5 ms·
I just signed up for 2 Tesco accounts the other day to dump 3k in each for the 3% interest. I'm certainly not going to be doing anything with the accounts unti
by 283894 10y ago
I just signed up for 2 Tesco accounts the other day to dump 3k in each for the 3% interest.
I'm certainly not going to be doing anything with the accounts until Tesco give some more clarification on what actually happened (although the way these things work, I doubt there will ever be a full technical response.)
Also if it is some sort of internal breach, would any other data have been taken?
Back in 2012, Tesco were storing passwords in plain text.
http://www.bbc.co.uk/news/technology-19316825 http://www.bbc.co.uk/news/technology-19316825
- simonvc 10y agoTesco ask you to log on with "character 2 and 4 from your password" which sort of implies they must store the password in clear text (unless some kind of zeroknowledge/homomorphic encryption magic i've not heard of.)
- nrki 10y agoThis is pretty standard for UK banks. They'd do a hash of each character of the password (in Lloyds' case, your "memorable word" combo), to compare your entries to.
- benkuhn 10y agoWait, that's still awful! It allows you to crack each character individually. For instance, a 10-letter password requires 26^10 ~= 1.4e14 attempts to test every option if you only have a hash of the full password, but only 10*26 = 260 attempts to test every option for every individual character.
- brassic 10y agoI have to use two passwords to login to Lloyds bank. One conventional password (which is presumably stored salted and hashed) and one where I have to enter characters from three positions they choose. The latter is intended to mitigate the risk of using your account from a vulnerable computer. The former takes care of vulnerabilities on their end (as far as any password can).
- Symbiote 10y agoCould they implement something like: Password: money Secret word: ABCD If they're going to ask for two characters from the secret word, they could then hash saltmoneyAB saltmoneyAC saltmoneyAD saltmoneyBC saltmoneyBD saltmoneyCD and check against the relevant one.
- nrki 10y agoI may be incorrect on the "hash each letter individually" part. But this is combined with a password.
- joncrocks 10y agoDepending on the length of the password, it's possible to encode/hash (+salt) all possible outputs of challenge combinations at the point of storing your password. It's a bit like having a number of related passwords, which the bank can ask you for any of them, and then verify is correct.
- deleted 10y ago[deleted]
- 283894 10y agoThat is not the password though. They call that the 'Security Number'. After entering the two digits of the 'Security Number' you then receive a 'One Time Access Code' through a text or phone call, although I have never logged in to my account before, and seem to be unable to get past this step now. I think you then enter your proper password in, which I would hope is not stored in plain text, although the article I linked seemed to imply this was the case back in 2012.
- 21 10y agoI have an account at Metro Bank in UK. One day I was on the phone with them, and to authenticate myself they asked me for characters 2/4/7 from the password. At the same time, they advise you to never give your password away, and that they will never ask you for your (full) password. Talk about a mixed message...
- asdf23 10y agoMost UK Banks use HSM modules to store 'pins' (Similar process to Apple with iCloud) which remain separate to passwords which are hash + salted
- deleted 10y ago[deleted]