3 ms·
CapitalOne.com also authenticates without case sensitivity.
by elbrian 10y ago
CapitalOne.com also authenticates without case sensitivity.
- saltedshiv 10y agoalso Chase.com
- develprofthngs 10y agoI noticed this issue on Wellsfargo as well. I did some research and learned it is due to being backwards compatible with phone banking. No shift key on the telephone.
- giarc 10y agoCredit card accounts with Bank of Montreal (one of Canada's largest banks) allows for a password of exactly 6 characters. No more, no less.
- zwerdlds 10y agoCapital One, at least at some point in the past, was storing in plaintext - they had a "what's the fourth character in your password" check. At least in this thread, people seem to be giving FB the benefit of the doubt on that particular anti-pattern. Can anyone rule out plaintext storage?
- joatmon-snoo 10y agoDuring my new grad interview there I was made privy to some very questionable security decisions that they mentioned linked to PCI-DSS, but nothing on this level. Edit: PCI compliance rules out plaintext storage so it seems unlikely. It's worth noting that plaintext storage might not be the case if they store the fourth and only the fourth character separately at encryption time.
- davis_m 10y agoThe only people that can positively rule out plaintext storage are Facebook engineers, which are generally competent, especially with something as simple as storing password hashes.
- tveita 10y agoThey've been pretty open about how they store passwords and it's definitely not plaintext, here's a talk about it: https://video.adm.ntnu.no/pres/54b660049af94 https://video.adm.ntnu.no/pres/54b660049af94 My outside impression is that security is taken seriously enough at Facebook to hire highly competent people to run it. They pay out bug bounties, and run internal red team exercises to test their own ability to detect and react to a compromise. https://threatpost.com/how-facebook-prepared-be-hacked-030813/77602/ https://threatpost.com/how-facebook-prepared-be-hacked-03081... I think we can extend them enough benefit of doubt to rule out storing user passwords in plaintext.
- adders 10y agoHSBC UK silently truncates passwords to 8 characters :-( https://twitter.com/HSBC_UK_Help/status/579661876017139713 https://twitter.com/HSBC_UK_Help/status/579661876017139713
- thatwebdude 10y agoI bet I know what subsystem their user authentication runs on!!!!!!! (Something old)