4 ms·
It's actually worse than that. I don't know what it's like now, since I haven't used POF since 2008 or so when I met my current girlfriend (though I only remem
by AgentConundrum 16y ago
It's actually worse than that.
I don't know what it's like now, since I haven't used POF since 2008 or so when I met my current girlfriend (though I only remembered to kill the account a few months back), but back then they would actually send you reminders every so often - I want to say once a week - that included your plain text password as a reminder.
I think this is just the kick in the ass I needed to go through all my accounts around the internet and make sure they all have unique, reasonably complex passwords. My email and banking passwords have always been unique, but I know I've been slack elsewhere. I won't let that happen again.
- jacquesm 16y agoIf there is an option to use some kind of hardware token with your banking then I would strongly advise you to take that. Having just a password to protect your bank account sounds pretty scary to me. That's about as juicy as it gets. I'm paranoid enough about my servers having 'just' a password to protect them (oh, and an ACL), if my bank accounts would have only a password I wouldn't sleep. Every time I log on I have to use my chipcard in a little electronic device with an LCD display and a bunch of buttons on it, the chipcard generates a unique ID every time I log in. When I want to do an actual transaction I have to authorize it using 1, 2 or 3 challenges depending on the amount and destination of the transaction. It's less convenient than a password protected system but it's fairly secure. It's also protected against the most common form of theft called 'skimming' because it uses the chip and not the magnetic stripe so a thief using the data on a skimmed card could only use that to use an ATM but not to access the internet banking section of the website of my bank.
- AgentConundrum 16y agoAre you European? I only ask because my friend in London is the only person I've ever heard of using such a device. Unfortunately, such a thing seems all but unheard of here in Canada. Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. I have noticed that when I login from a new computer (for example, when I visit my parents), the site uses one of my challenge questions to ensure it's really me. I guess that's something, although I really don't know the exact circumstances that trigger the challenge.
- statictype 16y agoOdd. It seems like almost every big bank in Asia has them by now. I would have thought their use is widespread world over.
- jacquesm 16y ago> Are you European? Yes, working from NL at the moment. > Unfortunately, such a thing seems all but unheard of here in Canada. That sucks! > Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. Ok. > I have noticed that when I login from a new computer (for example, when I visit my parents), the site uses one of my challenge questions to ensure it's really me. So the bank likely either keeps a record of 'known' IP addresses for you or they keep a cookie on the computer that they use to identify a computer that you've used at least once. How annoying. It's interesting how we berate POF for not following 'best practices' but even institutions such as banks could do a whole lot better to protect their and their customers best interests. Are you liable for fraud committed with your account online? Or would the bank indemnify you if your password were used to clean out your accounts?
- AgentConundrum 16y agoAre you liable for fraud committed with your account online? Or would the bank indemnify you if your password were used to clean out your accounts? Honestly, I have no idea. I really should look into the fine print in the online TOS/Rules&Regs.
- jacquesm 16y agoThe system we use here has it's own vulnerabilities (after all, if your card is stolen and the pin is known then any token can be used to authorize transactions, and there are known ways to attack the card electronically) but it makes it at least a little bit harder. On top of that we do have indemnification. Combating electronic banking fraud is an ever lasting game of leap frog, it looks like the banks are at least one step too far behind. At least they have the extra challenge question, I hope you made them hard enough :)
- _delirium 16y agoIn Denmark the currently-being-phased-in solution is a low-tech version of two-factor authentication. Instead of a hardware dongle, the centrally-administered "NemID" system issues you with a physical code card with some numerical codes on it. You enter your NemID password, your CPR number (Denmark's citizen-ID number), and the next unused code on the card. When there's fewer than 20 unused codes, the system notices and mails you a new card. The downside is that there's now a single point of failure, albeit with more factors. If you get someone's CPR number, their NemID password, and their current NemID card with some indication on it of which the next unused code is (most people mark off the used codes), you can log into everything: all Danish banks, the tax authority, the municipal authorities, your library account, etc., etc. They do try to minimize it by writing strongly worded warnings everywhere not to store your NemID password in your wallet. A typical wallet contains a Danish health card with CPR number, and the NemID code card, so it's fairly important that the NemID password not also be there.
- silvestrov 16y agoThe upside is that the NemID system gets the average citizen to a point where his/her family (and close friends) are the largest security problem. It is much more difficult for hackers in Argentina and Russia to get into your bank account when they need access to a piece of paper. If is impossible to protect against your own family: the have hardware access to your computer, they can intercept all your paper mail, they know all details about your life, etc. So they are the perfect identity thieves. Some Danes think they are clever and scan the paper card and store it as an image on their computer. Some people are just impossible to make a secure access system for. The upside of the downside is that if anybody gets hold of your login details, then there is a single place to stop them instead of having to change 20 logins. BTW. "NemID" translated to English is "EasyID". Within the next year, a hardware dongle will be available (e.g. for users who often login and uses up all the codes on a paper card in no time).
- jacquesm 16y agoIf there is one thing I would like it would be the option to specifically authorize a set of IP addresses allowed to access my bank account rather than the implicit way it is done right now.