‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. walrus01 · · focus · HN ↗
    Until just 8 years ago one of the major Canadian nationwide banks was provably storing peoples&#x27; online banking logins in plaintext in some ancient mainframe database system. If you got to a sufficiently high level of customer service people in an account recovery process (like executor&#x2F;probate process for the deceased) they could literally read back to you the entire password letter for letter.

    And just ten years ago BMO required passwords to be exactly 6 char, no more, no less: <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;PersonalFinanceCanada&#x2F;comments&#x2F;4t0mlk&#x2F;bmo_only_allows_6_character_passwords_for_its&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;PersonalFinanceCanada&#x2F;comments&#x2F;4t0m...

    For the Americans who might not be aware of what BMO is (it&#x27;s not some podunk small town bank): <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Bank_of_Montreal" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Bank_of_Montreal

    1. andrewstuart2 · · focus · HN ↗
      I mean that could still be encrypted. But passwords should never be reversible. It should be hashed with scrypt or apparently now Argon2id.
      1. walrus01 · · focus · HN ↗
        I mean literally like if the person&#x27;s password was &quot;potato##!&quot; the customer service person would read back &quot;potato##!&quot;. They weren&#x27;t reading the encrypted contents of a pw field.
        1. UqWBcuFx6NV4r · · focus · HN ↗
          That doesn’t mean that it is stored as plain text. It just means that it isn’t hashed.

          I agree that it any system that allows this IS almost certainly just storing as plain text, and that it’s bad regardless.

        2. unsnap_biceps · · focus · HN ↗
          their point is it could have been stored encrypted and then decrypted for the customer service person to read back to you. Access to plain text != storing it as plain text.
          1. Atheros · · focus · HN ↗
            The only way three people can keep a secret is if two of them are dead.

            If the data can be read by so many people in the company that even the customer service people have access, it&#x27;s functionally not encrypted.

            1. unsnap_biceps · · focus · HN ↗
              I don&#x27;t disagree with you, however the original claim of

              &gt; provably storing peoples&#x27; online banking logins in plaintext in some ancient mainframe database system

              Is not about functional encryption but storing directly as plain text.

    2. sippingabonedry · · focus · HN ↗
      &gt; For the Americans who might not be aware of what BMO is

      Maybe news hasn&#x27;t traveled north and broadcast on the CBC, so maybe you haven&#x27;t heard, but BMO has branches all over the US.

      1. walrus01 · · focus · HN ↗
        Yes, as the result of certain acquisitions, much as you can see the banks that TD acquired and rebranded particularly on the US east coast. But not everywhere and not as prevalent as like a Bank of America or Wells Fargo or Citibank. There&#x27;s huge swathes of the US that have zero BMO brand name presence.

        Additionally First Citizens acquired a bunch of &quot;BMO&quot; branchs and is presumably converting them back to their branding.

        <a href="https:&#x2F;&#x2F;www.google.com&#x2F;search?client=firefox-b-d&amp;q=first+citizens+bank+acquires+BMO+USA+branches" rel="nofollow">https:&#x2F;&#x2F;www.google.com&#x2F;search?client=firefox-b-d&amp;q=first+cit...

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.