5 ms·
Password manager? Hargreaves Lansdown, a UK broker big enough to hold people's pensions, asks you for eg the first, third and eighth letter of your password.
by lotsofcows 12y ago
Password manager?
Hargreaves Lansdown, a UK broker big enough to hold people's pensions, asks you for eg the first, third and eighth letter of your password.
So not only no password manager but they are almost certainly storing my password in plain text.
They supplement this "security" by asking for a username in the format <name><2 digit number> and your date of birth...
- zhte415 12y agoThat may be against FSA regulations. When I worked in banking that type of policy would have been torn apart by any competent auditor, an internal audit at that. If you're their customer or just concerned, write an email to the FSA, as certainly using a birth date as a username is phishy to the extreme.
- dogma1138 12y agoSadly it's not but it's also doesn't mean that they store you PW in plain text. Verified by Visa or 3Dsecure uses a similar scheme, they has the passwords however they chop them single chars and use a salt which is derived from your PAN.
- kruczek 12y agoIt is not necessarily a sign of storing passwords in plaintext. They might have as well prepared several combinations of different letters from your password and then hashed each combination separately.
- bobince 12y agoIt turns out storing hashed combinations is barely any stronger than plaintext. The attacker just has to be successful against one of the combinations (eg characters 1+2+3), which doesn't offer enough combinations to make it a sufficient slow guess even if the password is randomly-chosen; for real user-chosen passwords it falls very quickly. Once the attacker has that it's trivial to leverage to guess other combinations (eg 1+2+4) repeatedly until you have the whole password. If you have to implement a n-of-m password system, you can't do one-way hashing, so you have to fall back to keeping it encrypted in the database, and keeping the encryption keys separate and more strongly protected (eg in an HSM). (But yes: n-of-m is generally a bad idea for usability as well as of very doubtful security benefit.)
- hobarrera 12y agoHashing isn't to avoid someone guessing, but to avoid leaking thousands of passwords when you db get stolen. Even if someone got the db, and managed to get the hash of a certain character combination, they'd need to get the exact one that the bank prompts for on the next login attempt.