<input type="password" maxlength="20"> prevents me from logging into Vanguard
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
<input type="password" maxlength="20"> prevents me from logging into Vanguard
Unofficial Hacker News client; not affiliated with Y Combinator.
coaksford · · focus · HN ↗
airstrike · · focus · HN ↗
jiggawatts · · focus · HN ↗
Ass covering instead of responsibility.
Security theatre, in other words.
When the consequences for failure are very high but personal reward for success is very low, everyone does everything they can to avoid being held responsible for the consequences.
Note that I didn’t write “avoid consequences”!
That’s different.
pphysch · · focus · HN ↗
madamelic · · focus · HN ↗
It baffles me why so many sites block paste on bank account number inputs like it is 1995 and we are typing it from checks.
pwg · · focus · HN ↗
pulvinar · · focus · HN ↗
ajb · · focus · HN ↗
Also, for finance specifically : " A sound banker, alas, is not one who foresees danger and avoids it, but one who, when he is ruined, is ruined in a conventional way along with his fellows, so that no one can really blame him." - Keynes
sergiotapia · · focus · HN ↗
Every time I prodded for a passkey I have to run a grep in my brain, what app did I use, or what it an extension, under my personal or work email?
A NIGHTMARE, and for what.
winkelmann · · focus · HN ↗
esseph · · focus · HN ↗
xigoi · · focus · HN ↗
esseph · · focus · HN ↗
So passkey is saved to my account. Account is logged in on multiple devices, secured with an additional pin.
It doesn't matter what device I'm on, I can either use the app on a mobile device or a browser.
Site goes to login, prompts me for passkey, I type in PIN and select the passkey from my password manager.
It's fast and easy to use.
If I am on a random device (which never happens, ever) I would just log in via browser, or use one of my hardware tokens if I were expecting to access something from an unusual device.
skylurk · · focus · HN ↗
esseph · · focus · HN ↗
cyode · · focus · HN ↗
I think they use some cursed (or secure I guess) combo of stringent special character requirements, no reuse of old passwords, and automatic resets after incorrect guesses.
It actually hasn’t been an issue after finally using a password manager, but I remember it being a regular headache before that.
kstrauser · · focus · HN ↗
Sometimes I ended up explaining that to a well-meaning but overworked person who just wasn't aware of the "new" (cough 2017) standard, but they'd ask me for the citation and giggle gleefully, thrilled that they could show their boss that they could knock off that obsolete ritual.
Sometimes I ended up with someone a little smug, because they were at a megacorp and I wasn't, and you'd see the momentary flicker of surprise and uncertainty as they started to wonder if maybe they'd missed something, something very important. I took an unreasonable amount of joy from those interactions.
TZubiri · · focus · HN ↗
I think it has to do with the fact that Banks are heavily driven by nation law and regulation, so it's not engineering folk that are at the helm, rather it's driven by natural language source code written by non technical people that compiles to target code through engineering lackeys. It works for the most part, but you get very weird failure modes.