6 ms·
My bank only allows for up to 6 alphanumeric (no special!) characters. https://www.bmo.com/olbb/help-centre/en/my-profile/change-password.html https://www.bmo.
by mfoy_ 8y ago
My bank only allows for up to 6 alphanumeric (no special!) characters.
https://www.bmo.com/olbb/help-centre/en/my-profile/change-password.html https://www.bmo.com/olbb/help-centre/en/my-profile/change-pa...
- b_tterc_p 8y agoI believe this is because you may be required to enter it on a phone using the dial pad. This also means it’s secretly just 6 single digit numbers.
- walrus01 8y ago5 bucks says that's because it's stored in plaintext, no crypto, no hash, no salt, in some gargantuan ancient mainframe system database. https://www.theglobeandmail.com/technology/digital-culture/why-canadas-banks-have-weaker-passwords-than-twitter-or-google/article18325257/ https://www.theglobeandmail.com/technology/digital-culture/w...
- cperciva 8y agoYou'd lose your $5. BMO's online banking system is an outgrowth of their telephone banking system, which used 4-6 digit PINs. (Thankfully not the same PINs as used with their bank cards though! Or rather, each card had two PINs, one for use as a card and one for use with telephone/internet banking.) I'm sure they're all stored in plaintext in an ancient mainframe system, but that's not the reason for the odd requirement.
- Scooty 8y agoWhy is this such a common thing? Just about every bank I've used has had one of these issues on their website: - Password can't be long - Password can't be pasted - Password must contain symbols - Password can't contain symbols I even locked myself out of my credit card (AMEX) account 3 times in less than 2 days because they have multiple different password reset forms, but one of them doesn't enforce their password length limit, so I successfully set my password to a password that was too long for the web/mobile login forms.
- ska 8y agoWhy is this such a common thing? Short answer I suspect is old systems with complicated dependencies.
- lwansbrough 8y agoEven so, you could hash the password somehow in order to produce the number, which then goes into that old system.
- ska 8y agoThere are always engineering solutions to such things, but I don't think most of the decisions are made in terms of "it's possible". There is always a risk/reward conversation, and a lot of conservatism in systems currently processing a large number of transaction and/or $ successfully. Perceived risk may or may not be analyzed correctly, mind.
- mavhc 8y agoYou'd think when they have all the money the risk would be really high
- tuzakey 8y agoIn my experience with banks that did this it was to allow a mapping to 10digit keypads for bank by phone access. I haven't tried it recently, and they allow complex passwords now. When I noticed this several years ago I was able to log into my bank account via the website with the 10digit equivalent password. At least your bank balance is insured...
- ben509 8y agoFinance is worse than most industries because financial institutions grow by acquisition. You make money by managing customer assets of some sort, so you're constantly buying up smaller companies, and the main corporation is this frankenstein's monster of smaller companies. Not only does anything digital has to be transferred over, but often customers have to be persuaded to agree to new terms, which is obviously a long, complicated process. They also have legal legacy as the government will always grandfather old accounts when the law changes. So the banks may have special accounts that are obsolete but a few customers like the perks, that could live in an old system of their own. Plus there are various deals they've made over time that might restrict one part of the company from doing some activity, any kind of international stuff is a total mess, it goes on. All this means they have a ton of duplication and are constantly trying to merge their internal systems, on top of the normal awfulness of any non-tech company trying to do technology.
- cabaalis 8y agoMicrosoft will not let me go past 16 on my O365 email. Msft employees: change this!
- aczerepinski 8y agoaol.com also requires super short passwords
- Humdeee 8y agoThis was changed actually. You can change your password to something more secure now. The help files appear to not have been updated.
- Scoundreller 8y agoCorrect. It should be pointed out that the old passwords were all 6 numbers. Any alpha characters would be converted to a number through a simple map.
- cperciva 8y agoBMO changed that a few weeks ago! I guess their website hasn't been fully updated yet.