‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. walrus01 · · focus · HN ↗
    Until just 8 years ago one of the major Canadian nationwide banks was provably storing peoples&#x27; online banking logins in plaintext in some ancient mainframe database system. If you got to a sufficiently high level of customer service people in an account recovery process (like executor&#x2F;probate process for the deceased) they could literally read back to you the entire password letter for letter.

    And just ten years ago BMO required passwords to be exactly 6 char, no more, no less: <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;PersonalFinanceCanada&#x2F;comments&#x2F;4t0mlk&#x2F;bmo_only_allows_6_character_passwords_for_its&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;PersonalFinanceCanada&#x2F;comments&#x2F;4t0m...

    For the Americans who might not be aware of what BMO is (it&#x27;s not some podunk small town bank): <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Bank_of_Montreal" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Bank_of_Montreal

    1. andrewstuart2 · · focus · HN ↗
      I mean that could still be encrypted. But passwords should never be reversible. It should be hashed with scrypt or apparently now Argon2id.
      1. walrus01 · · focus · HN ↗
        I mean literally like if the person&#x27;s password was &quot;potato##!&quot; the customer service person would read back &quot;potato##!&quot;. They weren&#x27;t reading the encrypted contents of a pw field.
        1. UqWBcuFx6NV4r · · focus · HN ↗
          That doesn’t mean that it is stored as plain text. It just means that it isn’t hashed.

          I agree that it any system that allows this IS almost certainly just storing as plain text, and that it’s bad regardless.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.