4 ms·
Tesco ask you to log on with "character 2 and 4 from your password" which sort of implies they must store the password in clear text (unless some kind of zerokn
by simonvc 10y ago
Tesco ask you to log on with "character 2 and 4 from your password" which sort of implies they must store the password in clear text (unless some kind of zeroknowledge/homomorphic encryption magic i've not heard of.)
- nrki 10y agoThis is pretty standard for UK banks. They'd do a hash of each character of the password (in Lloyds' case, your "memorable word" combo), to compare your entries to.
- benkuhn 10y agoWait, that's still awful! It allows you to crack each character individually. For instance, a 10-letter password requires 26^10 ~= 1.4e14 attempts to test every option if you only have a hash of the full password, but only 10*26 = 260 attempts to test every option for every individual character.
- brassic 10y agoI have to use two passwords to login to Lloyds bank. One conventional password (which is presumably stored salted and hashed) and one where I have to enter characters from three positions they choose. The latter is intended to mitigate the risk of using your account from a vulnerable computer. The former takes care of vulnerabilities on their end (as far as any password can).
- Symbiote 10y agoCould they implement something like: Password: money Secret word: ABCD If they're going to ask for two characters from the secret word, they could then hash saltmoneyAB saltmoneyAC saltmoneyAD saltmoneyBC saltmoneyBD saltmoneyCD and check against the relevant one.
- nrki 10y agoI may be incorrect on the "hash each letter individually" part. But this is combined with a password.
- joncrocks 10y agoDepending on the length of the password, it's possible to encode/hash (+salt) all possible outputs of challenge combinations at the point of storing your password. It's a bit like having a number of related passwords, which the bank can ask you for any of them, and then verify is correct.
- deleted 10y ago[deleted]
- 283894 10y agoThat is not the password though. They call that the 'Security Number'. After entering the two digits of the 'Security Number' you then receive a 'One Time Access Code' through a text or phone call, although I have never logged in to my account before, and seem to be unable to get past this step now. I think you then enter your proper password in, which I would hope is not stored in plain text, although the article I linked seemed to imply this was the case back in 2012.
- 21 10y agoI have an account at Metro Bank in UK. One day I was on the phone with them, and to authenticate myself they asked me for characters 2/4/7 from the password. At the same time, they advise you to never give your password away, and that they will never ask you for your (full) password. Talk about a mixed message...
- asdf23 10y agoMost UK Banks use HSM modules to store 'pins' (Similar process to Apple with iCloud) which remain separate to passwords which are hash + salted