4 ms·
About 8 years ago Natwest had a policy of having a "browser whitelist" which was rarely updated. Each time a security update for chrome or firefox came out it w
by 4rt 9y ago
About 8 years ago Natwest had a policy of having a "browser whitelist" which was rarely updated. Each time a security update for chrome or firefox came out it would be 2 weeks before online banking was accessible, and using any pre-release versions were out of the question.
I complained and a member of the dev team phoned me up and after a long discussion about why this was madness he told me that it was better to use older browsers for important things such as online banking (like IE6 which was in their whitelist) because they're tried and tested.
- adenta 9y agoWhen I worked for Chase on their main app, the policy for support was the current version of the browser, minus one.
- foobarbazetc 9y agoTo be fair Chase seems (on the surface) to have the best site/app/whatever of the major US banks. The app is pretty great.
- DaiPlusPlus 9y agoExcept for the unnecessary 5 second wait when accessing chase.com for the login prompt to appear.
- foobarbazetc 9y agoI just go direct to chaseonline.chase.com . It’s not pretty but it’s quick. :)
- bubblethink 9y agoChase doesn't like chromium. It'll randomly load a mobile page if your user agent string is chromium. Not to mention, none of the US banks allow standard 2FA (TOTP). If they have 2FA at all, it'll be SMS.
- foobarbazetc 9y agoI think there’s some way to get a hardware token from Chase (no idea who you’d call about that) but you’re right, that part annoys me.
- astura 9y agoWhat? Chase.com is horribly bloated. It takes a good 25 seconds to load. (I measured) I open it in another tab and just go do something else.
- astura 9y agoAlso their passwords are not case sensitive (try it yourself)
- TallGuyShort 9y agoReminiscent of Amex's password policy (at least what it was a few years ago): can't use punctuation in your password, because those keys are less frequently used, and using them frequently in passwords will cause visible wear on the keys, indicating to an attacker with physical access to your keyboard which punctuation characters are in your password. Trying so hard, but failing so badly.
- toomanybeersies 9y ago"we require passwords to be a maximum of 8 characters, because if they were longer, people would forget them, and would have to write them down" I'm sure that has been said by some manager somewhere.
- Klathmon 9y agoNot that it's an excuse, but I've personally seen many "technology averse" people struggle with the changing "rules" about passwords. When they started using computers, they were taught to NEVER write your password down and to do things like replace letters like I with numbers like 1 for security. Not only are those not true any more, but the opposite is recommended. Making a unique LONG password is much more important, and writing it down on a sticky note next to your monitor is arguably more secure from some threats than even something like LastPass.
- TallGuyShort 9y agoWell a lack of rules (but a list of recommendations, perhaps) would be a solution there, not a maximum of 8 characters. Maximum password lengths just screams out to me that they're not hashing and just storing passwords directly in a database with a fixed-size column for passwords.
- Klathmon 9y agoOh I absolutely 100% agree, I just wanted to point out that sometimes a lot of these seemingly crazy reasons come from somewhere, and that as developers that might work with product managers like this, it's our job to help teach them. But maximum lengths (that aren't measured in kb) are a monumentally stupid thing, as are most other password "rules" (No, disallowing words in your password is not a good idea...) Provide a minimum length, and check passwords against common password lists, and use a damn good hashing algorithm with a process in place to easily allow upgrading that hash.
- seanalltogether 9y agoFor some dumb reason the Bank of America website is ok with firefox on windows, but throws up a big red error message when you try to use firefox on mac. https://www.bankofamerica.com/information/supported-browsers/?m=unsupportedBrowserType https://www.bankofamerica.com/information/supported-browsers...
- flyinghamster 9y agoOh, God yes - the same on Linux. I'm thinking that what I ought to do is go down to my local BoA branch and discuss (and demonstrate!) this to their branch manager. I can't help but feel I'd just get a brush-off if I tried to deal with this online or over the phone.