5 ms·
Quite shameful. Fortunately, I only use Schwab because of their awesome checking account that covers ATM fees. Definitely won't put more of my assets in there u
by markcerqueira 12y ago
Quite shameful. Fortunately, I only use Schwab because of their awesome checking account that covers ATM fees. Definitely won't put more of my assets in there until they get their act together.
I may be wrong, but I think user IDs can be longer than 8 characters too which makes this all even worse.
LinkedIn did something similar with having to append your auth token to the end of your password, but they actually checked the token AFAIK.
- mariusz331 12y agoAre there benefits to append the token to the end of the password over adding a field for it in the form?
- thesimon 12y agoConvenience for the user (no need to move to a different field) and UI advantages (no need for an third field which might make the form look complicated and confuse users who don't have 2FA activated. Not saying that this is a good idea, but there are some benefits for appending the token.
- jeremyt 12y agoI might buy it if two factor activation wasn't a one time operation. As it stands, there's no need to confuse existing users. You just need a separate pathway to activate the token. THEN you just ask for the token as a step two in the login process. That's actually how Schwab handles things right now.
- markcerqueira 12y agoFor some shitty services, like PayPal that don't give you a long-lived auth token, it is an every-time process. :| As expected, Schwab isn't the only perpetrator of bad two-factor auth. I think PayPal still DOES NOT support two-factor auth on their mobile clients. Shameless plug of my blog posts about Paypal's terrible two factor auth: http://mark.gg/2014/10/22/paypal-and-delusions-of-grandeur/ http://mark.gg/2014/10/22/paypal-and-delusions-of-grandeur/ http://mark.gg/2014/06/04/kicking-the-tires-with-paypal/ http://mark.gg/2014/06/04/kicking-the-tires-with-paypal/
- markcerqueira 12y agoDefinitely not more convenient for users in all cases. LinkedIn did something similar. When they told me to append my code to the end of my password and I click on the password field, my password would be wiped away so I'd have to type in my password AGAIN and then add the security token to the end of it. You don't need a third field. On mobile, if you pass the password auth, you go to a new screen and bring up a number pad and ask the user to wait for the text message. It's pretty smooth. Much smoother than the LinkedIn flow I described above. If you don't have 2-factor auth after passing the password auth, you just go right to the app. I documented my frustrations here in case you want to see: http://mark.gg/2013/07/17/linkedin-2.5-factor-authentication/ http://mark.gg/2013/07/17/linkedin-2.5-factor-authentication... LinkedIn already fixed this, but it's quite shameful they even let this out into the wild. :/
- michaelt 12y agoIf they're going for "less complicated" then what they've done hasn't achieved it :)
- markcerqueira 12y agoIt saves client engineers some small amount of time from implementing it on their end, but building these screens shouldn't take more than a few days. It's a terrible UX though. I wrote a blog post with some images about it if you want to see what it looks like: http://mark.gg/2013/07/17/linkedin-2.5-factor-authentication/ http://mark.gg/2013/07/17/linkedin-2.5-factor-authentication...
- elahd 12y agoThere are other banks that offer accounts with similar benefits plus the benefit of having physical branches. TD premier checking is one, if you're fine with keeping a minimum balance.
- arenaninja 12y agoI use Alliant Credit Union, and last month they started refunding ATM fees as well (limit 8 in a month, I believe)
- greggarious 12y agoI also only keep a bit in it for travel. The rest is in a different account. When I want to deposit funds, I write myself a check from my credit union, or deposit a reimbursement check. (I travel a lot for work so I get reimbursement checks frequently)