5 ms·
You think that’s bad? A bank here in Canada, Bank Of Montreal, was using a maximum of 8 characters (and I believe no special chars permitted). Couldn’t use them
by davidg109 7y ago
You think that’s bad? A bank here in Canada, Bank Of Montreal, was using a maximum of 8 characters (and I believe no special chars permitted). Couldn’t use them anymore.
- 0xFluegel 7y agoMy german bank Haspa has a limit of 12. My guess for the reason -- apart from "we didn't have any problems, yet" -- is that part of the relevant infrastructure is ancient and uses a hardcoded max length...
- pdexter 7y agocharles schwab did that up to about 4 or 5 years ago
- meowface 7y agoHow recently were they doing that? That would be utterly insane in 2005, let alone 2020.
- roter 7y agoThey're now asking for new passwords: * minimum of 8 characters * one uppercase and lowercase letter * one number * one special character They should just allow any character instead of requiring characters. At least they allow longer passwords...
- moltar 7y agoTangerine uses 6 digits
- duxup 7y agoI had a bank do that to me too. I was logging in and sure I typoed my password but it worked. Then I tried typoing it again and it failed. Then I started to wonder ... yeah after like 8 characters it just didn't matter. I emailed them and did not get a response, but to their credit they fixed it within about a month. Maybe that was planned already but at least they fixed it.
- recursive 7y agoIf they could just fix it, it seems like they must be storing user credentials insecurely. At least, I can't figure out how to fix something like this without at least a password change for all users.
- duxup 7y agoOh I wouldn't be surprised. A few years later I actually had visibility inside that bank due to my work. There was a whole IT team dedicated to "review this and fix the horrible decisions we made in the past". I didn't have visibility to their web interactions / front end and such but it wouldn't surprise me if that was just as much a project to clean up. To their credit whenever I talked to the "clean up" type team they were super sharp guys and quite willing to listen to outside vendors (me) who sometimes saw stuff the guys inside maybe didn't.
- yc-kraln 7y agoeasy enough; on next successful login re-hash the full length of the password and store it.
- Someone 7y agoThat would be somewhat risky; the user might have mistyped the password somewhere in the part that up to now got ignored.
- Someone 7y agoYou mark the existing hashes as “only use the first 8 characters to compute the hash” and, from now on, clear that bit for every password that gets changed and for new accounts. When all bits have been cleared, remove the logic for inspecting the bit and the mark bit. If that takes too long, force your users to update their password at whatever pace suits you.
- freehunter 7y agoI used to work infosec at a financial institution and I can explain why this is: the online banking systems have historically been extensions of the phone system. When bank-by-phone was popular, you’d have a four digit PIN to authenticate yourself. When they moved online, they used the same backend system but just doubled the required length of the PIN. So 8 digits or maybe 12 or 16 indicates the system runs on a modified bank by phone system. That also means they have to restrict password characters to things that would work on a phone keypad. Another place I worked had the same problem with passwords because any password that you use might have to be entered into a handheld scanner in the warehouse. And those handhelds didn’t have full keyboards so you could only use characters that exist on the handheld’s keyboard.
- l31g 7y agoLast time I changed my username and password for my AmEx login, their rules were very restrictive with the username (I couldn't use numbers at the beginning of it) and password (I could't use characters like commas or periods)...
- prostanac 7y agoIn Romania ING limits the password to 5 digits. However SMS 2FA is enabled by default (iirc, have been many years since I have this banking account).