‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. coaksford · · focus · HN ↗
    All my worst experiences with password length have been banking and finance and it boggles my mind that they all get something so incredibly basic so incredibly wrong. What is it about this sector that makes it so?
    1. airstrike · · focus · HN ↗
      Fear of the Compliance monster.
    2. jiggawatts · · focus · HN ↗
      Compliance over action.

      Ass covering instead of responsibility.

      Security theatre, in other words.

      When the consequences for failure are very high but personal reward for success is very low, everyone does everything they can to avoid being held responsible for the consequences.

      Note that I didn’t write “avoid consequences”!

      That’s different.

    3. pphysch · · focus · HN ↗
      Probably PCI and other regulations making it difficult to use and thus learn good software, so they develop entire ecosystems in-house
    4. madamelic · · focus · HN ↗
      Don&#x27;t forget blocking paste!

      It baffles me why so many sites block paste on bank account number inputs like it is 1995 and we are typing it from checks.

      1. pwg · · focus · HN ↗
        With Firefox, if one sets the dom.event.clipboardevents.enabled about::config setting to false, then websites can no longer block paste. Your pastes will work, despite their trying to intercept and block them.
    5. pulvinar · · focus · HN ↗
      Don&#x27;t be so hard on them. Their COBOL program is probably limited to 80 character records, so they&#x27;ll fit on a punched card.
    6. ajb · · focus · HN ↗
      There&#x27;s an inherent insularity to security groups or fraud teams; they have to have a professional suspicion of everything. This can go wrong and end up being NIH or gratuitously customer-unfriendly.

      Also, for finance specifically : &quot; A sound banker, alas, is not one who foresees danger and avoids it, but one who, when he is ruined, is ruined in a conventional way along with his fellows, so that no one can really blame him.&quot; - Keynes

    7. sergiotapia · · focus · HN ↗
      Don&#x27;t get me started on passkeys, where it seems it was made for people who literally only use one device: their phone.

      Every time I prodded for a passkey I have to run a grep in my brain, what app did I use, or what it an extension, under my personal or work email?

      A NIGHTMARE, and for what.

      1. winkelmann · · focus · HN ↗
        At least let me actually use a security key! PayPal already lets you use security keys for 2FA, but it appears they only allow for smartphone based passkeys for some reason. I&#x27;m sure these are behind all the TPMs and Secure Enclaves and whatnot, but a security key is still orders of magnitude safer.
      2. esseph · · focus · HN ↗
        My passkey is stored in my password manager and is available across devices with no hassle.
        1. xigoi · · focus · HN ↗
          Until you need to log in on some random device. Or inside an in-app browser popup.
          1. esseph · · focus · HN ↗
            Huh? Do you not understand how this works?

            So passkey is saved to my account. Account is logged in on multiple devices, secured with an additional pin.

            It doesn&#x27;t matter what device I&#x27;m on, I can either use the app on a mobile device or a browser.

            Site goes to login, prompts me for passkey, I type in PIN and select the passkey from my password manager.

            It&#x27;s fast and easy to use.

            If I am on a random device (which never happens, ever) I would just log in via browser, or use one of my hardware tokens if I were expecting to access something from an unusual device.

            1. skylurk · · focus · HN ↗
              Sometimes I need to sign in to a personal Github account on a work laptop, so I hope non-passkey flows keep working. I don&#x27;t install my personal password manager on a work laptop.
              1. esseph · · focus · HN ↗
                I would use hardware token for that use case
    8. cyode · · focus · HN ↗
      +1, plus Ticketmaster for some reason.

      I think they use some cursed (or secure I guess) combo of stringent special character requirements, no reuse of old passwords, and automatic resets after incorrect guesses.

      It actually hasn’t been an issue after finally using a password manager, but I remember it being a regular headache before that.

    9. kstrauser · · focus · HN ↗
      One of my most favorite things in the world was when an org with an outdated security program told me we&#x27;d have to rotate our passwords monthly. Then I&#x27;d get to tell them that no, we wouldn&#x27;t, and due to modern security practices, we couldn&#x27;t without causing a compliance exception.

      Sometimes I ended up explaining that to a well-meaning but overworked person who just wasn&#x27;t aware of the &quot;new&quot; (cough 2017) standard, but they&#x27;d ask me for the citation and giggle gleefully, thrilled that they could show their boss that they could knock off that obsolete ritual.

      Sometimes I ended up with someone a little smug, because they were at a megacorp and I wasn&#x27;t, and you&#x27;d see the momentary flicker of surprise and uncertainty as they started to wonder if maybe they&#x27;d missed something, something very important. I took an unreasonable amount of joy from those interactions.

    10. TZubiri · · focus · HN ↗
      In Argentina our password is called username, it gets the password treatment, but the UIs call it login.

      I think it has to do with the fact that Banks are heavily driven by nation law and regulation, so it&#x27;s not engineering folk that are at the helm, rather it&#x27;s driven by natural language source code written by non technical people that compiles to target code through engineering lackeys. It works for the most part, but you get very weird failure modes.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.