3 ms·
According to Fidelity's website [0] they still do so ("You'll be asked to enter your username and password using the keypad on your phone."). I basically assum
by karlding 6y ago
According to Fidelity's website [0] they still do so ("You'll be asked to enter your username and password using the keypad on your phone.").
I basically assume any financial institution that provides support for the old "telephone banking" methods via DTMF tones either stores your password in plaintext or a hashed version that reduces entropy. I'm honestly surprised hackers haven't gotten sophisticated enough to bruteforce these reduced entropy login passwords using a Twilio account.
[0] https://www.fidelity.com/customer-service/phone-numbers/overview https://www.fidelity.com/customer-service/phone-numbers/over...