5 ms·
The worst offender I have seen in the wild is treasurydirect.gov. The password must be click in on an online keyboard, and they do not allow password managers t
by Apylon777 8y ago
The worst offender I have seen in the wild is treasurydirect.gov. The password must be click in on an online keyboard, and they do not allow password managers to enter the passwords.
Screenshot here: https://en.m.wikipedia.org/wiki/TreasuryDirect https://en.m.wikipedia.org/wiki/TreasuryDirect
- dave5104 8y agoAnd here I was thinking that sites not allowing copy/paste on password fields was the worst atrocity...
- reaperducer 8y agoCitibank is bad, too. It uses some kind of JS trick to replace usernames and passwords with asterisks, and you end up with all kinds of invalid information stored in your password manager.
- c17r 8y agoI currently use BitWarden (LastPass previously) and neither have had a problem logging into Citi's website though it's been quite some time since I tried to add a new entry from their site.
- IggleSniggle 8y ago+1 for BitWarden. For anyone reading this unfamiliar, it's an open source password manager with all the usual features (including iOS Fingerprint enabled client etc, shared group passwords), but the server is also open-source, and you can host your vault on your own server. It's free for individuals/families, supported by Enterprise licensing (or you can roll your own).
- deleted 8y ago[deleted]
- pc86 8y agoI would think the fix to this would be manually entering the credentials into the password manager rather than having it read the credentials from the site.
- ArrayList 8y agoCitibank absolutely sucks for overall UX. Have they ever heard of input type="password"?
- photoguy112 8y agoChase beats Citybank - they ask for a case sensitive password but dont care about case sensitivity when entering your password.
- CharlesColeman 8y agoI'm guessing that was implemented to neuter keyloggers, but I do wonder how easy it would be to circumvent.
- donatzsky 8y agoEasy. Just log mouse coordinates and take a screenshot.
- MichaelDickens 8y agoIt's actually even worse than that: they keys on the virtual keyboard are displayed in a random order instead of QWERTY.
- FabHK 8y agoWell, that's better though. So even if there's a key logger and mouse click recorder on your machine, one cannot recover your password. Though, if your machine is that compromised, might as well have a screen recorder, too. Though that would create more outgoing traffic.
- jiveturkey 8y agodon't need a screen recorder. the keycap images are trivially machine readable. this technique is actually good if implemented correctly -- with secure display where the host OS cannot read the image data. some predecessor to SGX whose name I don't recall had this feature. the idea is to enter a PIN though, not a friggin password. treasurydirect seems to have only taken away the trivial aspect of it without understanding the underlying reasons and details. you know, like what most companies do with Agile.
- darkhorn 8y agoThis means that they don't use 2FA. In Turkey 2FA is mandatory for all banks, via SMS or app on the phone.
- why-el 8y agoWell I face this everyday with apps in my TV and playstation. Want to log in to your EA sports account? Here is a keyboard and type away. I usually have to open 1Password, make the password's font giant, then proceed to type. Dreadful.
- jeffmk 8y agoThe flow can be even more complicated: 1. "Does your account number begin with a *letter*" <- click link 2. Paste Account Number 3. One-time passcode emailed to you 4. Copy OTP from email 5. Paste OTP into site 6. Use onscreen virtual keyboard to enter password (readonly field; no pasting allowed) Opening up devtools and deleting the `readonly` attribute does allow you to paste from your password manager of choice without further hassle.
- xbryanx 8y agoA NON-QWERTY keyboard at that. With random number arrangement? That's insane.
- humblebee 8y ago> A virtual keyboard, with keys that display in random order, is available to deter others from learning your password. This is a weird way to describe keyloggers if that is actually what they are talking about. The random order I don't understand either unless the "keylogger" is also recording mouse positions. Otherwise, if this is actually talking about over shoulder lookers it probably has the exact opposite effect because of the increased time require to enter a password.
- astine 8y ago"The random order I don't understand either unless the "keylogger" is also recording mouse positions." I would bet that that is exactly what they are worried about. This seems to me to be a really hacky way to solve that problem. If you actually need to address the possibility of keyloggers then some sort of 2FA setup would be simpler, more standard, would address a wider variety of potential security problems, and would create less friction for the user.
- discreditable 8y agoIt sounds like they learned password security from Runescape.
- ben_jones 8y agoThe irony is that if someone managed to install a keylogger, they could've installed any other RATing tool such that the machine itself and everything it touches it completely compromised.
- Cpoll 8y agoI imagine 99% of keyloggers are the 'put this on as many machines as possible and look for worthwhile logins' type, which are well-thwarted by this approach. Anything more bespoke than that is probably much rarer.
- dddddaviddddd 8y agoMight not necessarily apply to a hardware keylogger, which an attacker might use to reduce the risk of detection in software.
- deepspace 8y agoThere is a South African bank (absa.co.za) that not only uses the online keyboard thing, but requires you to type in a randomized subset of your password. For example. if your password is "Password" it would display something like 257 and you are need to type "awr" (the 2nd, 5th and 7th letters of the password) to log in.
- torstenvl 8y agoUnless they're storing hashes of every combination of characters in your password... seems pretty indicative of them storing the password in plain text.
- lucb1e 8y agoWhich is not that big a deal if you have a password manager with unique, randomly generated passwords. Exactly the scenario they're preventing... And just in case it's not a joke, storing hashes of every subset is laughably easy to crack so that's plaintext-equivalent.
- darkhorn 8y agoIf hackers have access to the database of the bank then there is more serious issues than your password.
- freewilly1040 8y agoWhoa that's bad! "Does your account number begin with a [letter]?", Where letter is a link. It's like a riddle.