select from 3 dropdowns. This way you have your password that is presumably secure, and you have this thing which is pretty fast to complete once you get used to it, that should help with people looking at you or keyloggers.
- reitanqild 10y agoAround here every bank require 2fa for logon and then again for signing payments (although you can queue and batch sign a number at a time. )
- semi-extrinsic 10y agoBarclays in the UK does 2fa if you order it, otherwise this strange bit with just parts of the password. They also have the most complicated 2fa I've seen. You get a pocket-calculator-like device where you need to insert your card (chip and pin type), then you enter your personal code, and then you do a challenge-response thing where you enter a code generated from the website into the device, and it responds with a number you have to type into the website. They also have this anti-paste function that was triggered by me typing too fast.
- jorams 10y ago> You get a pocket-calculator-like device where you need to insert your card (chip and pin type), then you enter your personal code, and then you do a challenge-response thing where you enter a code generated from the website into the device, and it responds with a number you have to type into the website. Such a thing is rather common in The Netherlands, though it's often not a second factor but just the way you log in to online banking. It avoids having you remember yet another password, instead you just use the same card and PIN you need "offline". Side note: At the end of 2014 Rabobank (one of the banks with such a system) replaced those devices (which they called "random readers") with "Rabo scanners", which have a built-in camera to automatically read an image from the website instead of having you manually enter a code.
- DroidX86 10y agoThey could be extracting the 1st, 6th and 7th characters, concat them and storing the hash (+salt) of the resulting string. That way they can check equality without storing the plaintext password. You could extend this by storing the hash of all 3-letter combinations of the password on entry. Then ask for a random combination of 3-letters.
- StavrosK 10y agoYou realize that this is trivial to brute force, though.
- taneq 10y agoNot when they'd presumably lock the account for some period of time after a few failed attempts.
- jsn 10y agoPassword hashing is used to prevent the brute forcing when the attacker already has the copy of the password database, and is free from any failed attempt limits and timeouts. And in this case storing hashes of all 3-letter combos is basically useless, since all those hashes are very easy to bruteforce.
- cosecantt 10y agoCan't it be achieved by this simple steps? Consider ur password is y. a) f(y, i) = a func that gets i'th character of a pass. y; b) hash(x) is ur hashing func; c) x0 = hash(y); d) concat(a, b) - concatination func; 1. x1 = hash(concat(f(y,1), x0)); 2. x2 = hash(concat(f(y,2)+x0)); . . etc Store in DB id position hash user_id 1 0 x0 1 2 1 x1 1 3 2 x2 1
- taneq 10y agoAh ok, so you're starting from the assumption that the site has already been owned and the attacker has the hashed passwords. In which case yes, it does make it easier.
- twic 10y agoThe Co-operative Bank does this too. They absolutely store the password in plain text, because if you phone up, you have to tell the whole thing to the phone operator. To be fair, they're right in the middle of rolling out a new banking site which I think has proper passwords. The current system is a holdover from when they only had phone banking.
- deleted 10y ago[deleted]
- tamana 10y agoThat does not mean they store plaintext passwords. When you login to most any website you have to submit your whole password. It is usually hashed and the hash is compare to the stored hashed pasword
- twic 10y agoFrom my conversations with the telephone banking operators, it's clear that they have the plaintext password in front of them.
- JupiterMoon 10y agoOn the other hand a publicised password leak from a major bank would be the end of the bank whether they stored passwords hashed or plaintext.
- makomk 10y agoYes. This is to protect against attackers obtaining your full plaintext password on your end, for example by phishing or installing keyloggers. In practice this is a much bigger security threat in the online banking world than someone doing the same by compromising the bank's systems - even if that were to happen they can easily re-verify your identity and issue you with a new password, and you really shouldn't be using the same password elsewhere.
- MereInterest 10y agoPhishing is a much bigger security threat, but is a much less harmful one than having the password database stolen. It sounds like they are trying to minimize the day-to-day risks, at the expense of maximize the damage of a catastrophic event.
- kybernetikos 10y agoAll the systems I've used that do this make you have two passwords, only one of which they are storing in a reversible way.
- makomk 10y agoIf the password database is stolen somehow, that probably means that the bank's online banking systems have been compromised. Having the password database stolen is likely to be the least of their worries at that point.
- chris_wot 10y agoHow does this prevent key logging attacks? You still type in those characters. And secondly, that just immediately made it a hell of a lot easier to brute force your way through the passwords!
- k-mcgrady 10y agoIt asks for different characters from the password each time. So it'll ask for the 1st, 4th, and 5th characters. Next time you go to login it'll ask from 2nd, 8th, 14th. So a key logger is only getting a small portion of the password each time.
- signal11 10y agoHSBC doesn't do that any more for me -- they've moved to a Google Authenticator-like 2FA approach[1], but Lloyds[2] does - they have one username and password, and a "memorable phrase" which they clearly store as plaintext because ask for the xth, yth and zth character as a secondary security measure. Lloyds tech folk reading this -- please consider fixing this. [1] http://i.imgur.com/QCGPDWz.png http://i.imgur.com/QCGPDWz.png [2] http://i.imgur.com/VdtGC4T.png http://i.imgur.com/VdtGC4T.png
- Tenoke 10y agoSame for Natwest, but this does not mean they store it in plain-text.
- justsid 10y agoI have the memorable phrase and have to use the HSBC app for my password. Now, the fun thing is that my actual HSBC password is 40 characters randomness, so pretty secure. The mobile password that is used to derive the 2FA key must not be longer than 8 characters. So essentially I traded a long and secure password for an 8 character password. I really really dislike HSBCs online banking as a whole, the password system plus the constant “We encountered an error, please try again later” messages.
- oneeyedpigeon 10y agoPlus the unintuitive navigation, the ridiculous over-skeuomorphism of 'past statements', and the insanely-low, seemingly non-configurable session timeout. At least you can finally use a payment reference > 10 characters, but HSBC's online banking is still stuck in the stone-age overall.
- hobs 10y agoWhy cant they just also hash those three letter combinations they ask you? Not nearly as secure but I see many people saying that the plaintext must be stored to achieve this, and all I am thinking is that it would require you to store multiple hashes for each user, each a portion of their password. Still a lot easier to guess a portion of a password than a password, but it doesnt follow in my mind that it is definitely in plaintext.
- wtracz 10y agoThey can use Shamir's Secret Sharing to achieve this with no plaintext. see http://willtracz.co.uk/shamir-secret-sharing-and-passwords http://willtracz.co.uk/shamir-secret-sharing-and-passwords
- nxzero 10y ago>> "This post is intended to introduce concepts and practically demonstrate a method. The implementation provided is not a reliable/hardened solution (i.e. there are vulnerabilities because finite fields are not used) and should not be used anywhere near a production system." Above is on the page you're linking to.
- wtracz 10y agoYes, I wrote it and it is intended as a demo only. I have not put in the finite field logic in that implementation. It shows the concepts though.
- PepeGomez 10y agoOr the answers are premade when the password is created.
- geoelectric 10y agoNot necessarily. It might actually store multiple versions of your password as A.....B...C (where . means some known-to-them character, basically salt), ..A....B.C., etc, basically all the combo-of-3 templates encoded as PWs. Then it asks for one of them and recreates the template before comparing. Still crappy entropy, though. An eight char password has 56 combinations of 3 positions each, so with N character choices that's 56 * N^3 vs. N^8 the normal way. Gets much worse in comparison with longer passwords.