cancel
Showing results for 
Search instead for 
Did you mean: 

WACKY WEDNESDAY: case insensitive passwords and bank security

tag
Anonymous
Not applicable

Re: WACKY WEDNESDAY: case insensitive passwords and bank security


@Anonymous wrote:

@Anonymous wrote:
I remember system called nem-id when I was in Denmark, they send you a card with bunch of one time use passwords, and each time you log on it ask you to match the password number printed on card. It was very secured system but if you forget to take it with you on travel or lose the card, can't log on until you have the card.

Yes.  Hopefully more will move towards soft tokens which are generated by an app on a smart phone, which you are more likely to have with you!


If a gaming company can make mobile authenticator, I don't see why credit card companies can't, but then again that'll cost credit card company money, so.... I don't think it's gonna happen soon. 

Message 11 of 21
Kellan
Regular Contributor

Re: WACKY WEDNESDAY: case insensitive passwords and bank security


@Gunnar419 wrote:

Yes, it definitely worries me that so many banks have case insensitive passwords. I knew Amex did, but didn't know about those others.

 

It also worries me that so many companies limit the length of the password and forbid certain symbols to be used. We should have access to EVERYTHING that helps make our passwords more secure, period. In this day and age it's completely crazy to place requirements that make passwords less secure.

 

Also though, for our own part, we shouldn't be using the same password from bank to bank, but should use a different one for every login.


What this means is the password is being stored in plain text not hashed in the banks database. When you hash a password the password abcde and asdlkfjdfsgoihjskljvnsclkuv haepovjdobvuhsdfpohjdfpo take the same amount of space to store. When the bank limites you to 12 or 16 characters that means they are storing them in the database unhashed. Also a hashed password does not matter which characters you put in your password. 

 

It is simply amazing how insecure our banking is. 

 

Dan

EQ: 678
TU: 699
EX: 736
Message 12 of 21
Kellan
Regular Contributor

Re: WACKY WEDNESDAY: case insensitive passwords and bank security


@Anonymous wrote:

@Anonymous wrote:

@Anonymous wrote:
I remember system called nem-id when I was in Denmark, they send you a card with bunch of one time use passwords, and each time you log on it ask you to match the password number printed on card. It was very secured system but if you forget to take it with you on travel or lose the card, can't log on until you have the card.

Yes.  Hopefully more will move towards soft tokens which are generated by an app on a smart phone, which you are more likely to have with you!


If a gaming company can make mobile authenticator, I don't see why credit card companies can't, but then again that'll cost credit card company money, so.... I don't think it's gonna happen soon. 


I don't think it is about the cost of the Tokens. It is actually about the cost of support calls. The support problems this causes for companies is huge. 

EQ: 678
TU: 699
EX: 736
Message 13 of 21
Imperfectfuture
Super Contributor

Re: WACKY WEDNESDAY: case insensitive passwords and bank security


@Anonymous wrote:

What about SmOrgasBoArD?


Lol! Just thinking that.

Signature needs updating
Message 14 of 21
Imperfectfuture
Super Contributor

Re: WACKY WEDNESDAY: case insensitive passwords and bank security


@Gunnar419 wrote:

Yes, it definitely worries me that so many banks have case insensitive passwords. I knew Amex did, but didn't know about those others.

 

It also worries me that so many companies limit the length of the password and forbid certain symbols to be used. We should have access to EVERYTHING that helps make our passwords more secure, period. In this day and age it's completely crazy to place requirements that make passwords less secure.

 

Also though, for our own part, we shouldn't be using the same password from bank to bank, but should use a different one for every login.


Actually, I do.  Only some minor non sensitive accounts use the same, and even those get varied.  All others are different and stored.

Signature needs updating
Message 15 of 21
Anonymous
Not applicable

Re: WACKY WEDNESDAY: case insensitive passwords and bank security

Wow, I had no idea Chase and some others weren't case sensitive. I've been capitalizing letters every time I logged in. I just tried it and I'm in. Very bad security. But now I'll save time when I enter my PW. Hopefully they update this though.

Message 16 of 21
Anonymous
Not applicable

Re: WACKY WEDNESDAY: case insensitive passwords and bank security


@Kellan wrote:

@Gunnar419 wrote:

Yes, it definitely worries me that so many banks have case insensitive passwords. I knew Amex did, but didn't know about those others.

 

It also worries me that so many companies limit the length of the password and forbid certain symbols to be used. We should have access to EVERYTHING that helps make our passwords more secure, period. In this day and age it's completely crazy to place requirements that make passwords less secure.

 

Also though, for our own part, we shouldn't be using the same password from bank to bank, but should use a different one for every login.


What this means is the password is being stored in plain text not hashed in the banks database. When you hash a password the password abcde and asdlkfjdfsgoihjskljvnsclkuv haepovjdobvuhsdfpohjdfpo take the same amount of space to store. When the bank limites you to 12 or 16 characters that means they are storing them in the database unhashed. Also a hashed password does not matter which characters you put in your password. 

 

It is simply amazing how insecure our banking is. 

 

Dan


I don't think you can conclude that from the length.  It's certainly possible that their hash functions has a limited input length (although I agree they shouldn't care about the characters).   I would be very surprised if they are stored in plain text in any bank these days

Message 17 of 21
joedtx
Valued Contributor

Re: WACKY WEDNESDAY: case insensitive passwords and bank security

I can't believe I opened this thread thinking this was going to be about passwords that could offend others 

images.jpeg

Message 18 of 21
SnackTrader
Valued Contributor

Re: WACKY WEDNESDAY: case insensitive passwords and bank security

Perhaps someone can help me in explaining why this is a big deal. The way I see it, someone either knows my password EXACTLY or doesn't. I can't think of a situation where someone knows my password but can't remember if I capitalized the first letter or not. Not to mention that if someone has my password without hacking techniques, it's probably my fault for giving it to them. If they get the password from hacking techniques (whatever those might be), the person probably has my EXACT password. 

 

In a situation where the account is being accessed from a different computer, most companies ask additional questions or send a temporary code to a verified mobile device.  


In My Wallet: Amex BCP (12/12) $50,000, Chase Freedom (12/12) $16,500, Cap1 Quicksilver (6/12) $14,000, Barclaycard Rewards (5/13) $10,500, Citi Prestige (4/16) $30,000

Last App: June 27, 2015
Message 19 of 21
Anonymous
Not applicable

Re: WACKY WEDNESDAY: case insensitive passwords and bank security


@SnackTrader wrote:

Perhaps someone can help me in explaining why this is a big deal. The way I see it, someone either knows my password EXACTLY or doesn't. I can't think of a situation where someone knows my password but can't remember if I capitalized the first letter or not. Not to mention that if someone has my password without hacking techniques, it's probably my fault for giving it to them. If they get the password from hacking techniques (whatever those might be), the person probably has my EXACT password. 

 

In a situation where the account is being accessed from a different computer, most companies ask additional questions or send a temporary code to a verified mobile device.  


Simply because it greatly reduces the space that hacking techniques would need to search.   So I do a dictionary type search, and check password1, PASSWORD1, paSSwoRD1 etc.  But if the hacker knows bank X is case insensitive, I just check password1 and move on if that fails.

 

Now if this makes any practical difference, probably not, as big attacks would be mounted n different ways that just trying to get Joe Users bank password (only to discover the checking account has $6.34 in it!)

Message 20 of 21
Advertiser Disclosure: The offers that appear on this site are from third party advertisers from whom FICO receives compensation.