Hacker News new | ask | show | jobs
by monksy 807 days ago
They're pretty terrible when they do.

For the longest time the max password size was 8 characters and the csr knew what your password was.

Heck I've had Chase security tell me they'd call me back.. dude that's exactly how people get compromised.

1 comments

A friensd bank, hopefully not the one i use, only allow a password off 6 digits. Yes You read it right, 6 fucking digits to login, i hace him the asvice to run away from that shitty bank
Did this bank start out as a "telephone bank"? One of the largest German consumer banks still does this because they were the first "direct bank" without locations and typing in digits on the telephone pad was the most secure way of authenticating without telling the "bank teller" your password. So it was actually a good security measure but it is apparently too complicated to update their backend to modern standards.

They do require 2FA, though.

DiBa?